This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My hijack log

59 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

SPERSKY ONLINE SCANNER REPORT Monday, January 08, 2007 7:54:15 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 9/01/2007 Kaspersky Anti-Virus database records: 256920 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ H:\ I:\ Scan Statistics: Total number of scanned objects: 96006 Number of viruses found: 8 Number of infected objects: 18 / 0 Number of suspicious objects: 0 Duration of the scan process: 01:05:42 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Xodice\.housecall\Quarantine\i6A.tmp.bac_a02448 Infected: not-a-virus:AdWare.Win32.SurfSide.j skipped C:\Documents and Settings\Xodice\.housecall\Quarantine\pf78.exe.bac_a02812/data0002 Infected: Trojan-Downloader.Win32.VB.tw skipped C:\Documents and Settings\Xodice\.housecall\Quarantine\pf78.exe.bac_a02812/data0003 Infected: Trojan.Win32.VB.tg skipped C:\Documents and Settings\Xodice\.housecall\Quarantine\pf78.exe.bac_a02812/data0006 Infected: Trojan.Win32.VB.tg skipped C:\Documents and Settings\Xodice\.housecall\Quarantine\pf78.exe.bac_a02812/data0007 Infected: Trojan.Win32.VB.tg skipped C:\Documents and Settings\Xodice\.housecall\Quarantine\pf78.exe.bac_a02812 NSIS: infected - 4 skipped C:\Documents and Settings\Xodice\.housecall\Quarantine\pf78.exe.bac_a02812 CryptFF.b: infected - 4 skipped C:\Documents and Settings\Xodice\Application Data\Mozilla\Firefox\Profiles\mcdwn9rn.default\cert8.db Object is locked skipped C:\Documents and Settings\Xodice\Application Data\Mozilla\Firefox\Profiles\mcdwn9rn.default\formhistory.dat Object is locked skipped C:\Documents and Settings\Xodice\Application Data\Mozilla\Firefox\Profiles\mcdwn9rn.default\history.dat Object is locked skipped C:\Documents and Settings\Xodice\Application Data\Mozilla\Firefox\Profiles\mcdwn9rn.default\key3.db Object is locked skipped C:\Documents and Settings\Xodice\Application Data\Mozilla\Firefox\Profiles\mcdwn9rn.default\parent.lock Object is locked skipped C:\Documents and Settings\Xodice\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Xodice\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Xodice\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Xodice\Local Settings\Application Data\Mozilla\Firefox\Profiles\mcdwn9rn.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\Xodice\Local Settings\Application Data\Mozilla\Firefox\Profiles\mcdwn9rn.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\Xodice\Local Settings\Application Data\Mozilla\Firefox\Profiles\mcdwn9rn.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\Xodice\Local Settings\Application Data\Mozilla\Firefox\Profiles\mcdwn9rn.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\Xodice\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Xodice\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Xodice\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Xodice\NetHood\Desktop\Tom Coyote fixers\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Xodice\NetHood\Desktop\Tom Coyote fixers\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Xodice\NetHood\Desktop\Tom Coyote fixers\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Xodice\NetHood\Desktop\Tom Coyote fixers\SmitfraudFix.exe RarSFX: infected - 2 skipped C:\Documents and Settings\Xodice\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Xodice\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Xodice\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Program Files\HP\hpcoretech\hpcmerr.log Object is locked skipped C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped C:\Program Files\MSN Messenger\riched20.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{50516BC0-8C42-4A9C-8AA3-25C1E8FC0399}\RP872\A0237655.exe Infected: not-a-virus:AdWare.Win32.WinAD.i skipped C:\System Volume Information\_restore{50516BC0-8C42-4A9C-8AA3-25C1E8FC0399}\RP880\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped C:\WINDOWS\system32\f3PSSavr.scr Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\system32\YSB.exe/stream Infected: Trojan-Downloader.NSIS.Agent.a skipped C:\WINDOWS\system32\YSB.exe NSIS: infected - 1 skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped D:\System Volume Information\_restore{50516BC0-8C42-4A9C-8AA3-25C1E8FC0399}\RP880\change.log Object is locked skipped Scan process completed.
Logfile of HijackThis v1.99.1
Scan saved at 7:56:20 PM, on 1/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvraidservice.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Updater.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\LiveUpdate\LiveUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\hijack this\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\System32\nvraidservice.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [BTCLiveUpdate] "C:\Program Files\LiveUpdate\LiveUpdate.exe" /autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: D-Link AirPlus.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by23fd.bay23.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1168141373265
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
Hello Booberry,

Thanks for posting logs. Good work. We are making more progress now.
If you don't have any idea what thes files are or what programs use them
I need you to please do the following so we can check them out.

Please visit this link to upload file for scan virusscan.jotti.org click here
  • Click the Browse… button
  • Navigate to the following file C:\WINDOWS\system32\drivers\ev^gnmmn.sys
  • Click Open
  • Please post results in next reply.
Now do the same for this one unles you know what is.

Please visit this link to upload file for scan virusscan.jotti.org click here
  • Click the Browse… button
  • Navigate to the following file C:\WINDOWS\30.tmp
  • Click Open
  • Please post results in next reply.
————————————————————————-

This is to also check those files with a different scanner to be sure.

Please visit this link VIRUSTOTAL UPLOAD LINK
* Click the Browse… button
* Navigate to the file C:\WINDOWS\system32\drivers\ev^gnmmn.sys
* Click the Open button
* Click the Send button
* Copy and paste the results back here please.


Now do the same for this one

Please visit this link VIRUSTOTAL UPLOAD LINK
* Click the Browse… button
* Navigate to the file C:\WINDOWS\30.tmp
* Click the Open button
* Click the Send button
* Copy and paste the results back here please.


OK this is next:

1. Start Killbox place a tick next to [+]Delete on reboot
2. Press the ALL Files button <<<< This is important to hit the ALL FILES button now.
3. Copy this whole list into the windows clipboard, all the Bold below.

C:\Program Files\Common Files\VCClient\VCClient.exe
C:\Program Files\Common Files\VCClient\VCMain.exe
C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
C:\Program Files\MSN Messenger\riched20.dll
C:\WINDOWS\system32\YSB.exe

4. Back in Killbox go > file (Top left corner) > choose from drop down menu paste from clipboard.,
5. Click the red highlighted X button and say NO to the prompt to restart the pc.
Exit Killbox and restart Your PC.

If you get any messages or you think it didn't work it is ok continue with fix.
—————————————————————

You now have to manual navigate to like you did before to delete this folder only VCClient

Click on Start > then click on My Computer > C:\Program Files\Common Files\VCClient << folder to delete.

Click on Start > then click on My Computer > C:\WINDOWS\system32\f3PSSavr.scr << file to delete.


NOTE: If this folder will not delete in normal mode you can boot into safe mode and try again.

Reboot computer
——————————————————————-


Proper regfix to clear that entries: .

1. Please do this:
  • Copy the contents of the Quote Box below to Notepad make sure to just copy what is inside box nothing outside of it. (not Wordpad)
  • On file menu click Save as
  • Name the file as fix3.reg <<<< You must type exactly as shown period and all
  • Change the Save as Type to All Files (NOT as a txt file)
  • and Save it on the desktop
Quote:

REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CU1]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CU2]


Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.

2. Then double-click on the fix3.reg file icon should look like this [external image: Posted Image], that is on your desktop and when it prompts to merge say yes.

—————————————————————————

Please do the following:
  • Double click the CCleaner shortcut on the desktop to start the program.
  • On the Windows tab, under Internet Explorer,
  • All Boxes should have a check mark. (You will need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
  • On the Windows tab, under Windows Explorer,
  • All Boxes should have a check mark.
  • On the Windows tab, under System,
  • All Boxes should have a check mark.
  • On the Windows tab, under Advanced,
  • NO check marks
[*]If you use either the Firefox or Mozilla browsers, the box to put check in for "Cookies" is on the Applications tab, under Firefox/Mozilla. If already checked move to next step.

[*]Click on the "Options" icon at the left side of the window, then click on "Advanced."

deselect "Only delete files in Windows Temp folders older than 48 hours."
[*]Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.

[*]Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.

[*]After CCleaner has completed its process, click Exit.

[*]You will need to reboot here if not ask to do so.

_______________________________

  • Open AVG Anti-spyware program
  • Next to the words Last Update, click on Update now. (You will need an active internet connection to perform this)
  • Wait until you see the Update succesfull message.
  • Close AVG Anti-Spyware without running yet.
    Now disable (turn off AVG Anti-Spyware)
  • Right-click the AVG Anti-Spyware Tray Icon (Bottom right corner of computer screen near clock) and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon again and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update AVG Anti-Spyware.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________


Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
Note: If AVG Anti-Spyware screen does not fit your monitor screen Hold down the Alt button on keyboard then tap spacebar, menu should pop up then choose maximize. AVG Anti-Spyware screen should fix screen a little better.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
[external image: Posted Image]

IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
  • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
  • At the bottom of the window click on the Apply all Actions button.(3)
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
______________________________

Now Rerun combofix same has before

Next do the following:
1. Double click combofix.exe & follow the prompts.
2. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

———————————————–

Your version of Java is now outdated. Java vulnerabilites are commonly exploited by viruses. You need to update.

Download the latest version of Java Runtime Environment (JRE) 6
  • Scroll down to where it says "Java Runtime Environment (JRE) 6".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Click Start then Control Panel > then Add/Remove Programs and remove all older versions of Java.
  • Remove any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed to complete uninstall.
  • Then from your desktop double-click on jre-6-windows-i586.exe to install the newest version.
————————————————

Please post in your next reply to thread:
virusscan.jotti file scan results
VIRUSTOTAL file scan results
AVG Anti-Spyware
combofix log
new HJT log
i went to the virusscan.jotti.org and i don't know how i tell if it has scanned or if it is done??? Scanner Malware name AntiVir JOKE/Around joke ArcaVir X Avast Win32:Semnet AVG Antivirus X BitDefender X ClamAV X Dr.Web X F-Prot Antivirus X F-Secure Anti-Virus X Fortinet X Kaspersky Anti-Virus X NOD32 X Norman Virus Control X VirusBuster X VBA32 X This is what has shown up at the bottom of the page, but the red line at the top is still going and changing colors,is this what you need??
Hi Booberry Go to VIRUSTOTAL site and use that scanner instead for now I will check in to it. Some time those sites can take a while because they are very busy lot of other people running scans too.
Antivirus Version Update Result AntiVir 7.3.0.21 01.09.2007 no virus found Authentium 4.93.8 01.09.2007 no virus found Avast 4.7.892.0 12.30.2006 no virus found AVG 386 01.09.2007 no virus found BitDefender 7.2 01.10.2007 no virus found CAT-QuickHeal 9.00 01.09.2007 no virus found ClamAV devel-20060426 01.09.2007 no virus found DrWeb 4.33 01.09.2007 no virus found eSafe 7.0.14.0 01.09.2007 no virus found eTrust-InoculateIT 23.73.109 01.09.2007 no virus found eTrust-Vet 30.3.3313 01.09.2007 no virus found Ewido 4.0 01.09.2007 no virus found Fortinet 2.82.0.0 01.09.2007 no virus found F-Prot 3.16f 01.09.2007 no virus found F-Prot4 4.2.1.29 01.09.2007 no virus found Ikarus T3.1.0.27 01.09.2007 no virus found Kaspersky 4.0.2.24 01.10.2007 no virus found McAfee 4935 01.09.2007 no virus found Microsoft 1.1904 01.10.2007 no virus found NOD32v2 1968 01.09.2007 no virus found Norman 5.80.02 12.31.2007 no virus found Panda 9.0.0.4 01.09.2007 no virus found Prevx1 V2 01.10.2007 no virus found Sophos 4.13.0 01.05.2007 no virus found Sunbelt 2.2.907.0 01.05.2007 no virus found TheHacker [removed] 01.08.2007 no virus found UNA 1.83 01.10.2007 no virus found VBA32 3.11.2 01.09.2007 no virus found
——————————————————– AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 11:20:24 PM 1/9/2007 + Scan result: C:\System Volume Information\_restore{50516BC0-8C42-4A9C-8AA3-25C1E8FC0399}\RP872\A0237655.exe -> Adware.WinAD : Cleaned with backup (quarantined). ::Report end
odice - 07-01-09 23:38:02.35 Service Pack 2 ComboFix 06.11.27 - Running from: "C:\Documents and Settings\Xodice\NetHood\Desktop\Tom Coyote fixers" ((((((((((((((((((((((((((((((( Files Created from 2006-12-09 to 2007-01-09 )))))))))))))))))))))))))))))))))) 2007-01-09 23:33 d——– C:\Program Files\Common Files\Java 2007-01-09 22:27 dr-h—– C:\Documents and Settings\Xodice\Recent 2007-01-09 21:03 d——– C:\WINDOWS\ie7updates 2007-01-08 18:37 d——– C:\WINDOWS\system32\Kaspersky Lab 2007-01-07 10:25 127,208 –a—— C:\WINDOWS\system32\mucltui.dll 2007-01-06 21:32 d——– C:\WINDOWS\system32\ActiveScan 2007-01-06 21:05 d——– C:\WINDOWS\WBEM 2007-01-06 21:05 d——– C:\WINDOWS\system32\en-US 2007-01-06 21:04 d–h-c— C:\WINDOWS\ie7 2007-01-06 21:03 121,856 ——— C:\WINDOWS\system32\xmllite.dll 2007-01-06 21:03 d——– C:\WINDOWS\network diagnostic 2007-01-06 21:00 d——– C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage 2007-01-06 19:59 d——– C:\SDFix 2007-01-05 18:49 d——– C:\!KillBox 2007-01-05 18:30 d——– C:\VundoFix Backups 2007-01-04 19:41 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-01-03 22:49 d——– C:\Program Files\WON 2007-01-03 22:28 d——– C:\avenger 2007-01-03 22:24 60,416 –a—— C:\WINDOWS\system32\drivers\ev^gnmmn.sys 2007-01-03 22:24 d——– C:\Rustbfix 2007-01-03 19:05 2,506 –a—— C:\WINDOWS\system32\tmp.reg 2007-01-03 19:05 d——– C:\Documents and Settings\Xodice\SmitfraudFix 2007-01-02 12:33 d——– C:\Program Files\CCleaner 2007-01-01 22:30 90,112 –a—— C:\WINDOWS\system32\RegDACL.exe 2007-01-01 22:30 7,483 –a—— C:\clean.bat 2007-01-01 22:30 4,096 –a—— C:\WINDOWS\system32\reboot.exe 2007-01-01 22:30 38,400 –a—— C:\WINDOWS\system32\moveex.exe 2007-01-01 22:29 d——– C:\Program Files\HaxFix 2006-12-27 00:48 dr-h—– C:\$VAULT$.AVG 2006-12-19 23:52 816,672 –a—— C:\WINDOWS\system32\drivers\avg7core.sys 2006-12-19 23:52 4,960 –a—— C:\WINDOWS\system32\drivers\avgtdi.sys 2006-12-19 23:52 4,224 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys 2006-12-19 23:52 3,968 –a—— C:\WINDOWS\system32\drivers\avgclean.sys 2006-12-19 23:52 28,416 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys 2006-12-19 23:52 18,240 –a—— C:\WINDOWS\system32\drivers\avgmfx86.sys 2006-12-19 23:52 d——– C:\Program Files\Grisoft 2006-12-19 23:52 d——– C:\Documents and Settings\Xodice\Application Data\AVG7 2006-12-19 23:52 d——– C:\Documents and Settings\All Users\Application Data\Grisoft 2006-12-19 23:52 d——– C:\Documents and Settings\All Users\Application Data\avg7 2006-12-19 12:41 d——– C:\Documents and Settings\Xodice\Application Data\Real 2006-12-10 00:03 d——– C:\Program Files\Winamp (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-01-09 23:35 ——– d——– C:\Program Files\Mozilla Firefox 2007-01-09 23:33 ——– d-a—— C:\Program Files\Common Files 2007-01-09 23:33 ——– d——– C:\Program Files\Java 2007-01-08 19:56 ——– d——– C:\Program Files\hijack this 2007-01-06 21:51 ——– d——– C:\Program Files\LiveUpdate 2007-01-06 21:50 ——– d——– C:\Program Files\Internet Explorer 2007-01-06 19:54 ——– d——– C:\Documents and Settings\Xodice\Application Data\Azureus 2007-01-04 00:26 ——– d–h—– C:\Program Files\InstallShield Installation Information 2007-01-02 21:43 ——– d——– C:\Program Files\Common Files\Symantec Shared 2006-12-19 23:52 ——– d—s—- C:\Documents and Settings\Xodice\Application Data\Microsoft 2006-12-17 23:17 ——– d——– C:\Program Files\Jasc Software Inc 2006-12-14 03:01 ——– d——– C:\Program Files\Outlook Express 2006-12-14 03:01 ——– d——– C:\Program Files\Common Files\System 2006-12-06 22:29 2374472 –a—— C:\WINDOWS\system32\wmvcore.dll 2006-11-07 22:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll 2006-11-07 21:03 6049280 ——— C:\WINDOWS\system32\ieframe.dll 2006-11-07 21:03 50688 ——— C:\WINDOWS\system32\msfeedsbs.dll 2006-11-07 21:03 458752 ——— C:\WINDOWS\system32\msfeeds.dll 2006-11-07 21:03 413696 –a—— C:\WINDOWS\system32\vbscript.dll 2006-11-07 21:03 231424 –a—— C:\WINDOWS\system32\webcheck.dll 2006-11-07 21:03 180736 ——— C:\WINDOWS\system32\ieui.dll 2006-11-07 21:03 156160 –a—— C:\WINDOWS\system32\msls31.dll 2006-11-07 03:27 382976 –a—— C:\WINDOWS\system32\iedkcs32.dll 2006-11-07 03:27 229376 –a—— C:\WINDOWS\system32\ieaksie.dll 2006-11-07 03:26 71680 –a—— C:\WINDOWS\system32\admparse.dll 2006-11-07 03:26 55296 –a—— C:\WINDOWS\system32\iesetup.dll 2006-11-07 03:26 54784 –a—— C:\WINDOWS\system32\ie4uinit.exe 2006-11-07 03:26 43008 –a—— C:\WINDOWS\system32\iernonce.dll 2006-11-07 03:26 152064 –a—— C:\WINDOWS\system32\ieakeng.dll 2006-11-07 03:26 13312 –a—— C:\WINDOWS\system32\ieudinit.exe 2006-11-07 03:26 123904 –a—— C:\WINDOWS\system32\advpack.dll 2006-11-07 03:25 161792 –a—— C:\WINDOWS\system32\ieakui.dll 2006-11-04 14:14 1245696 –a—— C:\WINDOWS\system32\msxml4.dll 2006-10-19 06:56 713216 –a—— C:\WINDOWS\system32\sxs.dll 2006-10-17 12:06 78336 –a—— C:\WINDOWS\system32\ieencode.dll 2006-10-17 12:05 40960 –a—— C:\WINDOWS\system32\licmgr10.dll 2006-10-17 12:05 206336 ——— C:\WINDOWS\system32\WinFXDocObj.exe 2006-10-17 12:05 105984 –a—— C:\WINDOWS\system32\url.dll 2006-10-17 12:04 101376 –a—— C:\WINDOWS\system32\occache.dll 2006-10-17 12:03 17408 –a—— C:\WINDOWS\system32\corpol.dll 2006-10-17 11:58 61952 ——— C:\WINDOWS\system32\icardie.dll 2006-10-17 11:58 12288 ——— C:\WINDOWS\system32\msfeedssync.exe 2006-10-17 11:57 36352 –a—— C:\WINDOWS\system32\imgutil.dll 2006-10-17 11:57 266752 ——— C:\WINDOWS\system32\iertutil.dll 2006-10-17 11:56 45568 –a—— C:\WINDOWS\system32\mshta.exe 2006-10-17 11:28 48128 –a—— C:\WINDOWS\system32\mshtmler.dll 2006-10-17 11:27 380928 ——— C:\WINDOWS\system32\ieapfltr.dll 2006-10-13 05:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "BTCLiveUpdate"="\"C:\\Program Files\\LiveUpdate\\LiveUpdate.exe\" /autostart" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "NVRaidService"="C:\\WINDOWS\\System32\\nvraidservice.exe" "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe" "HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\"" "NVMixerTray"="\"C:\\Program Files\\NVIDIA Corporation\\NvMixer\\NVMixerTray.exe\"" "iRiver Updater"="\\Updater.exe" "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe" "nwiz"="nwiz.exe /install" "ANIWZCS2Service"="C:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe" "UserFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,75,00 "NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit" "RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\"" "DAEMON Tools-1033"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033 -noicon" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000000 [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\ATI CATALYST System Tray.lnk" "backup"="C:\\WINDOWS\\pss\\ATI CATALYST System Tray.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\ATITEC~1\\ATI.ACE\\CLI.exe SystemTray" "item"="ATI CATALYST System Tray" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\HP Digital Imaging Monitor.lnk" "backup"="C:\\WINDOWS\\pss\\HP Digital Imaging Monitor.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\HP\\DIGITA~1\\bin\\hpqtra08.exe " "item"="HP Digital Imaging Monitor" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\InterVideo WinCinema Manager.lnk" "backup"="C:\\WINDOWS\\pss\\InterVideo WinCinema Manager.lnkCommon Startup" "location"="Common Startup" "command"="G:\\PROGRA~1\\INTERV~1\\Common\\Bin\\WINCIN~1.EXE " "item"="InterVideo WinCinema Manager" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinScheduler.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\InterVideo WinScheduler.lnk" "backup"="C:\\WINDOWS\\pss\\InterVideo WinScheduler.lnkCommon Startup" "location"="Common Startup" "command"="G:\\PROGRA~1\\INTERV~1\\MSIPVS\\WINSCH~1.EXE " "item"="InterVideo WinScheduler" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Kodak EasyShare software.lnk" "backup"="C:\\WINDOWS\\pss\\Kodak EasyShare software.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Kodak\\KODAKE~1\\bin\\EASYSH~1.EXE -h" "item"="Kodak EasyShare software" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Kodak software updater.lnk" "backup"="C:\\WINDOWS\\pss\\Kodak software updater.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Kodak\\KODAKS~1\\7288971\\Program\\KODAKS~1.EXE " "item"="Kodak software updater" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Xodice^Start Menu^Programs^Startup^Desperate Housewives Registration.lnk] "path"="C:\\Documents and Settings\\Xodice\\Start Menu\\Programs\\Startup\\Desperate Housewives Registration.lnk" "backup"="C:\\WINDOWS\\pss\\Desperate Housewives Registration.lnkStartup" "location"="Startup" "command"="D:\\PROGRA~1\\BUENAV~1\\DESPER~1\\eReg\\DSN1.exe /remind /language=ENU /PRNM=\"Desperate Housewives\"" "item"="Desperate Housewives Registration" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="" "hkey"="HKCU" "command"="" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="cli" "hkey"="HKLM" "command"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="atiptaxx" "hkey"="HKLM" "command"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CTDetect" "hkey"="HKCU" "command"="C:\\Program Files\\Creative\\MediaSource\\Detector\\CTDetect.exe /R" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="daemon" "hkey"="HKLM" "command"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMOFFICE4DMOUSE] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="moffice" "hkey"="HKLM" "command"="C:\\Program Files\\Labtec\\moffice.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HPWuSchd2" "hkey"="HKLM" "command"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\klop] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="30" "hkey"="HKCU" "command"="C:\\WINDOWS\\30.tmp" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="msmsgs" "hkey"="HKCU" "command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="nwiz" "hkey"="HKLM" "command"="nwiz.exe /install" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="mssysmgr" "hkey"="HKCU" "command"="C:\\PROGRA~1\\Ahead\\NEROPH~2\\data\\Xtras\\mssysmgr.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\POINTER] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="point32" "hkey"="HKLM" "command"="C:\\Program Files\\Microsoft Hardware\\Mouse\\point32.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pop-Up Stopper] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dpps2" "hkey"="HKLM" "command"="\"C:\\PROGRA~1\\PANICW~1\\POP-UP~1\\dpps2.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QD FastAndSafe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="point32" "hkey"="HKLM" "command"="C:\\Program Files\\Microsoft Hardware\\Mouse\\point32.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="qttask" "hkey"="HKLM" "command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RealPlay" "hkey"="HKLM" "command"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PDVDServ" "hkey"="HKLM" "command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TeaTimer" "hkey"="HKCU" "command"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="" "hkey"="HKCU" "command"="" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="jusched" "hkey"="HKLM" "command"="C:\\Program Files\\Java\\jre1.5.0_01\\bin\\jusched.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dumprep 0 -u" "hkey"="HKLM" "command"="%systemroot%\\system32\\dumprep 0 -u" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="winampa" "hkey"="HKLM" "command"="C:\\Program Files\\Winamp\\winampa.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "FreezeScreenSaver"=dword:00000002 [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Completion time: 07-01-09 23:38:49.46 C:\ComboFix.txt … 07-01-09 23:38 C:\ComboFix2.txt … 07-01-08 18:32 C:\ComboFix3.txt … 07-01-06 22:14
Logfile of HijackThis v1.99.1
Scan saved at 11:39:50 PM, on 1/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvraidservice.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Updater.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\LiveUpdate\LiveUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\hijack this\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\System32\nvraidservice.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [BTCLiveUpdate] "C:\Program Files\LiveUpdate\LiveUpdate.exe" /autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: D-Link AirPlus.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by23fd.bay23.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1168141373265
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
Hello Booberry, Thanks for posting logs. Your logs are appears to be clean now. Are you still getting the error message? We need to tidy up some here. I need you do delete these tools they are of no longer any use because they update to new verison so frequently that new one have to be downloaded each time used. Delete these: haxfix.exe SmitFraudFix.exe and folder rustbfix.exe killbox VundoFix SDFix.exe Delete all reg fix files I had to make and save to your desktop.>>> regfix.reg, and all others. Combofix.exe Please let me know about the error message?
Thank you so much my computer is running way faster now it's great i appreciate it so much, and no i have not had the pop up's at all latley! But one more question: How do i delete something that won't let me delete, even in safe mode i cannot delete it? it is something i downloaded and i can't get rid of it, spyware found nothing and avg anti virus found nothing!
no it was for a keygen and i never opened it or anything its just sitting in my downloads folder. i just want it off my computer but i guess its not a threat if you never saw it right, but it is in my D drive not my C drive.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI