This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT Log, thought I was clean but - Softomate!

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there,

I followed the self help guide and that seemed to clear out a whole load of stuff - but then

I got a XP Taskbar Search bar appear and AVG Anti-Spyware shows an infection of Adware.Softomate. And something tried to open http://clk.atdmt.com

So here's the HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 00:13:20, on 14/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\kybrdff_e28.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\PuTTY\pageant.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\dfndrff_e28.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
E:\Sources\_PC Security\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://messenger.msn.com/flash/?mkt=en-gb&…ersion=7,0,19,0
R3 - URLSearchHook: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll (file missing)
O2 - BHO: Burn4Free Toolbar Helper - {F8E5CA21-C27B-43e7-B2BE-4CA93C9F9A1F} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
O3 - Toolbar: Burn4Free Toolbar - {70DE7956-479D-4eb7-8641-2B45774C350E} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
O3 - Toolbar: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e28.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [defender] c:\\dfndrff_e28.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [strmfilt] C:\WINDOWS\system32\strmfilt.exe
O4 - HKCU\..\Run: [kbdest] C:\WINDOWS\system32\kbdest.exe
O4 - HKCU\..\Run: [wmpasf] C:\WINDOWS\system32\wmpasf.exe
O4 - HKCU\..\Run: [FIREFOX] C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
O4 - HKCU\..\Run: [wshirda] C:\WINDOWS\system32\wshirda.exe
O4 - HKCU\..\Run: [ddrawex] C:\WINDOWS\system32\ddrawex.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
O4 - Global User Startup: Bluetooth Manager.lnk = ?
O4 - Global User Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache - Unknown owner - C:\Program Files\IBserver\apache\Apache.exe" –ntservice (file missing)
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: batt.exe - Unknown owner - C:\WINDOWS\system32\batt.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: mqutil.exe - Unknown owner - C:\WINDOWS\system32\mqutil.exe (file missing)
O23 - Service: MySql - Unknown owner - C:\Program Files\IBserver\mysql\bin\mysqld-opt.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: nvwimg.exe - Unknown owner - C:\WINDOWS\system32\nvwimg.exe (file missing)
O23 - Service: unzip32.exe - Unknown owner - C:\WINDOWS\system32\unzip32.exe (file missing)



Many Thanks for your help

David
Well - I still suffered from something so I ran Spybot, Ad-Aware, AVG-Antivirus, ATF-Cleaner and my AV: Avast once again (with on boot virust scan and spybot on logon) and most of it in safe mode. and I still get a program called "Project1" running visible in Task Manager and am expecting problems with a search bar again.

Here's the Ad-Aware Log, AVG-Antivirus Log and HJT Logs again

Ad-Aware Log
==================================================================

Ad-Aware SE Build 1.06r1
Logfile Created on:14 October 2006 23:38:14
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R126 12.10.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Adware.DollarRevenue(TAC index:10):18 total references
MRU List(TAC index:0):13 total references
Other(TAC index:5):1 total references
Possible Browser Hijack attempt(TAC index:3):6 total references
Softomate Toolbar(TAC index:9):2 total references
Tracking Cookie(TAC index:3):1 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


14-10-2006 23:38:14 - Scan started. (Full System Scan)

MRU List Object Recognized!
Location: : C:\Documents and Settings\David\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office


MRU List Object Recognized!
Location: : C:\Documents and Settings\David\recent
Description : list of recently opened documents


MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d


MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X


MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw


MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\mediaplayer\preferences
Description : last playlist index loaded in microsoft windows media player


MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player


MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\office\10.0\common\open find\microsoft word\settings\save as\file name mru
Description : list of recent documents saved by microsoft word


MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\office\10.0\excel\recent files
Description : list of recent files used by microsoft excel


MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\office\10.0\powerpoint\recent file list
Description : list of recent files used by microsoft powerpoint


MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened


MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension


MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened


Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 608
ThreadCreationTime : 14-10-2006 11:17:54
BasePriority : Normal


#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 672
ThreadCreationTime : 14-10-2006 11:17:56
BasePriority : Normal


#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 696
ThreadCreationTime : 14-10-2006 11:17:56
BasePriority : High


#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 740
ThreadCreationTime : 14-10-2006 11:17:57
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe

#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 752
ThreadCreationTime : 14-10-2006 11:17:57
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe

#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 904
ThreadCreationTime : 14-10-2006 11:17:57
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 988
ThreadCreationTime : 14-10-2006 11:17:57
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1080
ThreadCreationTime : 14-10-2006 11:17:57
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1136
ThreadCreationTime : 14-10-2006 11:17:57
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1348
ThreadCreationTime : 14-10-2006 11:17:58
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:11 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1548
ThreadCreationTime : 14-10-2006 11:17:59
BasePriority : Normal
FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
ProductVersion : 5.1.2600.2696
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe

#:12 [aswupdsv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 1700
ThreadCreationTime : 14-10-2006 11:18:06
BasePriority : Normal


#:13 [ashserv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 1712
ThreadCreationTime : 14-10-2006 11:18:06
BasePriority : High
FileVersion : 4, 7, 889, 0
ProductVersion : 4, 7, 0, 0
ProductName : avast! Antivirus
FileDescription : avast! antivirus service
InternalName : aswServ
LegalCopyright : Copyright © 2006 ALWIL Software
OriginalFilename : aswServ.exe

#:14 [guard.exe]
FilePath : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\
ProcessID : 1736
ThreadCreationTime : 14-10-2006 11:18:06
BasePriority : Normal
FileVersion : 7, 5, 0, 47
ProductVersion : 7, 5, 0, 47
ProductName : AVG Anti-Spyware
CompanyName : Anti-Malware Development a.s.
FileDescription : AVG Anti-Spyware guard
InternalName : AVG Anti-Spyware guard
LegalCopyright : Copyright © 2006 Anti-Malware Development a.s.
OriginalFilename : guard.exe

#:15 [mdm.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\VS7Debug\
ProcessID : 1872
ThreadCreationTime : 14-10-2006 11:18:07
BasePriority : Normal
FileVersion : 7.00.9064.9150
ProductVersion : 7.00.9064.9150
ProductName : Microsoft Development Environment
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : Copyright © Microsoft Corp. 1997-2000
OriginalFilename : mdm.exe

#:16 [nvsvc32.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1912
ThreadCreationTime : 14-10-2006 11:18:07
BasePriority : Normal
FileVersion : 6.14.10.7181
ProductVersion : 6.14.10.7181
ProductName : NVIDIA Driver Helper Service, Version 71.81
CompanyName : NVIDIA Corporation
FileDescription : NVIDIA Driver Helper Service, Version 71.81
InternalName : NVSVC
LegalCopyright : © NVIDIA Corporation. All rights reserved.
OriginalFilename : nvsvc32.exe

#:17 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 240
ThreadCreationTime : 14-10-2006 11:18:11
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:18 [wdfmgr.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 260
ThreadCreationTime : 14-10-2006 11:18:11
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: dnsrv(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe

#:19 [ashmaisv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 380
ThreadCreationTime : 14-10-2006 11:18:13
BasePriority : Normal


#:20 [ashwebsv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 660
ThreadCreationTime : 14-10-2006 11:18:14
BasePriority : Normal


#:21 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1116
ThreadCreationTime : 14-10-2006 11:18:14
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe

#:22 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 548
ThreadCreationTime : 14-10-2006 22:06:39
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE

Adware.DollarRevenue Object Recognized!
Type : Process
Data : deskbar.dll
TAC Rating : 10
Category : Adware
Comment : deskbar.dll.dmp
Object : C:\Program Files\Deskbar\


Warning! Adware.DollarRevenue Object found in memory(C:\Program Files\Deskbar\deskbar.dll)


#:23 [type32.exe]
FilePath : C:\Program Files\Microsoft IntelliType Pro\
ProcessID : 2272
ThreadCreationTime : 14-10-2006 22:06:46
BasePriority : Normal


#:24 [point32.exe]
FilePath : C:\Program Files\Microsoft IntelliPoint\
ProcessID : 2336
ThreadCreationTime : 14-10-2006 22:06:57
BasePriority : Normal


#:25 [realsched.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ProcessID : 2472
ThreadCreationTime : 14-10-2006 22:06:58
BasePriority : Normal
FileVersion : 0.1.0.3275
ProductVersion : 0.1.0.3275
ProductName : RealPlayer (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
LegalTrademarks : RealAudio™ is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe

#:26 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2628
ThreadCreationTime : 14-10-2006 22:06:59
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:27 [hpztsb10.exe]
FilePath : C:\WINDOWS\system32\spool\drivers\w32x86\3\
ProcessID : 2800
ThreadCreationTime : 14-10-2006 22:07:01
BasePriority : Normal
FileVersion : 2.323.0.0
ProductVersion : 2.323.0.0
ProductName : HP DeskJet
CompanyName : HP
LegalCopyright : Copyright © Hewlett-Packard Company 1999-2004

#:28 [qttask.exe]
FilePath : C:\Program Files\QuickTime\
ProcessID : 2840
ThreadCreationTime : 14-10-2006 22:07:02
BasePriority : Normal
FileVersion : 7.0.4
ProductVersion : QuickTime 7.0.4
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
FileDescription : QuickTime Task
InternalName : QuickTime Task
LegalCopyright : Copyright Apple Computer, Inc. 1989-2006
OriginalFilename : QTTask.exe

#:29 [hpcmpmgr.exe]
FilePath : C:\Program Files\HP\hpcoretech\
ProcessID : 2880
ThreadCreationTime : 14-10-2006 22:07:04
BasePriority : Normal
FileVersion : 2.1.1.0
ProductVersion : 2.1.4
ProductName : hp coretech (COmponent REuse TECHnology)
CompanyName : Hewlett-Packard Company
FileDescription : HP Framework Component Manager Service
InternalName : HPComponentManagerService module
LegalCopyright : Copyright © Hewlett-Packard. 2002-2003
OriginalFilename : HpCmpMgr.exe

#:30 [ashdisp.exe]
FilePath : C:\PROGRA~1\ALWILS~1\Avast4\
ProcessID : 2764
ThreadCreationTime : 14-10-2006 22:07:08
BasePriority : Normal
FileVersion : 5, 0, 0, 0
ProductVersion : 5, 0, 0, 0
ProductName : avast! Antivirus
FileDescription : avast! service GUI component
InternalName : aswDisp
LegalCopyright : Copyright © 2006 ALWIL Software
OriginalFilename : aswDisp.exe

#:31 [ctfmon.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 3204
ThreadCreationTime : 14-10-2006 22:07:17
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE

#:32 [avgas.exe]
FilePath : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\
ProcessID : 3232
ThreadCreationTime : 14-10-2006 22:07:22
BasePriority : Normal
FileVersion : 7, 5, 0, 50
ProductVersion : 7, 5, 0, 50
ProductName : AVG Anti-Spyware
CompanyName : Anti-Malware Development a.s.
FileDescription : AVG Anti-Spyware
InternalName : AVG Anti-Spyware
LegalCopyright : Copyright © 2006 Anti-Malware Development a.s.
OriginalFilename : avgas.exe

#:33 [msmsgs.exe]
FilePath : C:\Program Files\Messenger\
ProcessID : 3344
ThreadCreationTime : 14-10-2006 22:07:34
BasePriority : Normal
FileVersion : 4.7.3001
ProductVersion : Version 4.7.3001
ProductName : Messenger
CompanyName : Microsoft Corporation
FileDescription : Windows Messenger
InternalName : msmsgs
LegalCopyright : Copyright © Microsoft Corporation 2004
LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msmsgs.exe

#:34 [kybrdff_e29.exe]
FilePath : c:\
ProcessID : 3380
ThreadCreationTime : 14-10-2006 22:07:42
BasePriority : Normal
FileVersion : 1.00.0183
ProductVersion : 1.00.0183
ProductName : Project1
CompanyName : fdslj reditf8eru8turdtreduj54tr8u548
InternalName : kybrdff_18_a
OriginalFilename : kybrdff_18_a.exe

#:35 [msnmsgr.exe]
FilePath : C:\Program Files\MSN Messenger\
ProcessID : 2064
ThreadCreationTime : 14-10-2006 22:07:45
BasePriority : Normal
FileVersion : 7.5.0324
ProductVersion : 7.5.0324
ProductName : MSN Messenger
CompanyName : Microsoft Corporation
FileDescription : MSN Messenger
InternalName : msnmsgr
LegalCopyright : Copyright © Microsoft Corporation 1997-2004
LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msnmsgr.exe

#:36 [wcescomm.exe]
FilePath : C:\Program Files\Microsoft ActiveSync\
ProcessID : 3492
ThreadCreationTime : 14-10-2006 22:07:48
BasePriority : Normal
FileVersion : 4.2.4876.0
ProductVersion : 4.2.4876
ProductName : Microsoft ActiveSync
CompanyName : Microsoft Corporation
FileDescription : ActiveSync Connection Manager
InternalName : wcescomm
LegalCopyright : Copyright © 1995-2006 Microsoft Corp. All rights reserved.
LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation.
OriginalFilename : WCESCOMM.EXE

#:37 [dfndrff_e29.exe]
FilePath : c:\
ProcessID : 3608
ThreadCreationTime : 14-10-2006 22:07:49
BasePriority : Normal
FileVersion : 1.00.0254
ProductVersion : 1.00.0254
ProductName : Project1
CompanyName : ;ew;weew;e;wr;43;;5;
InternalName : Project1
OriginalFilename : Project1.exe

#:38 [rapimgr.exe]
FilePath : C:\PROGRA~1\MI3AA1~1\
ProcessID : 3620
ThreadCreationTime : 14-10-2006 22:07:49
BasePriority : Normal
FileVersion : 4.2.4876.0
ProductVersion : 4.2.4876
ProductName : Microsoft ActiveSync
CompanyName : Microsoft Corporation
FileDescription : ActiveSync RAPI Manager
InternalName : rapimgr
LegalCopyright : Copyright © 1995-2006 Microsoft Corp. All rights reserved.
LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation.
OriginalFilename : rapimgr.exe

#:39 [pageant.exe]
FilePath : C:\Program Files\PuTTY\
ProcessID : 1188
ThreadCreationTime : 14-10-2006 22:07:57
BasePriority : Normal


#:40 [tosbtmng.exe]
FilePath : C:\Program Files\Toshiba\Bluetooth Toshiba Stack\
ProcessID : 3904
ThreadCreationTime : 14-10-2006 22:07:58
BasePriority : Normal


#:41 [tosa2dp.exe]
FilePath : C:\Program Files\Toshiba\Bluetooth Toshiba Stack\
ProcessID : 212
ThreadCreationTime : 14-10-2006 22:08:01
BasePriority : Normal


#:42 [tosbthsp.exe]
FilePath : C:\Program Files\Toshiba\Bluetooth Toshiba Stack\
ProcessID : 1200
ThreadCreationTime : 14-10-2006 22:08:01
BasePriority : Normal


#:43 [wuauclt.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1776
ThreadCreationTime : 14-10-2006 22:09:38
BasePriority : Normal
FileVersion : 5.8.0.2469 built by: lab01_n(wmbla)
ProductVersion : 5.8.0.2469
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Automatic Updates
InternalName : wuauclt.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : wuauclt.exe

#:44 [spybotsd.exe]
FilePath : C:\Program Files\Spybot - Search & Destroy\
ProcessID : 3312
ThreadCreationTime : 14-10-2006 22:34:38
BasePriority : Normal
FileVersion : 1.4.0.3
ProductVersion : 1, 4, 0, 3
ProductName : SpyBot-S&D;
CompanyName : Safer Networking Limited
FileDescription : Spybot - Search & Destroy
InternalName : SpybotSD
LegalCopyright : © 2000-2005 Patrick M. Kolla / Safer Networking Limited. Alle Rechte vorbehalten.
LegalTrademarks : "Spybot" und "Spybot - Search & Destroy" sind registrierte Warenzeichen.
OriginalFilename : SpyBotSD.exe
Comments : Software zum Entfernen von Spyware und ähnlichen Bedrohungen.

#:45 [ashsimpl.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 3884
ThreadCreationTime : 14-10-2006 22:37:33
BasePriority : Normal
FileVersion : 4, 7, 889, 0
ProductVersion : 4, 7, 0, 0
ProductName : avast! Antivirus
CompanyName : ALWIL Software
FileDescription : Virus scanner
InternalName : aswSimpl.exe
LegalCopyright : Copyright © 2006 ALWIL Software
OriginalFilename : aswSimpl.exe

#:46 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 3128
ThreadCreationTime : 14-10-2006 22:37:35
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 14


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{a8b28872-3324-4cd2-8aa3-7d555c872d96}

Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{d7cc80d4-376c-4586-b023-4f35c2ceb28e}

Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{d8c2d4b4-eeaf-4ec4-b1f8-9b6ed15d5a38}

Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{8f15b157-40d9-4b20-8d3b-b1f8b475b58d}

Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{a0881aa1-68be-41ac-9c0d-4c8a69c6c72c}

Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{e827ffd9-95d1-4b49-beb3-5d49e688c108}

Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{a4c8f181-6cdb-4dcc-9fc9-bb9933c81e1f}

Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\windows\currentversion\ext\stats\{a8b28872-3324-4cd2-8aa3-7d555c872d96}

Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\explorer\browser helper objects\{a8b28872-3324-4cd2-8aa3-7d555c872d96}

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 9
Objects found so far: 23


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Possible Browser Hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Page.findthewebsiteyouneed.com

Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "http://searchbar.findthewebsiteyouneed.com"
TAC Rating : 10
Category : Adware
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "http://searchbar.findthewebsiteyouneed.com"
Possible Browser Hijack attempt : Software\Microsoft\Internet Explorer\SearchSearchAssistant.findthewebsiteyouneed.com

Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "http://searchbar.findthewebsiteyouneed.com"
TAC Rating : 10
Category : Adware
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Search
Value : SearchAssistant
Data : "http://searchbar.findthewebsiteyouneed.com"
Possible Browser Hijack attempt : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\MainSearch Page.findthewebsiteyouneed.com

Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "http://searchbar.findthewebsiteyouneed.com"
TAC Rating : 10
Category : Adware
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_USERS
Object : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "http://searchbar.findthewebsiteyouneed.com"
Possible Browser Hijack attempt : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\MainStart Page.findthewebsiteyouneed.com

Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "http://www.findthewebsiteyouneed.com"
TAC Rating : 10
Category : Adware
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_USERS
Object : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "http://www.findthewebsiteyouneed.com"
Possible Browser Hijack attempt : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\MainSearch Bar.findthewebsiteyouneed.com

Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "http://searchbar.findthewebsiteyouneed.com"
TAC Rating : 10
Category : Adware
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_USERS
Object : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "http://searchbar.findthewebsiteyouneed.com"
Possible Browser Hijack attempt : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\MainDefault_Search_URL.findthewebsiteyouneed.com

Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "http://searchbar.findthewebsiteyouneed.com"
TAC Rating : 10
Category : Adware
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_USERS
Object : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\Main
Value : Default_Search_URL
Data : "http://searchbar.findthewebsiteyouneed.com"

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 6
Objects found so far: 29


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:14
Value : Cookie:[removed]/
Expires : 28-10-2006 00:07:04
LastSync : Hits:14
UseCount : 0
Hits : 14

Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 30



Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Adware.DollarRevenue Object Recognized!
Type : File
Data : deskbar.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\



Softomate Toolbar Object Recognized!
Type : File
Data : nsProcess.dll
TAC Rating : 9
Category : Data Miner
Comment :
Object : C:\Documents and Settings\David\Local Settings\Temp\nsj33.tmp\



Adware.DollarRevenue Object Recognized!
Type : File
Data : deskbar.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\Odd\



Adware.DollarRevenue Object Recognized!
Type : File
Data : __delete_on_reboot__d_e_s_k_b_a_r_._d_l_l_
TAC Rating : 10
Category : Adware
Comment :
Object : C:\Program Files\Deskbar\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll


Adware.DollarRevenue Object Recognized!
Type : File
Data : A0116020.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP233\



Adware.DollarRevenue Object Recognized!
Type : File
Data : A0116544.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\



Adware.DollarRevenue Object Recognized!
Type : File
Data : A0116568.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP235\



Adware.DollarRevenue Object Recognized!
Type : File
Data : A0116572.dll
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP236\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll


Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 38


Deep scanning and examining files (E:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for E:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 38


Scanning Hosts file……
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
6728 entries scanned.
New critical objects:0
Objects found so far: 38




Performing conditional scans…
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Adware.DollarRevenue Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\run
Value : defender

Softomate Toolbar Object Recognized!
Type : RegData
Data : 0
TAC Rating : 9
Category : Data Miner
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main\featurecontrol\feature_localmachine_lockdown
Value : iexplore.exe
Data : 0

Other Object Recognized!
Type : File
Data : DESKBAR.EXE-38CDF805.pf
TAC Rating : 7
Category : Malware
Comment :
Object : C:\WINDOWS\prefetch\



Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 3
Objects found so far: 41

00:00:04 Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:21:50.78
Objects scanned:215272
Objects identified:29
Objects ignored:0
New critical objects:29

AVG-Antivirus Log:
==================================================================
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 14:40:15 15/10/2006

+ Scan result:



C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116512.exe -> Adware.Look2Me : Cleaned.
C:\Program Files\Common Files\{84173296-095F-2057-1125-04100504002c}\services.dll -> Adware.Softomate : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116513.dll -> Adware.Softomate : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116514.exe -> Adware.Softomate : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116515.dll -> Adware.Softomate : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116511.exe -> Adware.SurfSide : Cleaned.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\GPUNOLQ7\1[1].exe -> Backdoor.Small.ml : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116505.exe -> Backdoor.Small.ml : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116506.exe -> Backdoor.Small.ml : Cleaned.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ST6ZWXEV\drsmartload815a[1].exe -> Downloader.Adload.fu : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116504.exe -> Downloader.Adload.fu : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116509.exe -> Downloader.Adload.gk : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116510.exe -> Downloader.Adload.gk : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP236\A0116595.exe -> Downloader.Adload.gp : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP236\A0116594.exe -> Downloader.Adload.gr : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116507.exe -> Downloader.Banload.bni : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116508.exe -> Downloader.Banload.bni : Cleaned.
:mozilla.40:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.41:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.42:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.15:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.16:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.17:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.18:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.19:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.21:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.


::Report end

HijackThis Log
==================================================================
Logfile of HijackThis v1.99.1
Scan saved at 16:59:40, on 15/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\kybrdff_e29.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\PuTTY\pageant.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
E:\Sources\_PC Security\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://messenger.msn.com/flash/?mkt=en-gb&…ersion=7,0,19,0
R3 - URLSearchHook: (no name) - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{34173296-095F-2057-1125-04100504002c}\MyToolBar.dll (file missing)
O2 - BHO: Burn4Free Toolbar Helper - {F8E5CA21-C27B-43e7-B2BE-4CA93C9F9A1F} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
O3 - Toolbar: Burn4Free Toolbar - {70DE7956-479D-4eb7-8641-2B45774C350E} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{34173296-095F-2057-1125-04100504002c}\MyToolBar.dll (file missing)
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e29.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [strmfilt] C:\WINDOWS\system32\strmfilt.exe
O4 - HKCU\..\Run: [kbdest] C:\WINDOWS\system32\kbdest.exe
O4 - HKCU\..\Run: [wmpasf] C:\WINDOWS\system32\wmpasf.exe
O4 - HKCU\..\Run: [FIREFOX] C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
O4 - HKCU\..\Run: [wshirda] C:\WINDOWS\system32\wshirda.exe
O4 - HKCU\..\Run: [ddrawex] C:\WINDOWS\system32\ddrawex.exe
O4 - HKCU\..\Run: [prflbmsg] C:\WINDOWS\system32\prflbmsg.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
O4 - Global User Startup: Bluetooth Manager.lnk = ?
O4 - Global User Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache - Unknown owner - C:\Program Files\IBserver\apache\Apache.exe" –ntservice (file missing)
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: batt.exe - Unknown owner - C:\WINDOWS\system32\batt.exe
O23 - Service: dxmasf.exe - Unknown owner - C:\WINDOWS\system32\dxmasf.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: mqutil.exe - Unknown owner - C:\WINDOWS\system32\mqutil.exe (file missing)
O23 - Service: MySql - Unknown owner - C:\Program Files\IBserver\mysql\bin\mysqld-opt.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: nvwimg.exe - Unknown owner - C:\WINDOWS\system32\nvwimg.exe (file missing)
O23 - Service: unzip32.exe - Unknown owner - C:\WINDOWS\system32\unzip32.exe (file missing)




Many Thanks, Any help greatly appreciated.

David
OK - Spoftomate is back again and deskbar.exe and a bunch of other .exe files in the root of my C:drive (which I've deleted) and this Project1 thing in Task Manager!

Please help me.

Here's another HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 23:16:45, on 16/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\PuTTY\pageant.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
E:\Sources\_PC Security\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://messenger.msn.com/flash/?mkt=en-gb&…ersion=7,0,19,0
R3 - URLSearchHook: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll (file missing)
O2 - BHO: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{34173296-095F-2057-1125-04100504002c}\MyToolBar.dll (file missing)
O2 - BHO: Burn4Free Toolbar Helper - {F8E5CA21-C27B-43e7-B2BE-4CA93C9F9A1F} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
O3 - Toolbar: Burn4Free Toolbar - {70DE7956-479D-4eb7-8641-2B45774C350E} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{34173296-095F-2057-1125-04100504002c}\MyToolBar.dll (file missing)
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [keyboard] c:\\kybrdff_e31.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [defender] c:\\dfndrff_e31.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [strmfilt] C:\WINDOWS\system32\strmfilt.exe
O4 - HKCU\..\Run: [kbdest] C:\WINDOWS\system32\kbdest.exe
O4 - HKCU\..\Run: [wmpasf] C:\WINDOWS\system32\wmpasf.exe
O4 - HKCU\..\Run: [FIREFOX] C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
O4 - HKCU\..\Run: [wshirda] C:\WINDOWS\system32\wshirda.exe
O4 - HKCU\..\Run: [ddrawex] C:\WINDOWS\system32\ddrawex.exe
O4 - HKCU\..\Run: [prflbmsg] C:\WINDOWS\system32\prflbmsg.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
O4 - Global User Startup: Bluetooth Manager.lnk = ?
O4 - Global User Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache - Unknown owner - C:\Program Files\IBserver\apache\Apache.exe" –ntservice (file missing)
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: batt.exe - Unknown owner - C:\WINDOWS\system32\batt.exe
O23 - Service: dxmasf.exe - Unknown owner - C:\WINDOWS\system32\dxmasf.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: mqutil.exe - Unknown owner - C:\WINDOWS\system32\mqutil.exe (file missing)
O23 - Service: MySql - Unknown owner - C:\Program Files\IBserver\mysql\bin\mysqld-opt.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: nvwimg.exe - Unknown owner - C:\WINDOWS\system32\nvwimg.exe (file missing)
O23 - Service: unzip32.exe - Unknown owner - C:\WINDOWS\system32\unzip32.exe (file missing)

Cheers

David

(Please Help!)
AVG is still finding Softomate and now also "Backdoor.Small.ml" in C:\WINDOWS\explorer.exe, which I've instructed it to clean. Cheers David
David :D

Welcome to Tom Coyote, sorry about the delay , but you kept replying to yourself and it took you out of the posts we search for with Zero replies.

You have quite an array of infections going on, lets do this one first.


Please download ComboFix from either of these two locations

BleepingComputerComboFix
TechSupportForumComboFix
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


Post back with the Combofix log and a new HJT log please.
I wondered if replying to myself would do that! I couldn't find a way to edit my own post though.

Thanks for the instructions.

Here's the Combofix log:

David - 06-10-19 23:09:13.78 Service Pack 2
ComboFix 06.10.19 - Running from: "E:\Sources\_PC Security\Combofix"

((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\David\Application Data\Dxcdmns.dll
C:\Documents and Settings\David\Application Data\Dxcknwrd.dll
C:\Documents and Settings\David\Application Data\Dxcuknwrd.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\drsmartload815a.exe
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E16B230N\dfndrff_e[1].exe
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E16B230N\drsmartload815a[1].exe
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\WPEV09UL\deskbar_e[1].exe
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\M5GD0ZY1\kybrdff_e[1].exe
C:\Program Files\Deskbar
C:\Program Files\Common Files\{34173296-095F-2057-1125-04100504002c}
C:\Program Files\Common Files\{84173296-095F-2057-1125-04100504002c}


((((((((((((((((((((((((((((((( Files Created from 2006-09-19 to 2006-10-19 ))))))))))))))))))))))))))))))))))


2006-10-19 09:00 18,944 –a—— C:\Documents and Settings\David\UQPT.exe
2006-10-17 09:11 74,240 –a—— C:\WINDOWS\system32\2.exe
2006-10-17 09:11 45,056 –a—— C:\WINDOWS\system32\QHKN.exe
2006-10-17 09:11 45,056 –a—— C:\WINDOWS\system32\DDAN.exe
2006-10-17 08:55 45,056 –a—— C:\Documents and Settings\David\BUEK.exe
2006-10-17 00:08 48,640 –a—— C:\Documents and Settings\David\7.exe
2006-10-17 00:08 45,056 –a—— C:\WINDOWS\system32\JHDE.exe
2006-10-17 00:07 45,056 –a—— C:\Documents and Settings\David\FLCL.exe
2006-10-16 23:19 720,896 –a—— C:\WINDOWS\iun6002.exe
2006-10-16 23:10 45,056 –a—— C:\Documents and Settings\David\KNRL.exe
2006-10-14 23:27 45,056 –a—— C:\WINDOWS\system32\PAMJ.exe
2006-10-14 23:27 35,591 –a—— C:\WINDOWS\system32\prflbmsg.exe
2006-10-14 23:07 45,056 –a—— C:\Documents and Settings\David\OGCL.exe
2006-10-13 19:49 45,056 –a—— C:\Documents and Settings\David\GFOR.exe
2006-10-13 15:13 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-10-13 13:39 45,056 –a—— C:\WINDOWS\system32\ODJB.exe
2006-10-13 13:39 35,591 –a—— C:\WINDOWS\system32\ddrawex.exe
2006-10-13 13:38 45,056 –a—— C:\Documents and Settings\David\BHJU.exe
2006-10-13 13:38 35,079 –a—— C:\WINDOWS\system32\umdmxfrm.exe
2006-10-13 00:02 45,056 –a—— C:\Documents and Settings\David\BBNS.exe
2006-10-12 23:37 45,056 –a—— C:\WINDOWS\system32\ELJA.exe
2006-10-12 23:37 35,591 –a—— C:\WINDOWS\system32\wshirda.exe
2006-10-12 23:37 35,079 –a—— C:\WINDOWS\system32\batt.exe
2006-10-12 23:36 45,056 –a—— C:\Documents and Settings\David\EMPA.exe
2006-10-12 13:30 24,576 –a—— C:\Documents and Settings\David\JFQO.exe
2006-10-12 11:36 24,576 –a—— C:\Documents and Settings\David\GULC.exe
2006-10-12 10:17 35,591 –a—— C:\WINDOWS\system32\wmpasf.exe
2006-10-12 10:17 24,576 –a—— C:\WINDOWS\system32\AHRN.exe
2006-10-12 09:40 24,576 –a—— C:\Documents and Settings\David\SLCI.exe
2006-10-10 21:51 35,591 –a—— C:\WINDOWS\system32\strmfilt.exe
2006-10-10 21:51 115,947 –a—— C:\WINDOWS\system32\5.exe
2006-10-01 22:12 42 –a—— C:\WINDOWS\system32\nt32200ax.dll
2006-10-01 22:12 32 –a—— C:\WINDOWS\ntcheck3232bx.dll
2006-09-25 22:11 356,352 –a—— C:\WINDOWS\eSellerateEngine.dll
2006-09-25 11:05 73,216 –a—— C:\WINDOWS\ST6UNST.EXE
2006-09-25 11:05 249,856 ——— C:\WINDOWS\Setup1.exe
2006-09-25 10:06 202,240 C:\WINDOWS\system32AIT screensaver.scr


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-19 23:09 ——– d——– C:\Program Files\Common Files
2006-10-19 22:47 ——– d——– C:\Program Files\Mozilla Firefox
2006-10-18 09:38 ——– d——– C:\Program Files\Mozilla Thunderbird
2006-10-16 23:33 ——– d——– C:\Program Files\Word Search Factory
2006-10-13 19:50 71800 –a—— C:\Documents and Settings\David\Application Data\GDIPFONTCACHEV1.DAT
2006-10-13 15:13 ——– d——– C:\Program Files\Grisoft
2006-10-13 13:43 ——– d——– C:\Program Files\Lavasoft
2006-10-13 13:43 ——– d——– C:\Documents and Settings\David\Application Data\Lavasoft
2006-10-13 00:02 ——– d——– C:\Program Files\InterMute
2006-10-10 22:32 ——– d——– C:\Documents and Settings\David\Application Data\InterVideo
2006-10-09 11:13 ——– d——– C:\Program Files\outlookDuplicates
2006-10-09 10:40 ——– d——– C:\Program Files\Jeyo Mobile Extender for Outlook
2006-10-09 10:36 9354 –a—— C:\Documents and Settings\David\Application Data\Comma Separated Values (Windows).EML
2006-10-05 23:43 ——– d——– C:\Program Files\Periscope
2006-10-03 23:04 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-10-03 23:00 ——– d——– C:\Program Files\RD Wireless, Inc
2006-10-03 22:59 ——– d——– C:\Program Files\PowerPoint Controller
2006-10-03 19:47 ——– dr-h—– C:\Program Files\rnamfler
2006-10-03 15:02 ——– d——– C:\Program Files\NetMeeting
2006-10-03 14:55 ——– dr-h—– C:\Program Files\rnamfler.old
2006-10-02 23:29 ——– d——– C:\Program Files\Synergy Solutions
2006-10-02 19:05 ——– d——– C:\Program Files\Microsoft ActiveSync
2006-10-01 17:25 42 –a—— C:\WINDOWS\system32\nt32200ax1.dll
2006-10-01 17:25 32 –a—— C:\WINDOWS\ntcheck3232bx1.dll
2006-10-01 14:16 ——– d——– C:\Program Files\Toshiba
2006-09-30 00:31 ——– d—s—- C:\Documents and Settings\David\Application Data\Microsoft
2006-09-30 00:07 ——– d——– C:\Program Files\Internet Explorer
2006-09-29 23:38 ——– d——– C:\Program Files\Common Files\Microsoft Shared
2006-09-28 10:45 2508 –a—— C:\Documents and Settings\David\Application Data\$_hpcst$.hpc
2006-09-28 09:37 ——– d——– C:\Documents and Settings\David\Application Data\SpamBayes
2006-09-25 22:11 ——– d——– C:\Documents and Settings\David\Application Data\Salling Software AB
2006-09-25 16:45 666240 –a—— C:\WINDOWS\system32\aswBoot.exe
2006-09-25 16:40 87424 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2006-09-25 16:40 85952 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2006-09-25 16:39 36176 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2006-09-25 16:39 16352 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2006-09-25 16:37 90112 –a—— C:\WINDOWS\system32\AVASTSS.scr
2006-09-25 16:37 24560 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2006-09-25 11:17 ——– d——– C:\Documents and Settings\David\Application Data\Sync App Settings
2006-09-25 11:05 ——– d——– C:\Program Files\DirSizeView
2006-09-25 11:01 ——– d——– C:\Program Files\Allway Sync
2006-09-25 10:06 202240 –a—— C:\WINDOWS\system32\AIT screensaver.scr
2006-09-15 22:29 ——– d——– C:\Program Files\Eraser
2006-09-15 19:07 ——– d——– C:\Program Files\Musicmatch
2006-09-15 18:59 ——– d——– C:\Documents and Settings\David\Application Data\Musicmatch
2006-09-15 18:55 503808 –a—— C:\WINDOWS\system32\msvcp71.dll
2006-09-15 18:55 348160 –a—— C:\WINDOWS\system32\msvcr71.dll
2006-09-13 06:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll
2006-09-11 20:33 ——– d——– C:\Program Files\Burn4Free
2006-09-11 10:29 ——– d——– C:\Program Files\Slovak Technical Services
2006-08-25 16:45 617472 –a—— C:\WINDOWS\system32\comctl32.dll
2006-08-21 13:21 16896 –a—— C:\WINDOWS\system32\fltlib.dll
2006-08-21 10:14 23040 –a—— C:\WINDOWS\system32\fltmc.exe
2006-08-21 10:14 128896 ——— C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-16 14:57 22426 –a—— C:\Documents and Settings\David\Application Data\Microsoft Excel.ADR
2006-08-16 12:58 100352 –a—— C:\WINDOWS\system32\6to4svc.dll
2006-07-27 14:24 679424 –a—— C:\WINDOWS\system32\inetcomm.dll
2006-07-21 09:24 72704 –a—— C:\WINDOWS\system32\hlink.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"H/PC Connection Agent"="\"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe\""
"strmfilt"="C:\\WINDOWS\\system32\\strmfilt.exe"
"kbdest"="C:\\WINDOWS\\system32\\kbdest.exe"
"wmpasf"="C:\\WINDOWS\\system32\\wmpasf.exe"
"FIREFOX"="C:\\PROGRA~1\\MOZILL~1\\FIREFOX.EXE"
"wshirda"="C:\\WINDOWS\\system32\\wshirda.exe"
"ddrawex"="C:\\WINDOWS\\system32\\ddrawex.exe"
"prflbmsg"="C:\\WINDOWS\\system32\\prflbmsg.exe"
"nvrsel"="C:\\WINDOWS\\system32\\nvrsel.exe"
"msvcrt"="C:\\WINDOWS\\system32\\msvcrt.exe"
"paqsp"="C:\\WINDOWS\\system32\\paqsp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SiSUSBRG"="C:\\WINDOWS\\SiSUSBrg.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"type32"="\"C:\\Program Files\\Microsoft IntelliType Pro\\type32.exe\""
"IntelliPoint"="\"C:\\Program Files\\Microsoft IntelliPoint\\point32.exe\""
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,96,00,00,00,00,00,00,00,6a,04,00,00,e2,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,03,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,03,\
00,00,01,00,00,00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

Completion time: 06-10-19 23:11:23.71
C:\ComboFix.txt … 06-10-19 23:11


And here's a fresh HJT:

Logfile of HijackThis v1.99.1
Scan saved at 23:14:08, on 19/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\PuTTY\pageant.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
E:\Sources\_PC Security\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://messenger.msn.com/flash/?mkt=en-gb&…ersion=7,0,19,0
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{34173296-095F-2057-1125-04100504002c}\MyToolBar.dll (file missing)
O2 - BHO: Burn4Free Toolbar Helper - {F8E5CA21-C27B-43e7-B2BE-4CA93C9F9A1F} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
O3 - Toolbar: Burn4Free Toolbar - {70DE7956-479D-4eb7-8641-2B45774C350E} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{34173296-095F-2057-1125-04100504002c}\MyToolBar.dll (file missing)
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [strmfilt] C:\WINDOWS\system32\strmfilt.exe
O4 - HKCU\..\Run: [kbdest] C:\WINDOWS\system32\kbdest.exe
O4 - HKCU\..\Run: [wmpasf] C:\WINDOWS\system32\wmpasf.exe
O4 - HKCU\..\Run: [FIREFOX] C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
O4 - HKCU\..\Run: [wshirda] C:\WINDOWS\system32\wshirda.exe
O4 - HKCU\..\Run: [ddrawex] C:\WINDOWS\system32\ddrawex.exe
O4 - HKCU\..\Run: [prflbmsg] C:\WINDOWS\system32\prflbmsg.exe
O4 - HKCU\..\Run: [nvrsel] C:\WINDOWS\system32\nvrsel.exe
O4 - HKCU\..\Run: [msvcrt] C:\WINDOWS\system32\msvcrt.exe
O4 - HKCU\..\Run: [paqsp] C:\WINDOWS\system32\paqsp.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
O4 - Global User Startup: Bluetooth Manager.lnk = ?
O4 - Global User Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache - Unknown owner - C:\Program Files\IBserver\apache\Apache.exe" –ntservice (file missing)
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: batt.exe - Unknown owner - C:\WINDOWS\system32\batt.exe
O23 - Service: dxmasf.exe - Unknown owner - C:\WINDOWS\system32\dxmasf.exe (file missing)
O23 - Service: fdeploy.exe - Unknown owner - C:\WINDOWS\system32\fdeploy.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: mqutil.exe - Unknown owner - C:\WINDOWS\system32\mqutil.exe (file missing)
O23 - Service: MySql - Unknown owner - C:\Program Files\IBserver\mysql\bin\mysqld-opt.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: nvwimg.exe - Unknown owner - C:\WINDOWS\system32\nvwimg.exe (file missing)
O23 - Service: unzip32.exe - Unknown owner - C:\WINDOWS\system32\unzip32.exe (file missing)

Cheers

David
David, :D

I wondered if replying to myself would do that! Not a problem, :D but this is the way most forums work, I know its frustrating but sometimes you need to just kick back and wait. We are so busy on this forum that most times we don't get to a log for 3 or 4 days after there posted.

We are making some headway but still lots to do. You may want to print this all out because we will be offlne for part of the fix.


Are you aware of this? Is this a program that you knowingly installed.

Finding a program by the name of iun6002.exe running on your computer is usually a sign that you may have a spyware program known as 'desktop surveillance personal' installed on your computer. This process was potentially installed manually by a user using an installation package (possibly with another application). The 'desktop surveillance personal' process may perform actions such as recording your key-strokes and taking screen-shots



We need to make sure all hidden files are showing :
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide file extensions for known types option.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Once your system is clean, we suggest that you reverse this to keep critical windows files from accidently being deleted.





Download the Stand Alone Version of CWShredder to your desktop.
  • Open CWShredder
  • Check for Updates
  • Close out the program. <– Dont run it yet






    Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop.
    • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
    • Once the setup is complete you will need run Ewido and update the definition files.
    • On the main screen select the icon Update then select the Update now link.
    • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
    • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
    • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
    • Under Reports
    • Select Automatically generate report after every scan
    • Un-Select Only if threats were found
    • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.






    Look for these services and disable them

    dxmasf.exe
    fdeploy.exe
    mqutil.exe
    nvwimg.exe

    • Go to Start> Run and type in services.msc then press Enter
    • Scroll down to All services in the quote
    • Double Click that service to open it.
    • Click on Stop Service.
    • Then change the Startup Type to Disabled.
    • OK your way out of the program.




    Open HJT Scan Only, make sure your browser and all open windows are closed, check these and click on Fix Checked.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com

    O2 - BHO: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{34173296-095F-2057-1125-04100504002c}\MyToolBar.dll (file missing)
    O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{34173296-095F-2057-1125-04100504002c}\MyToolBar.dll (file missing)

    O4 - HKCU\..\Run: [strmfilt] C:\WINDOWS\system32\strmfilt.exe
    O4 - HKCU\..\Run: [kbdest] C:\WINDOWS\system32\kbdest.exe
    O4 - HKCU\..\Run: [wmpasf] C:\WINDOWS\system32\wmpasf.exe
    O4 - HKCU\..\Run: [wshirda] C:\WINDOWS\system32\wshirda.exe
    O4 - HKCU\..\Run: [ddrawex] C:\WINDOWS\system32\ddrawex.exe
    O4 - HKCU\..\Run: [prflbmsg] C:\WINDOWS\system32\prflbmsg.exe
    O4 - HKCU\..\Run: [nvrsel] C:\WINDOWS\system32\nvrsel.exe
    O4 - HKCU\..\Run: [msvcrt] C:\WINDOWS\system32\msvcrt.exe
    O4 - HKCU\..\Run: [paqsp] C:\WINDOWS\system32\paqsp.exe

    O23 - Service: dxmasf.exe - Unknown owner - C:\WINDOWS\system32\dxmasf.exe (file missing)
    O23 - Service: fdeploy.exe - Unknown owner - C:\WINDOWS\system32\fdeploy.exe (file missing)
    O23 - Service: mqutil.exe - Unknown owner - C:\WINDOWS\system32\mqutil.exe (file missing)
    O23 - Service: nvwimg.exe - Unknown owner - C:\WINDOWS\system32\nvwimg.exe (file missing)





    Boot your computer into Safemode
    • Go to Start> Shut Off your Computer> Restart
    • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
    • This will bring up a menu.
    • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
    • Then press the Enter on your Keyboard
    IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning process:
    • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
    • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
    • Ewido will now begin the scanning process, be patient this may take a little time.
    • Once the scan is complete do the following:
    • If you have any infections you will prompted, then select Apply all actions
    • Next select the Reports icon at the top.
    • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
    • make sure to remember where you saved that file, this is important
    • Close AVG Anti-Spyware 7.5




    Open CWShredder
  • Double-click on CWShredder.exe.
  • Click Fix and click OK at the prompt.
  • CWShredder will scan and clean your system of CWS files.
  • Click Next and then Exit .



Still in safemode, look for these files and delete them.

C:\Program Files\Common Files\{34173296-095F-2057-1125-04100504002c}

C:\WINDOWS\system32\ddrawex.exe
C:\WINDOWS\system32\dxmasf.exe
C:\WINDOWS\system32\fdeploy.exe
C:\WINDOWS\system32\kbdest.exe
C:\WINDOWS\system32\msvcrt.exe
C:\WINDOWS\system32\mqutil.exe
C:\WINDOWS\system32\nvrsel.exe
C:\WINDOWS\system32\nvwimg.exe
C:\WINDOWS\system32\paqsp.exe
C:\WINDOWS\system32\prflbmsg.exe
C:\WINDOWS\system32\strmfilt.exe
C:\WINDOWS\system32\wmpasf.exe
C:\WINDOWS\system32\wshirda.exe




Reboot normally and run this system cleaner.

Please download ATF Cleaner by Atribune.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.



I need you to post the log from AVG and a new HJT log please.
OK - Followed your instructions - here are some differences:

Look for these services and disable them


dxmasf.exe
fdeploy.exe
mqutil.exe
nvwimg.exe

Found those for services - none of them were actually started, so I just had to disable them.

O23 - Service: dxmasf.exe - Unknown owner - C:\WINDOWS\system32\dxmasf.exe (file missing)
O23 - Service: fdeploy.exe - Unknown owner - C:\WINDOWS\system32\fdeploy.exe (file missing)
O23 - Service: mqutil.exe - Unknown owner - C:\WINDOWS\system32\mqutil.exe (file missing)
O23 - Service: nvwimg.exe - Unknown owner - C:\WINDOWS\system32\nvwimg.exe (file missing)

These enteries weren't present in the HJT this log - so I couldn't check and fix them (perhaps because they were disabled>)

Open CWShredder

  • Double-click on CWShredder.exe.
  • Click Fix and click OK at the prompt.
  • CWShredder will scan and clean your system of CWS files.
  • Click Next and then Exit .
  • CoolWebSearch not found on the system.

    Still in safemode, look for these files and delete them.
    C:\Program Files\Common Files\{34173296-095F-2057-1125-04100504002c}

    Not there to be deleted

    C:\WINDOWS\system32\ddrawex.exe
    C:\WINDOWS\system32\dxmasf.exe
    C:\WINDOWS\system32\fdeploy.exe
    C:\WINDOWS\system32\kbdest.exe
    C:\WINDOWS\system32\msvcrt.exe
    C:\WINDOWS\system32\mqutil.exe
    C:\WINDOWS\system32\nvrsel.exe
    C:\WINDOWS\system32\nvwimg.exe
    C:\WINDOWS\system32\paqsp.exe
    C:\WINDOWS\system32\prflbmsg.exe
    C:\WINDOWS\system32\strmfilt.exe
    C:\WINDOWS\system32\wmpasf.exe
    C:\WINDOWS\system32\wshirda.exe

    dxmasf.exe, fdeploy.exe and nvrsel.exe weren't there to be deleted.
    They all had a .dll of the same name - should those be deleted too?

    Here's the AGV-Anti:

    ———————————————————
    AVG Anti-Spyware - Scan Report
    ———————————————————

    + Created at: 08:31:16 20/10/2006

    + Scan result:



    C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP236\A0116673.exe -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP236\A0116674.exe -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP236\A0116679.dll -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP237\A0116792.dll -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP237\A0116793.exe -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP237\A0116794.dll -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP238\A0116848.dll -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP239\A0116914.exe -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP239\A0116961.dll -> Adware.Softomate : Cleaned with backup (quarantined).
    HKU\S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A8B28872-3324-4CD2-8AA3-7D555C872D96} -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\2.exe -> Backdoor.Small.ml : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP239\A0116956.exe -> Downloader.Adload.fu : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP232\A0115887.exe -> Downloader.Adload.gj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP237\A0116744.exe -> Downloader.Adload.gt : Cleaned with backup (quarantined).
    :mozilla.203:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.95:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.96:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.124:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.125:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.126:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.127:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.128:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.129:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.97:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.98:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.10:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Com : Cleaned.
    :mozilla.11:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Com : Cleaned.
    :mozilla.12:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Com : Cleaned.
    :mozilla.87:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Com : Cleaned.
    :mozilla.8:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Com : Cleaned.
    :mozilla.9:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Com : Cleaned.
    :mozilla.148:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
    :mozilla.149:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
    :mozilla.150:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
    :mozilla.151:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
    :mozilla.155:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
    :mozilla.143:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.38:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.39:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.40:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.46:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.


    ::Report end

    And here's a latest HJT Log:

    Logfile of HijackThis v1.99.1
    Scan saved at 08:56:01, on 20/10/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\PROGRA~1\MI3AA1~1\rapimgr.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
    C:\Program Files\PuTTY\pageant.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    E:\Sources\_PC Security\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://messenger.msn.com/flash/?mkt=en-gb&…ersion=7,0,19,0
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Burn4Free Toolbar Helper - {F8E5CA21-C27B-43e7-B2BE-4CA93C9F9A1F} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
    O3 - Toolbar: Burn4Free Toolbar - {70DE7956-479D-4eb7-8641-2B45774C350E} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
    O3 - Toolbar: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
    O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [FIREFOX] C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    O4 - Global Startup: Bluetooth Manager.lnk = ?
    O4 - Global Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
    O4 - Global User Startup: Bluetooth Manager.lnk = ?
    O4 - Global User Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apache - Unknown owner - C:\Program Files\IBserver\apache\Apache.exe" –ntservice (file missing)
    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: batt.exe - Unknown owner - C:\WINDOWS\system32\batt.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: MySql - Unknown owner - C:\Program Files\IBserver\mysql\bin\mysqld-opt.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: unzip32.exe - Unknown owner - C:\WINDOWS\system32\unzip32.exe (file missing)

    Many Thanks for your help.

    You guys are very good at writing clear explicit instructions!

    Cheers

    David
    David, :D

    We are almost 95% there. A few questions for you.

    No, these are unknown so lets just let them be.

    They all had a .dll of the same name - should those be deleted too?



    Remove this with HJT.
    O3 - Toolbar: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)

    Do you have the Firefox browser installed on your system, if not , remove this line also.
    O4 - HKCU\..\Run: [FIREFOX] C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

    You need to disable this service like you did before . batt.exe Then make sure this is gone., if not remove it
    O23 - Service: batt.exe - Unknown owner - C:\WINDOWS\system32\batt.exe

    This is related to an unziping utility, is it something you installed and know about, if not fix it.
    O23 - Service: unzip32.exe - Unknown owner - C:\WINDOWS\system32\unzip32.exe (file missing)



    AVG fixed a few things, you need to open that program and go to the Quarantne folder and delete it all, nothing in there we need to keep on your system.


    After your done, I would like you to run Panda, its a free online scan, it won't fix anything but I need to see the report along with a new HJT log .
    Panda ActiveScan <—-Accept default settings

    David, :D

    We are almost 95% there. A few questions for you.

    Cool - thanks for all this - you saviours!

    Remove this with HJT.
    O3 - Toolbar: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)

    Done

    Do you have the Firefox browser installed on your system, if not , remove this line also.
    O4 - HKCU\..\Run: [FIREFOX] C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

    I do have Firefox
    I think this problem started because some website that was potentialy going to give me an MP3 told me I needed to use IE to browse the site! - bah. :-(

    You need to disable this service like you did before . batt.exe Then make sure this is gone., if not remove it
    O23 - Service: batt.exe - Unknown owner - C:\WINDOWS\system32\batt.exe

    Services wasn't runnin - disabled it and then it was no longer in HJT log.

    This is related to an unziping utility, is it something you installed and know about, if not fix it.
    O23 - Service: unzip32.exe - Unknown owner - C:\WINDOWS\system32\unzip32.exe (file missing)

    I don't remember installing any 3rd party unzippers so I got rid of it (then HJT asked for a restart so I did.

    AVG fixed a few things, you need to open that program and go to the Quarantne folder and delete it all, nothing in there we need to keep on your system.

    Done

    After your done, I would like you to run Panda, its a free online scan, it won't fix anything but I need to see the report along with a new HJT log .

    Well - I started Pandascan (having worked out it wanted IE not FF!)
    And as it was downloading the ActiveScan ActiveX control, avast! AV flagged up that it contained a virus:
    Filename looked like the URL from where it was coming.
    Malware name: W32:CTX Virus/Worm
    VPS Version 0642-4, 20/10/2006

    So I aborted that connection and obviously Panda didn't run.

    Can you advise?

    Here's an HJT Log:
    Logfile of HijackThis v1.99.1
    Scan saved at 13:22:55, on 20/10/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\PROGRA~1\MI3AA1~1\rapimgr.exe
    C:\Program Files\PuTTY\pageant.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
    E:\Sources\_PC Security\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://messenger.msn.com/flash/?mkt=en-gb&…ersion=7,0,19,0
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Burn4Free Toolbar Helper - {F8E5CA21-C27B-43e7-B2BE-4CA93C9F9A1F} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
    O3 - Toolbar: Burn4Free Toolbar - {70DE7956-479D-4eb7-8641-2B45774C350E} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
    O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [FIREFOX] C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    O4 - Global Startup: Bluetooth Manager.lnk = ?
    O4 - Global Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
    O4 - Global User Startup: Bluetooth Manager.lnk = ?
    O4 - Global User Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apache - Unknown owner - C:\Program Files\IBserver\apache\Apache.exe" –ntservice (file missing)
    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: MySql - Unknown owner - C:\Program Files\IBserver\mysql\bin\mysqld-opt.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    Thanks again

    David

    And as it was downloading the ActiveScan ActiveX control, avast! AV flagged up that it contained a virus:

    Never ran into this before, I wonder if it flagged the virus definition files that it uses to scan your system.



    What can you tell me about this?

    C:\Program Files\PuTTY\pageant.exe





    • Your Java is out of date and leaving your system vulnerable.
    • Go to your Add-Remove Programs in the Control Panel and uninstall any previous versions of Java (J2SE Runtime Environment)
    • It should have an icon next to it:
      [external image: Posted Image]
      Select it and click Remove.
    • Reboot your system.
    • Then go to the Sun Java website and download and install the update.
    • Java Runtime Environment (JRE) 5.0 Update 9 <–This is what you need to download and install.
    • Then after install you can verify your installation here Sun Java Verify

    The rest of your log looks fine :thumbup: How are things running now??
    C:\Program Files\PuTTY\pageant.exe is a sys tray program for launching Putty the ssh client Shall I disable AV and run ActiveScan? Will carry on with the Java thing after the w/e I;ve got to go and run a youth weekend now! System doesn't seem to be showing signs of illness. I'll post again after the w/e Many Thanks David
    David, :D I will be gone for the weekend also, so will check back with you on Monday. Panda is one of the leading AV software companies in the world, I have been at this for over 3 years and yours was the first that I have ever come accross. Panda used to clean up bad entries real well but they discontinued that about a year ago, they will still let you run a scan and the report is pretty impressive, if there is still something lurking on your system, Panda will find it. Go ahead and disable your AV and give Panda another shot. Ken
    Re Panda and Avast: http://www.avast.com/eng/faq_panda.html

    One odd bit of behaviour - Firefox seems to be launching at startup - just noticed that's in the registry for Run - no idea how it got there! Bah

    Here's the Panda Scan

    Incident Status Location

    Adware:adware/dollarrevenue Not disinfected c:\windows\keyboard1.dat
    Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt[.toplist.cz/]
    Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt[.2o7.net/]
    Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt[.adtech.de/]
    Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\David\Cookies\david@2o7[1].txt
    Adware:Adware/Maxifiles Not disinfected C:\WINDOWS\system32\5.exe
    Virus:Eicar.Mod Renamed E:\David's Data Archive\Sites\Archive\DavidJeanneret.co.zip[DavidJeanneret.co.uk/useful/virus.txt]
    Virus:W32/Netsky.D.worm Disinfected Archive Folders\Deleted Items\Re: Hello\your_picture.pif
    Virus:W32/Netsky.D.worm Disinfected Archive Folders\Deleted Items\Re: Your text\your_text.pif
    Virus:W32/Netsky.D.worm Disinfected Archive Folders\Deleted Items\Re: Your bill\your_bill.pif
    Virus:W32/Netsky.D.worm Disinfected Archive Folders\Deleted Items\Re: Here\yours.pif
    Virus:EICAR-AV-TEST-FILE Disinfected Archive Folders\Sent Items\RE: Just testing\virus.exe
    Virus:EICAR-AV-TEST-FILE Disinfected Archive Folders\Sent Items\Just testing\virus.txt
    Virus:EICAR-AV-TEST-FILE Disinfected Archive Folders\Sent Items\virus.com\virus.com
    Virus:EICAR-AV-TEST-FILE Disinfected Archive Folders\Sent Items\virus.txt\virus.txt
    Virus:Trj/Mitglieder.FN Disinfected David\Deleted Items\text_sms.zip[1.exe]
    Virus:Trj/Mitglieder.GB Disinfected David\Deleted Items\Harry\Cybil.zip[1.exe]
    Virus:Trj/Mitglieder.GO Disinfected David\Deleted Items\Roberte\Nycholas.zip[S3700026.exe]
    Virus:Eicar.Mod Renamed E:\Documents and Settings\David\My Documents\Admin\virus.txt


    And here's another HJT Log:

    Logfile of HijackThis v1.99.1
    Scan saved at 01:29:02, on 23/10/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\PROGRA~1\MI3AA1~1\rapimgr.exe
    C:\Program Files\PuTTY\pageant.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    E:\Sources\_PC Security\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://messenger.msn.com/flash/?mkt=en-gb&…ersion=7,0,19,0
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: Burn4Free Toolbar Helper - {F8E5CA21-C27B-43e7-B2BE-4CA93C9F9A1F} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
    O3 - Toolbar: Burn4Free Toolbar - {70DE7956-479D-4eb7-8641-2B45774C350E} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
    O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [FIREFOX] C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    O4 - Global Startup: Bluetooth Manager.lnk = ?
    O4 - Global Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
    O4 - Global User Startup: Bluetooth Manager.lnk = ?
    O4 - Global User Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apache - Unknown owner - C:\Program Files\IBserver\apache\Apache.exe" –ntservice (file missing)
    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: MySql - Unknown owner - C:\Program Files\IBserver\mysql\bin\mysqld-opt.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    Cheers

    David

    Are we nearly there yet!

    Ask AI

    AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

    Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI