This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Same Ol' I Need your help

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

well heres my log thanks to who ever takes the time to read it :D

Logfile of HijackThis v1.99.1
Scan saved at 11:13:25 PM, on 3/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
J:\bit comet\BitComet\BitComet.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\system32\sndvol32.exe
C:\Documents and Settings\User\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,rdjpftv.exe
O2 - BHO: Yvakt Class - {00172AD1-F4BD-48C0-AEB5-A4CFE4638393} - C:\WINDOWS\system32\v199.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Microsoft Works Update Detection] ???\WkDetect.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - (no file)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: *.elitemediagroup.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} - http://moneycentral.msn.com/cabs/pmupd806.exe
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\wuauboot.dll
O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dxq.dll
O20 - Winlogon Notify: App Paths - C:\WINDOWS\
O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\artm_new.dll (file missing)
O20 - Winlogon Notify: hpprintx - hpprintx.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\winsys2f.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbtcoms.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
I'm Bob4, I'll be glad to help you with your computer problems.

Before we start: Please be aware that removing Malware is a hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

In light of this it would be wise for you to back up any files and folders that you don't want to lose before we start.

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • REMEMBER, ABSENCE OF SYMPTOMS DOES NOT MEAN THE INFECTION IS ALL GONE.
If you can do these things, everything should go smoothly.
  • Please note you'll need to have Administrator priviledges to perform the fixes. (XP accounts are Administrator by default)
  • Please let me know if you are using a computer with multiple accounts, as this can affect the instructions given.
It may be helpful to you to print out or take a copy of any instructions given, or save them as a txt document on your desktop as sometimes it is necessary to go offline and you will lose access to them.





I see no signs of an anti virus program.. I suggest you get one in asap. This left you open to become as infected as you are.
I will list 2 free anti virus programs just choose 1.

AVG FREE

Avast

Download and install one of these and run a full scan.


_____________________________

It looks like you have been infected by 2 backdoor trojans.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we can't guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found
http://antivirus.about.com/library/weekly/aa100400a.htm]here

I suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.
If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities.

Should you have any questions, please feel free to ask.

Please let me know what you decide to do in your next post.

Should you decide to clean this machine start by doing the following.




____________________________________


download haxfix

or from here
save it to your desktop
Double click on haxfix.exe to install the program. (standard installation path is c:\program Files\haxfix)
Checkmark "Create a desktop icon".
Click "Next".
When the installation is completed, make sure that the checkmark "Launch haxfix" is placed.
Click "Finish".


A red "dos window" (dos box) will open with options:
1. Make logfile
2. Run auto fix
3. Run manual fix
E. Exit Haxfix

Choose option 1 and copy the contents of that log file in your next reply.
I know you have AVG 7.5 anti malware/spyware. That is not a real time /active anti virus program. It uses a different set of definitions. It was meant to run alongside an anti virus program. Not take the place of one.
The infection you have can not be fixed by simply checking off the bad lines in HJT. I wish it were that simple.
I suggest you follow my instructions for removing this Haxdoor malware you currently have..
ok i thought i what i had was an anti virus program thanks.. also i dont know if some virus is causing this but something keeps disabling my network connection, or it randomly will say a network cable is unplugged oh and here is my haxfix thingy you requested HAXFIX logfile - by Marckie version 4.39 Thu 03/29/2007 12:34:48.15 — Checking for Haxdoor — checking for a3d files a3d files not found checking for matching notify keys no matching notify keys found checking for matching services matching services found ASPI32 checking for matching safeboot services no matching safeboot services found checking for other Haxdoor-files no other Haxdoor-files found — Checking for Goldun — checking for SSODL keys no ssodl keys found checking for notify keys hpprintx checking for services hpprintdrv checking for other Goldun-files no other Goldun-files found checking iexplore.exe iexplore.exe is not infected Finished!
Good Job. :thumbup:


To be honest I'm not sure I have heard of malware making the connection lost/unplugged" icon come up from windows. Doest it seem like a tight fit/connection ? Maybe it will go away after we do a few things. Ya never know they come up with new garbage all the time.



_____________________________
You have a bit of work to do to clean all I see thus far.

Follow these in the order given please and hopefully it goes smooth.

Here we go
__________________________________

Please be sure and do this now. if you haven't already. It is important.

You are running HJT directly from the desktop.
Create a folder called HJT either in C: or My documents and place the
hijackthis.exe in there.
This will ensure we have back ups made and it doesn't get deleted .



_________________________________________
  • Open this folder program files > haxfix and double click on fix.bat (or double click on fix.bat desktop icon)
  • Close all other open windows since this step requires a reboot
  • Select option 2. Run auto fix by typing 2 and then pressing Enter
If an infection is found, you'll get a message to close all other open windows.
  • Close all open windows except the red dos window from haxfix and then press Enter
  • The computer will reboot
  • After reboot a logfile will open > (c:\haxfix.txt)
  • Post the contents of that logfile along with a new HijackThis log.

_________________________________________


Next….

Look in your control panels add/remove programs for any of these and uninstall them:

Oin
Yazzle by Oin
Purityscan by Oin
Snowballwars by Oin
or anything similar with Oin or Outerinfo in it.
Zolero
Tizzletalk
MediaTickets
Cowabanga
and any other programs you didn't install or don't recognize - if your not sure please ask first


If that wasn't there or didn't work use step 2.


Download and run this uninstaller:
http://www.outerinfo.com/OiUninstaller.exe

Tutorial for the uninstaller if needed

Close ALL programs down, leaving ONLY HijackThis running - Click Scan and…..
Place a check against the following items:

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,rdjpftv.exe
O2 - BHO: Yvakt Class - {00172AD1-F4BD-48C0-AEB5-A4CFE4638393} - C:\WINDOWS\system32\v199.dll (file missing)
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - (no file)
O15 - Trusted Zone: *.elitemediagroup.net
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - <http://69.56.176.76/webplugin.cab>
O20 - AppInit_DLLs: C:\WINDOWS\system32\wuauboot.dll
O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dxq.dll
O20 - Winlogon Notify: App Paths - C:\WINDOWS\
O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\artm_new.dll (file missing)
O20 - Winlogon Notify: hpprintx - hpprintx.dll (file missing)
O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\winsys2f.dll

close all open windows and browsers

Click on Fix Checked and exit HijackThis.

_______________________________________
Install MVPS HOSTS:

Download and unzip hosts.zip from HERE to a folder (hosts).

When you get a chance please read more about what we are doing HERE.

Here's a Tutorial on how to install it, but it's installed like this:

Open up the hosts folder and double-click on the mvps.bat file, it will rename your present HOSTS file to HOSTS.MVP, then it will copy the new HOSTS file to the correct location on your machine. It happens very quickly so don't blink!




____________________________
Please download the Killbox by Option^Explicit

Note: In the event you already have Killbox, this is a new version that I need you to download.
Save it to your desktop.
Please double-click Killbox.exe to run it.
Select:
Delete on Reboot
then Click on the All Files button.
Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\WINDOWS\system32\wuauboot.dll
C:\WINDOWS\system32\a3dxq.dll
C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\artm_new.dll
C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\winsys2f.dll
C:\WINDOWS\system32\rdjpftv.exe



Return to Killbox, go to the File menu, and choose Paste from Clipboard.

Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).


If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.




_______________________________________________

Panda
Run Panda's ActiveScan from here and perform a full system scan.
- Once you are on the Panda site click the "Scan your PC" button
- A new window will open…click the big "Check Now" button
- Enter your Country
- Enter your State/Province
- Enter your Valid Email
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
- Click on "Local Disks" to start the scan . This will take a while so be paitient.
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
- Post Panda scan results in your next reply

___________________________________

In your next reply I would like to see:
  • A new HJT log
  • The report from Haxfix
  • ]The report from Pandas online scan.
everything went ok except for when i copied the paths to killbox and used paste from the file menu it said i needed to eneter them still, so i copied them all again and clicked paste on the pulldown box itself and it worked but my only concern is that i could only see the 1st path that i copied the "C:\WINDOWS\system32\wuauboot.dll " one, so im thinking it did nothing with the other 4 you told me to do. however it did restart with no problems after


—————————————————-


here is the hijack this log before i clicked fix the ones you wanted —–>>>>

Logfile of HijackThis v1.99.1
Scan saved at 5:04:08 PM, on 3/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,rdjpftv.exe
O2 - BHO: Yvakt Class - {00172AD1-F4BD-48C0-AEB5-A4CFE4638393} - C:\WINDOWS\system32\v199.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Microsoft Works Update Detection] ???\WkDetect.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - (no file)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: *.elitemediagroup.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} - http://moneycentral.msn.com/cabs/pmupd806.exe
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\wuauboot.dll
O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dxq.dll (file missing)
O20 - Winlogon Notify: App Paths - C:\WINDOWS\
O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\artm_new.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\winsys2f.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbtcoms.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe

——————————————————-

Here is the HJT log after fix checked had run —->>>


_________________________________________

Logfile of HijackThis v1.99.1
Scan saved at 5:33:48 PM, on 3/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Microsoft Works Update Detection] ???\WkDetect.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} - http://moneycentral.msn.com/cabs/pmupd806.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbtcoms.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe

—————————————-

Here is the Hxfix report


HAXFIX logfile - by Marckie

version 4.39
Thu 03/29/2007 16:52:38.73

— Auto Haxdoorfix —


searching for files:

no infections found


— Goldunfix —


searching for files:


checking iexplore.exe
iexplore.exe is not infected

searching for SSODLkeys:
no SSODLkeys found

searching for notifykeys:
hpprintx

searching for services:
hpprintdrv


deleting service hpprintdrv
[SWSC] DeleteService SUCCESS


…..rebooting the computer…..


searching for ssodlkeys

not needed


searching for notifykeys

notifykey hpprintx not found


searching for services

service hpprintdrv not found


searching for safeboot services

not needed


searching for files

hpprintx.dll exists
deleting hpprintx.dll
hpprintx.dll has been deleted

hpprintdrv.sys exists
deleting hpprintdrv.sys
hpprintdrv.sys has been deleted


checking for other files

No other files found


checking for a3d files

no a3d files found


Finished
_____________________________________________

Here is the PANDA Scan Results —–>


Incident Status Location

Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Owner\Cookies\owner@atwola[1].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Owner\Cookies\owner@offeroptimizer[1].txt
Spyware:Spyware/BetterInet Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\biini.inf
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.advertising.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.com.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[www.burstbeacon.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.overture.com/]
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.ads.addynamix.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.weborama.fr/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[citi.bridgetrack.com/]
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.ct.360i.com/]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Coremetrics Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[data.coremetrics.com/]
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.bfast.com/]
Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.targetnet.com/]
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.i.screensavers.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\46wl92zj.default\cookies.txt[.go.com/]
Spyware:spyware/surfsidekick Not disinfected C:\Documents and Settings\User\Application Data\Sskknwrd.dll
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\User\Cookies\[removed][1].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\User\Cookies\[removed][1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\User\Cookies\user@atwola[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\User\Cookies\user@doubleclick[2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\User\Cookies\user@mediaplex[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\User\Cookies\user@statcounter[1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\User\Cookies\user@trafficmp[2].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Program Files\HaxFix\Process.exe
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP139\snapshot\MFEX-1.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP140\snapshot\MFEX-1.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP141\snapshot\MFEX-1.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP142\snapshot\MFEX-1.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP143\snapshot\MFEX-1.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP144\snapshot\MFEX-1.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP145\snapshot\MFEX-1.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP146\snapshot\MFEX-1.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP147\snapshot\MFEX-1.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP148\A0016666.dll
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP148\snapshot\MFEX-1.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP153\snapshot\MFEX-1.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP153\snapshot\MFEX-2.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP153\snapshot\MFEX-3.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP153\snapshot\MFEX-4.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP154\A0017668.dll
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP154\snapshot\MFEX-1.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP154\snapshot\MFEX-2.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP154\snapshot\MFEX-3.DAT
Adware:Adware/HuntBar Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP154\snapshot\MFEX-4.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP155\snapshot\MFEX-1.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP156\snapshot\MFEX-1.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP156\snapshot\MFEX-2.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP157\snapshot\MFEX-1.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP157\snapshot\MFEX-2.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP157\snapshot\MFEX-3.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP158\snapshot\MFEX-1.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP158\snapshot\MFEX-2.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP158\snapshot\MFEX-3.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP159\snapshot\MFEX-1.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP159\snapshot\MFEX-2.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP159\snapshot\MFEX-3.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP160\snapshot\MFEX-1.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP160\snapshot\MFEX-2.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP160\snapshot\MFEX-3.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP161\snapshot\MFEX-1.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP161\snapshot\MFEX-2.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP161\snapshot\MFEX-3.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP162\snapshot\MFEX-1.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP162\snapshot\MFEX-2.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP162\snapshot\MFEX-3.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP163\snapshot\MFEX-1.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP163\snapshot\MFEX-2.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP163\snapshot\MFEX-3.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP164\snapshot\MFEX-1.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP164\snapshot\MFEX-2.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP164\snapshot\MFEX-3.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP165\snapshot\MFEX-1.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP165\snapshot\MFEX-2.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP165\snapshot\MFEX-3.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP166\snapshot\MFEX-1.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP166\snapshot\MFEX-2.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP166\snapshot\MFEX-3.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP167\snapshot\MFEX-1.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP167\snapshot\MFEX-2.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information\_restore{DD52B3A0-B9BD-4869-B718-C49FCA7D3D65}\RP167\snapshot\MFEX-3.DAT
Adware:Adware/WebSearch Not disinfected C:\System Volume Information
Nice work, looking much better. :thumbup:


_____________________________

Please double-click Killbox.exe to run it.
Select:
Delete on Reboot
then Click on the All Files button.
Please copy the file paths below to the clipboard by highlighting this line and pressing CTRL + C (or, after highlighting, right-click and choose copy):


C:\Documents and Settings\User\Application Data\Sskknwrd.dll

Return to Killbox, go to the File menu, and choose Paste from Clipboard.

click unregister dll before deleting

Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).


If your computer does not restart automatically, please restart it manually.


_____________________________________________________-

Navigate to your c drive through MY computer. In Local disk C there should be a folder called !killbox in that folder should be everything we have deleted with it thus far.
You should see all the files in there we have deleted.
Let me know if 6 files are in there.

In your last try did you click Click on the All Files button ?




___________________________________
Reconfigure Windows XP to show hidden files::

Click Start. My Computer.
Select the Tools menu Folder Options. Select the View Tab.
Under the Hidden files and folders heading select "Show hidden files and folders".
Uncheck the "Hide protected operating system files (recommended)" option.
Uncheck the "Hide file extensions for known file types" option.
Click Yes to confirm. Click OK.

Now I want you to do an all files search for ..By clicking start/search
copy this in

WkDetect.exe

and I want to know all the locations windows finds it.
Don't delete it . It very well may be legitimate..
HiJackThis is reporting something strange about it.
May be nothing.

__________________________________

I also want to see a registry key for this.

click start/run and copy this in exactly.

regedit /e desktop\runkey.txt "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run"

This will place a notepad file on your sesktop called runkey.txt.
Open that and copy the contenets in your next reply for me.




_____________________________________________
1. Download Combo fix from one of these locations.
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe


2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

___________________________________
In your next reply I would like to see:
  • The report from combo fix
  • Let me know abouth the contents of c:/!killbox
  • The runkey.txt file
  • all locations of WkDetect.exe
here is the kill box log, only that one file it as i suspected, i did click all flies both times, it seems it is only letting me paste in one Dir only,

____________________________
No traces on wkdeect.exe anywhere…
____________________


anyways here the log

Pocket Killbox version 2.0.0.648
Running on Windows XP as User(Administrator)
was started @ Thursday, March 29, 2007, 5:08 PM

# 1 [Delete on Reboot]
Path = C:\WINDOWS\system32\wuauboot.dll


I Rebooted @ 5:11:13 PM
Killbox Closed(Exit) @ 5:11:14 PM
__________________________________________________

Pocket Killbox version 2.0.0.648
Running on Windows XP as User(Administrator)
was started @ Friday, March 30, 2007, 2:11 PM

# 1 [Delete on Reboot]
Path = C:\Documents and Settings\User\Application Data\Sskknwrd.dll


I Rebooted @ 2:12:09 PM
Killbox Closed(Exit) @ 2:12:15 PM
__________________________________________________



heres the RUNkey



Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="࠳粑\\WkDetect.exe"
"AnyDVD"="C:\\Program Files\\SlySoft\\AnyDVD\\AnyDVD.exe"

_______________________________________________

Combo FIx Report


"User" - 07-03-30 14:21:38 Service Pack 2
ComboFix 07-03-27.4.2 - Running from: "C:\Program Files\Mozilla Firefox"


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\uninstall_nmon.vbs
C:\DOCUME~1\User\APPLIC~1\Sskdmns.dll
C:\DOCUME~1\User\APPLIC~1\Sskuknwrd.dll
C:\Documents and Settings\All Users.WINDOWS.\documents\settings\desktop.ini
C:\DOCUME~1\LOCALS~1.NTA\APPLIC~1\netmon\domains.txt
C:\DOCUME~1\LOCALS~1.NTA\APPLIC~1\netmon\log.txt
C:\WINDOWS\inet20010\mm.pid
C:\WINDOWS\inet20010\winelf.txt
C:\Documents and Settings\All Users.WINDOWS.\documents\settings
C:\WINDOWS\DOWNLO~1.\Temp
C:\DOCUME~1\LOCALS~1.NTA\APPLIC~1\netmon
C:\WINDOWS\inet20010
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\DOCUME~1\User
C:\qoobox\purity\DOCUME~1\User\APPLIC~1
C:\qoobox\purity\DOCUME~1\User\MYDOCU~1
C:\qoobox\purity\DOCUME~1\User\APPLIC~1\from.txt
C:\qoobox\purity\DOCUME~1\User\APPLIC~1\MCROSO~1
C:\qoobox\purity\DOCUME~1\User\APPLIC~1\PPATCH~1
C:\qoobox\purity\DOCUME~1\User\APPLIC~1\MCROSO~1\MCROSO~1
C:\qoobox\purity\DOCUME~1\User\MYDOCU~1\from.txt
C:\qoobox\purity\DOCUME~1\User\MYDOCU~1\STEM32~1
C:\qoobox\purity\Program Files\Common Files\FNTS~1
C:\qoobox\purity\Program Files\Common Files\FNTS~2
C:\qoobox\purity\Program Files\Common Files\ICROSO~1
C:\qoobox\purity\Program Files\Common Files\ICROSO~1\?icrosoft
C:\qoobox\purity\WINDOWS\TSKS~1
C:\qoobox\purity\WINDOWS\system32\ASEMBL~1
C:\qoobox\purity\WINDOWS\system32\CROSOF~1


((((((((((((((((((((((((((((((( Files Created from 2007-02-28 to 2007-03-30 ))))))))))))))))))))))))))))))))))


2007-03-29 17:17 d——– C:\WINDOWS\system32\ActiveScan
2007-03-29 17:08 d——– C:\!KillBox
2007-03-29 17:00 d——– C:\HJT
2007-03-29 12:34 90,112 –a—— C:\WINDOWS\system32\RegDACL.exe
2007-03-29 12:34 8,234 –a—— C:\clean.bat
2007-03-29 12:34 53,248 –a—— C:\WINDOWS\system32\process.exe
2007-03-29 12:34 40,960 –a—— C:\WINDOWS\system32\swsc.exe
2007-03-29 12:34 4,096 –a—— C:\WINDOWS\system32\reboot.exe
2007-03-29 12:34 38,400 –a—— C:\WINDOWS\system32\moveex.exe
2007-03-28 18:22 d——– C:\DVD
2007-03-28 14:31 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-03-28 14:20 d——– C:\Program Files\True Sword 4
2007-03-28 14:20 d——– C:\DOCUME~1\User\APPLIC~1\True Sword
2007-03-19 14:00 504 –a—— C:\WINDOWS\ONSPCLCK.exe
2007-03-19 00:03 d——– C:\Program Files\Free WMA to MP3 Converter
2007-03-15 13:25 d——– C:\Program Files\MagicISO
2007-03-15 12:40 14,604 –a—— C:\WINDOWS\system32\drivers\pfc.sys
2007-03-15 12:34 d——– C:\Program Files\PowerISO
2007-03-14 19:11 22,040 —h—– C:\DOCUME~1\User\APPLIC~1\addon.dat
2007-03-14 19:11 d–h—– C:\WINDOWS\system32\win32GI
2007-03-14 18:53 524,288 –a—— C:\WINDOWS\system32\xvidcore.dll
2007-03-14 18:53 413,760 –a—— C:\WINDOWS\system32\mpg4c32.dll
2007-03-14 18:53 261,632 –a—— C:\WINDOWS\system32\mcdvd_32.dll
2007-03-14 18:53 24,576 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-03-14 18:53 139,264 –a—— C:\WINDOWS\system32\xvidvfw.dll
2007-03-14 18:53 1,700,352 –a—— C:\WINDOWS\system32\GdiPlus.dll
2007-03-14 18:53 d——– C:\Program Files\Common Files\AVSMedia
2007-03-14 18:04 d——– C:\Program Files\Digidesign
2007-03-14 17:22 536,576 –a—— C:\WINDOWS\system32\Dsi.dll
2007-03-14 17:22 180,276 –a—— C:\WINDOWS\system32\Mspdb50.dll
2007-03-14 17:22 d——– C:\Program Files\Common Files\Digidesign
2007-03-14 17:21 45,056 –a—— C:\WINDOWS\system32\wnaspi32.dll
2007-03-14 17:20 d——– C:\Program Files\SafeNet Sentinel
2007-03-14 17:20 d——– C:\Program Files\Common Files\SafeNet Sentinel
2007-03-14 17:19 53,248 –a—— C:\WINDOWS\system32\ipl.dll
2007-03-14 17:19 2,981,888 –a—— C:\WINDOWS\system32\iplw7.dll
2007-03-14 17:19 2,973,696 –a—— C:\WINDOWS\system32\iplA6.dll
2007-03-14 17:19 2,785,280 –a—— C:\WINDOWS\system32\iplM6.dll
2007-03-14 17:19 2,686,976 –a—— C:\WINDOWS\system32\iplM5.dll
2007-03-14 17:19 2,531,328 –a—— C:\WINDOWS\system32\iplP6.dll
2007-03-14 17:19 2,502,656 –a—— C:\WINDOWS\system32\iplPX.dll
2007-03-14 17:19 d——– C:\Program Files\Common Files\Avid
2007-03-14 15:16 d——– C:\Program Files\Duplicate Music Files Finder
2007-03-08 22:18 d——– C:\Program Files\msn gaming zone
2007-03-05 15:45 10,240 –a—— C:\WINDOWS\CTDCRES.DLL
2007-03-02 18:52 409,600 –a—— C:\WINDOWS\system32\wrap_oal.dll
2007-03-02 18:51 3,072 –a—— C:\WINDOWS\CTXFIRES.DLL


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-03-29 17:43 ——– d——– C:\Program Files\lexmark 5200 series
2007-03-29 17:42 ——– d——– C:\Program Files\itunes
2007-03-27 08:53 ——– d——– C:\Program Files\lx_cats
2007-03-26 19:20 ——– d——– C:\Program Files\electronic arts
2007-03-15 13:29 ——– d–h—– C:\Program Files\installshield installation information
2007-03-14 10:51 96256 –a—— C:\WINDOWS\system32\drivers\sptd8237.sys
2007-03-12 16:34 ——– d——– C:\Program Files\winamp
2007-03-11 22:07 30944 –a–c— C:\DOCUME~1\User\APPLIC~1\gdipfontcachev1.dat
2007-03-05 15:56 ——– d——– C:\Program Files\creative
2007-03-05 15:45 86016 –a—— C:\WINDOWS\system32\openal32.dll
2007-03-05 15:45 ——– d——– C:\DOCUME~1\User\APPLIC~1\creative
2007-02-27 20:28 ——– d——– C:\DOCUME~1\User\APPLIC~1\command & conquer 3 tiberium wars demo
2007-02-27 15:26 ——– d——– C:\DOCUME~1\User\APPLIC~1\u3
2007-02-22 14:16 ——– d——– C:\Program Files\lavasoft
2007-02-22 14:16 ——– d——– C:\Program Files\Common Files\wise installation wizard
2007-02-22 14:16 ——– d——– C:\DOCUME~1\User\APPLIC~1\lavasoft
2007-01-28 14:02 ——– d——– C:\DOCUME~1\User\APPLIC~1\teleca
2007-01-28 13:56 ——– d——– C:\DOCUME~1\User\APPLIC~1\sony ericsson
2007-01-28 13:53 ——– d——– C:\Program Files\sony ericsson
2007-01-28 13:53 ——– d——– C:\Program Files\Common Files\teleca shared
2007-01-28 13:38 8704 –a—— C:\WINDOWS\system32\drivers\ggsemc.sys
2007-01-08 20:01 17408 –a—— C:\WINDOWS\system32\corpol.dll
2007-01-05 00:51 40 —hs—- C:\DOCUME~1\User\APPLIC~1\.zreglib


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Microsoft Works Update Detection"="???\\WkDetect.exe"
"AnyDVD"="C:\\Program Files\\SlySoft\\AnyDVD\\AnyDVD.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"zBrowser Launcher"="C:\\Program Files\\Logitech\\iTouch\\iTouch.exe"
"EM_EXEC"="C:\\PROGRA~1\\Logitech\\MOUSEW~1\\SYSTEM\\EM_EXEC.EXE"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Lexmark 5200 series"="\"C:\\Program Files\\Lexmark 5200 series\\lxbtbmgr.exe\""
"LXBTCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\LXBTtime.dll,_RunDLLEntry@16"
"Sony Ericsson PC Suite"="\"C:\\Program Files\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"
"CTHelper"="CTHELPER.EXE"
"CTxfiHlp"="CTXFIHLP.EXE"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"POSTRBT"="C:\\Program Files\\Norton AntiVirus\\Navw32.exe /REMEDIATE"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^dlbcserv.lnk]
"path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\dlbcserv.lnk"
"backup"="C:\\WINDOWS\\pss\\dlbcserv.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\DELLPH~1\\dlbcserv.exe "
"item"="dlbcserv"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^EPSON Status Monitor 3 Environment Check 2.lnk]
"path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\EPSON Status Monitor 3 Environment Check 2.lnk"
"backup"="C:\\WINDOWS\\pss\\EPSON Status Monitor 3 Environment Check 2.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\E_SRCV02.EXE "
"item"="EPSON Status Monitor 3 Environment Check 2"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^gwum.lnk]
"path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\gwum.lnk"
"backup"="C:\\WINDOWS\\pss\\gwum.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Gigabyte\\GIGABY~1\\gwum.exe "
"item"="gwum"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^jgwib.exe]
"path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\jgwib.exe"
"backup"="C:\\WINDOWS\\pss\\jgwib.exeCommon Startup"
"location"="Common Startup"
"command"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\jgwib.exe"
"item"="jgwib"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="cli"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cnum]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="l?gonui"
"hkey"="HKCU"
"command"="C:\\Program Files\\F?nts\\l?gonui.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WkDetect"
"hkey"="HKCU"
"command"="???\\WkDetect.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mmtask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\MusicMatch\\MusicMatch Jukebox\\mmtask.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmwav]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"hkey"="HKCU"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pppytl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="kernels8"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\kernels8.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TheMonitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SYSC00"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\SYSC00.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="UpdReg"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\UpdReg.EXE"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows update loader]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="xpupdate"
"hkey"="HKCU"
"command"="C:\\Windows\\xpupdate.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mi-raysat_3dsmax8"=dword:00000002
"IDriverT"=dword:00000003
"Network Monitor"=dword:00000002
"EPSONStatusAgent2"=dword:00000002


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{40847941-2F5E-4BEB-802C-74849B8BA2E4}"="ahdp"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Htpwzdyg"="C:\\DOCUME~1\\User\\APPLIC~1\\PPATCH~1\\WAUCLT~1.EXE"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{268738ce-c6b1-11db-8c3a-000d61c1efb2}]
Shell\AutoRun\command G:\LaunchU3.exe -a



~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

backup-20070329-170727-906
O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\winsys2f.dll (file missing)
backup-20070329-170727-706
O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\artm_new.dll (file missing)
backup-20070329-170727-782
O20 - Winlogon Notify: App Paths - C:\WINDOWS\
backup-20070329-170727-677
O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dxq.dll (file missing)
backup-20070329-170713-780
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab
backup-20070329-170713-966
O15 - Trusted Zone: *.elitemediagroup.net
backup-20070329-170713-383
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - (no file)
backup-20070329-170713-123
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,rdjpftv.exe
backup-20070329-170713-604
O2 - BHO: Yvakt Class - {00172AD1-F4BD-48C0-AEB5-A4CFE4638393} - C:\WINDOWS\system32\v199.dll (file missing)

Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Ad-Aware SE Personal.job


********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBTCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-03-30 14:23:37


____________________________________________
Hi ihatemyself,
We have a bit of work to do. But real quick were you able to do the all files search for
WkDetect.exe so I may see all it's locations?
The reason I'm asking is HJT reopts it being run from a funny folder that I don't trust 100%. So I am trying to determin if it's some sort of glitch in windows or is it malware.

What I would like to know if it's in a legitimate folder.

Please do the all files search and let me know where windowns finds all the WkDetect.exe

____________________



Heres how

open a new Notepad document on your desktop.

Leave it open

click start/search then all files and folders.
copy this in WkDetect.exe and hit search!

when it's done you can right click each of them and choose properties
copy the Location portion from that window into the note pad you have open and post those for me.
Along with what I asked for above please do the following.

Ok I still see parts of purtity/oin in your logs. Did the uninstaller seem to work ?
___________________________________
Reconfigure Windows XP to show hidden files::

Click Start. My Computer.
Select the Tools menu Folder Options. Select the View Tab.
Under the Hidden files and folders heading select "Show hidden files and folders".
Uncheck the "Hide protected operating system files (recommended)" option.
Uncheck the "Hide file extensions for known file types" option.
Click Yes to confirm. Click OK.
___________________________________
Search for and remove
Now I want you to search for and delete the following folder and all it's contents if present. If you need help finding them.
Click start /search/ all files and folders/ look for More advanced options. once in there select the first 3 boxes.
Please just remove the files/folders I listed in BOLD

Delete These folders

C:\WINDOWS\system32\win32GI
C:\Program Files\F?nts






______________________________________________

NOTE: If files were aleready killed off by another process killbox will not copy them.

Please double-click Killbox.exe to run it.
Select:
Delete on Reboot
then Click on the All Files button.
Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


C:\DOCUMENTS AND SETTINGS\User\APPLICATIONS\PPATCH~1\WAUCLT~1.EXE
C:\WINDOWS\SYSC00.exe
C:\WINDOWS\UpdReg.EXE


Return to Killbox, go to the File menu, and choose Paste from Clipboard.

Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).


If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.








______________________________
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths 1 at a time:.




C:\WINDOWS\system32\drivers\sptd8237.sys
Then hit Submit


C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\jgwib.exe

Then hit Submit

The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html




In your next reply I would like to see:
  • A new HJT log
  • The report from Jottis on both files
  • Let me know how things seem to be running.
  • Location/s of the WkDetect.exe file
both websites say this when i try to send the File to them…

The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file

when i search for the F?nts thingy i find like 6 places in program files mostly adobe or whatever, but the thing is when i select all of those to delete them the search window closes and windows explorer shuts down/ taskbar and icons go away for a couple of seconds, but after this the weird thing was some program came up out of nowhere called Drwatson32 or something, after about a minute of my destop having heavy trails it returned to normal.

i search all/files folders for wkdetect.exe again and still no results at all, which is odd im guessing.
___________________________________

the Oiuninstaller worked fine no problems
___________________________

The NEw HJT this—–

Logfile of HijackThis v1.99.1
Scan saved at 12:01:51 PM, on 3/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Microsoft Works Update Detection] ???\WkDetect.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} - http://moneycentral.msn.com/cabs/pmupd806.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbtcoms.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
Hi again ihatemyself.

_________________________________
Open HJT
this time click on
Misc tools section
then:
Open uninstall Manager
click on save list.
Post that for me.
______________________________
Please do another combo scan for me.

_____________________________
Windows firewall
open control panel
open network connections
right click your local area connection.
choose properties
choose advanced
choose settings
choose OFF ( not recommended)

click OK and OK again.

Now… retry reloading those files for a scan @ jottis.

C:\WINDOWS\system32\drivers\sptd8237.sys

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\jgwib.exe

___________________________

Tell me if you have Micrsoft works installed.

C:\Program Files\Microsoft Works ( yes it is strange that wkdetect.exe isn't showing up in a search.)
You have set windows to see all files and folders I'm sure but have to ask. :)


_____________________________
Drwatson is a safe program.. Drwatson32 is not.
So if this happens again be sure and get the name right for me.


___________________________


Download and Save Blacklight to your desktop:

  • Doubleclick on blbeta.exe.
  • Click on Scan.
  • Once the Scan is Finished, click on Next.
  • Click on Exit.
    A new document will be produced on the desktop.
    Open this document with Notepad.
  • Copy and Paste its contents your next reply.

_____________________
In your next reply I would like to see:
  • The report from combo fix
  • ]The reports from jottis
  • ]The report from blacklight beta
  • Tell me if you have microsft works installed.
  • The uninstall list from HJT.
yes i have clicked all the things to show all hidden files and folders but, still no results.
still nothing from jottis same 0 bytes recieved story even with th efire wall off.

i do have microsoft works suite add-in for microsoft word and some microsoft works 2002 setup launcher but i dont use either of them ever, ide just use the microfost word or other office programs.

i tried that C:\Program Files\F?nts search again and its not locking up anymore, should i still delete all those folders?
the folders in the search results are

C:\Program Files\common files\adobe
C:\Program Files\Mozilla Firefox\res
C:\Program Files\java\jre1.5.0_01\lib
C:\Program Files\videolan\VLC\skins
C:\Program Files\Common Files\Adobe\PDFL\5.0
C:\Program Files\Common Files\Adobe\PDFL\7.0
C:\Program Files\Sony Ericsson\update service\jre\lib

i just wasnt sure if it would like delete fonts i use in say photoshop or word…


here is combofix ———————

"User" - 07-04-01 11:52:25 Service Pack 2
ComboFix 07-03-27.4.2 - Running from: "C:\Documents and Settings\User\Desktop"


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\DOCUME~1\User
C:\qoobox\purity\DOCUME~1\User\APPLIC~1
C:\qoobox\purity\DOCUME~1\User\MYDOCU~1
C:\qoobox\purity\DOCUME~1\User\APPLIC~1\from.txt
C:\qoobox\purity\DOCUME~1\User\APPLIC~1\MCROSO~1
C:\qoobox\purity\DOCUME~1\User\APPLIC~1\PPATCH~1
C:\qoobox\purity\DOCUME~1\User\APPLIC~1\MCROSO~1\MCROSO~1
C:\qoobox\purity\DOCUME~1\User\MYDOCU~1\from.txt
C:\qoobox\purity\DOCUME~1\User\MYDOCU~1\STEM32~1
C:\qoobox\purity\Program Files\Common Files\FNTS~1
C:\qoobox\purity\Program Files\Common Files\FNTS~2
C:\qoobox\purity\Program Files\Common Files\ICROSO~1
C:\qoobox\purity\Program Files\Common Files\ICROSO~1\?icrosoft
C:\qoobox\purity\WINDOWS\TSKS~1
C:\qoobox\purity\WINDOWS\system32\ASEMBL~1
C:\qoobox\purity\WINDOWS\system32\CROSOF~1


((((((((((((((((((((((((((((((( Files Created from 2007-03-01 to 2007-04-01 ))))))))))))))))))))))))))))))))))


2007-03-30 17:54 d——– C:\DOCUME~1\User\APPLIC~1\Command & Conquer 3 Tiberium Wars
2007-03-30 17:22 3,426,072 –a—— C:\WINDOWS\system32\d3dx9_32.dll
2007-03-30 16:36 d——– C:\CNC3
2007-03-29 17:17 d——– C:\WINDOWS\system32\ActiveScan
2007-03-29 17:08 d——– C:\!KillBox
2007-03-29 17:00 d——– C:\HJT
2007-03-29 12:34 90,112 –a—— C:\WINDOWS\system32\RegDACL.exe
2007-03-29 12:34 8,234 –a—— C:\clean.bat
2007-03-29 12:34 53,248 –a—— C:\WINDOWS\system32\process.exe
2007-03-29 12:34 40,960 –a—— C:\WINDOWS\system32\swsc.exe
2007-03-29 12:34 4,096 –a—— C:\WINDOWS\system32\reboot.exe
2007-03-29 12:34 38,400 –a—— C:\WINDOWS\system32\moveex.exe
2007-03-28 14:31 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-03-28 14:20 d——– C:\Program Files\True Sword 4
2007-03-28 14:20 d——– C:\DOCUME~1\User\APPLIC~1\True Sword
2007-03-19 14:00 504 –a—— C:\WINDOWS\ONSPCLCK.exe
2007-03-19 00:03 d——– C:\Program Files\Free WMA to MP3 Converter
2007-03-15 13:25 d——– C:\Program Files\MagicISO
2007-03-15 12:40 14,604 –a—— C:\WINDOWS\system32\drivers\pfc.sys
2007-03-15 12:34 d——– C:\Program Files\PowerISO
2007-03-14 19:11 22,040 —h—– C:\DOCUME~1\User\APPLIC~1\addon.dat
2007-03-14 18:53 524,288 –a—— C:\WINDOWS\system32\xvidcore.dll
2007-03-14 18:53 413,760 –a—— C:\WINDOWS\system32\mpg4c32.dll
2007-03-14 18:53 261,632 –a—— C:\WINDOWS\system32\mcdvd_32.dll
2007-03-14 18:53 24,576 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-03-14 18:53 139,264 –a—— C:\WINDOWS\system32\xvidvfw.dll
2007-03-14 18:53 1,700,352 –a—— C:\WINDOWS\system32\GdiPlus.dll
2007-03-14 18:53 d——– C:\Program Files\Common Files\AVSMedia
2007-03-14 18:04 d——– C:\Program Files\Digidesign
2007-03-14 17:22 536,576 –a—— C:\WINDOWS\system32\Dsi.dll
2007-03-14 17:22 180,276 –a—— C:\WINDOWS\system32\Mspdb50.dll
2007-03-14 17:22 d——– C:\Program Files\Common Files\Digidesign
2007-03-14 17:21 45,056 –a—— C:\WINDOWS\system32\wnaspi32.dll
2007-03-14 17:20 d——– C:\Program Files\SafeNet Sentinel
2007-03-14 17:20 d——– C:\Program Files\Common Files\SafeNet Sentinel
2007-03-14 17:19 53,248 –a—— C:\WINDOWS\system32\ipl.dll
2007-03-14 17:19 2,981,888 –a—— C:\WINDOWS\system32\iplw7.dll
2007-03-14 17:19 2,973,696 –a—— C:\WINDOWS\system32\iplA6.dll
2007-03-14 17:19 2,785,280 –a—— C:\WINDOWS\system32\iplM6.dll
2007-03-14 17:19 2,686,976 –a—— C:\WINDOWS\system32\iplM5.dll
2007-03-14 17:19 2,531,328 –a—— C:\WINDOWS\system32\iplP6.dll
2007-03-14 17:19 2,502,656 –a—— C:\WINDOWS\system32\iplPX.dll
2007-03-14 17:19 d——– C:\Program Files\Common Files\Avid
2007-03-14 15:16 d——– C:\Program Files\Duplicate Music Files Finder
2007-03-08 22:18 d——– C:\Program Files\msn gaming zone
2007-03-05 15:45 10,240 –a—— C:\WINDOWS\CTDCRES.DLL
2007-03-02 18:52 409,600 –a—— C:\WINDOWS\system32\wrap_oal.dll
2007-03-02 18:51 3,072 –a—— C:\WINDOWS\CTXFIRES.DLL


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-03-31 11:33 ——– d——– C:\Program Files\lx_cats
2007-03-29 17:43 ——– d——– C:\Program Files\lexmark 5200 series
2007-03-29 17:42 ——– d——– C:\Program Files\itunes
2007-03-26 19:20 ——– d——– C:\Program Files\electronic arts
2007-03-15 13:29 ——– d–h—– C:\Program Files\installshield installation information
2007-03-14 10:51 96256 –a—— C:\WINDOWS\system32\drivers\sptd8237.sys
2007-03-12 16:34 ——– d——– C:\Program Files\winamp
2007-03-11 22:07 30944 –a–c— C:\DOCUME~1\User\APPLIC~1\gdipfontcachev1.dat
2007-03-05 15:56 ——– d——– C:\Program Files\creative
2007-03-05 15:45 86016 –a—— C:\WINDOWS\system32\openal32.dll
2007-03-05 15:45 ——– d——– C:\DOCUME~1\User\APPLIC~1\creative
2007-02-27 20:28 ——– d——– C:\DOCUME~1\User\APPLIC~1\command & conquer 3 tiberium wars demo
2007-02-27 15:26 ——– d——– C:\DOCUME~1\User\APPLIC~1\u3
2007-02-22 14:16 ——– d——– C:\Program Files\lavasoft
2007-02-22 14:16 ——– d——– C:\Program Files\Common Files\wise installation wizard
2007-02-22 14:16 ——– d——– C:\DOCUME~1\User\APPLIC~1\lavasoft
2007-01-08 20:01 17408 –a—— C:\WINDOWS\system32\corpol.dll
2007-01-05 00:51 40 —hs—- C:\DOCUME~1\User\APPLIC~1\.zreglib


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Microsoft Works Update Detection"="???\\WkDetect.exe"
"AnyDVD"="C:\\Program Files\\SlySoft\\AnyDVD\\AnyDVD.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"zBrowser Launcher"="C:\\Program Files\\Logitech\\iTouch\\iTouch.exe"
"EM_EXEC"="C:\\PROGRA~1\\Logitech\\MOUSEW~1\\SYSTEM\\EM_EXEC.EXE"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Lexmark 5200 series"="\"C:\\Program Files\\Lexmark 5200 series\\lxbtbmgr.exe\""
"LXBTCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\LXBTtime.dll,_RunDLLEntry@16"
"Sony Ericsson PC Suite"="\"C:\\Program Files\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"
"CTHelper"="CTHELPER.EXE"
"CTxfiHlp"="CTXFIHLP.EXE"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"POSTRBT"="C:\\Program Files\\Norton AntiVirus\\Navw32.exe /REMEDIATE"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^dlbcserv.lnk]
"path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\dlbcserv.lnk"
"backup"="C:\\WINDOWS\\pss\\dlbcserv.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\DELLPH~1\\dlbcserv.exe "
"item"="dlbcserv"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^EPSON Status Monitor 3 Environment Check 2.lnk]
"path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\EPSON Status Monitor 3 Environment Check 2.lnk"
"backup"="C:\\WINDOWS\\pss\\EPSON Status Monitor 3 Environment Check 2.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\E_SRCV02.EXE "
"item"="EPSON Status Monitor 3 Environment Check 2"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^gwum.lnk]
"path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\gwum.lnk"
"backup"="C:\\WINDOWS\\pss\\gwum.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Gigabyte\\GIGABY~1\\gwum.exe "
"item"="gwum"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^jgwib.exe]
"path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\jgwib.exe"
"backup"="C:\\WINDOWS\\pss\\jgwib.exeCommon Startup"
"location"="Common Startup"
"command"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\jgwib.exe"
"item"="jgwib"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="cli"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cnum]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="l?gonui"
"hkey"="HKCU"
"command"="C:\\Program Files\\F?nts\\l?gonui.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WkDetect"
"hkey"="HKCU"
"command"="???\\WkDetect.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mmtask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\MusicMatch\\MusicMatch Jukebox\\mmtask.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmwav]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"hkey"="HKCU"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pppytl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="kernels8"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\kernels8.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TheMonitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SYSC00"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\SYSC00.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="UpdReg"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\UpdReg.EXE"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows update loader]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="xpupdate"
"hkey"="HKCU"
"command"="C:\\Windows\\xpupdate.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mi-raysat_3dsmax8"=dword:00000002
"IDriverT"=dword:00000003
"Network Monitor"=dword:00000002
"EPSONStatusAgent2"=dword:00000002


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{40847941-2F5E-4BEB-802C-74849B8BA2E4}"="ahdp"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Htpwzdyg"="C:\\DOCUME~1\\User\\APPLIC~1\\PPATCH~1\\WAUCLT~1.EXE"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{268738ce-c6b1-11db-8c3a-000d61c1efb2}]
Shell\AutoRun\command G:\LaunchU3.exe -a

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e60ac32e-6d92-11da-beb2-000d61c1efb2}]
Shell\AutoRun\command F:\autorun.exe


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Ad-Aware SE Personal.job


********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBTCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-04-01 11:56:33
C:\ComboFix2.txt … 07-03-30 14:23
_________________________________________


here is HJT uninstall list———

A1 DVD Audio Ripper 1.1.40
Ad-Aware SE Personal
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Premiere Pro
Adobe Reader 7.0
Adobe Stock Photos 1.0
AnyDVD
AOL Instant Messenger
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
Autodesk 3ds Max 8
AVG 7.5
AVG Anti-Spyware 7.5
AVI/MPEG/RM/WMV Joiner 4.61
Avid DIO Runtime
Battlefield 2™
Battlefield 2: Special Forces
BitComet 0.70
Command & Conquer 3
Creative Audio Console
Digidesign Command8
DivX Codec
DivX Player
Duplicate Music Files Finder 1.5.5
DVD Decrypter (Remove Only)
EA downloader
Enable S3 for USB Device
EPSON Printer Software
Gigabyte Windows Utility Manager
Google Earth
Guitar Pro 5.0
Half-Life® 2
HaxFix 4.39
HijackThis 1.99.1
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Intel® PRO Network Adapters and Drivers
Intel® PROSet
iPod for Windows 2006-06-28
Ipswitch WS_FTP Home 2006
J2SE Runtime Environment 5.0 Update 1
Lexmark 5200 Series
LimeWire PRO 4.8.1
Logitech iTouch Software
Logitech MouseWare 9.28
Macromedia Dreamweaver MX 2004
Macromedia Extension Manager
Macromedia Flash 8
Macromedia Flash 8 Video Encoder
Macromedia Flash Player 8
Macromedia Flash Player 8
Macromedia Flash Player 8 Plugin
Magic ISO Maker v5.3 (build 0229)
Microsoft Data Access Components KB870669
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2003
Microsoft Office XP Professional with FrontPage
Microsoft Office XP Standard
Microsoft Word 2002
Microsoft Works 2002 Setup Launcher
Microsoft Works Suite Add-in for Microsoft Word
Mozilla Firefox (1.5.0.11)
MP3 Splitter version 3.0
MSXML 4.0 SP2 (KB927978)
Musicmatch® Jukebox
Nero 7 Premium
Panda ActiveScan
Power Tab Editor 1.7
PowerISO
QuickTime
RealPlayer
Reason 3.0
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Sentinel Protection Installer 7.2.2
Sony Ericsson PC Suite
Sound Blaster Audigy
SpeechRedist
Steam™
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB929338)
Update for Windows XP (KB931836)
Update Service
VideoLAN VLC media player 0.8.4a
WildTangent Web Driver
Winamp (remove only)
WinAVIVideoConverter
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885626
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinRAR archiver

____________________________

and Blacklight found nothing wrong
OK.. The only thing bothering me at this point are these two files

C:\WINDOWS\system32\drivers\sptd8237.sys
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\jgwib.exe

I'm sure the second one is no good. Were going to kill box them. There will be backups made.
____________________________________
Please double-click Killbox.exe to run it.
Select:
Delete on Reboot
then Click on the All Files button.
Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
C:\WINDOWS\system32\drivers\sptd8237.sys
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\jgwib.exe

Return to Killbox, go to the File menu, and choose Paste from Clipboard.

Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).


If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.


_________________________________
Please do an online scan with Kaspersky Online Scanner
Click on Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer

The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:

Save the file to your desktop.

Copy and paste that information in your next post.


__________________________


Can you tell me where you got those fonts ?
I am trying to determine if by chance they came from another country ? Some things in some of the logs make me think they may be safe and just chinese characters. But then again if you got them free they realy werent.. :)
C:\Program Files\F?nts\l?gonui.exe most all of my searches are telling me that this file ( which is part of the f?nts folder are from click spring/Purity infection.) is unsafe to have.
This folder is where your computer may have become infected.

I just hate to tell you your all clean and not be sure about it.

In your next reply post
  • The Log from kasperskys
  • Tell me wherer you got thiose fonts.
  • Tell me if you know where you got those fonts.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI