This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Gradually Slowing Down

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Over the past few months I have noticed my computer gradually getting slower and slower. It's not having extremely detrimental problems yet, but I would like to find and fix the problem before it gets much worse. The symptoms include; occasional periods of lag during programs, slow internet page loading, delay in startup, ect. I have downloaded AVG and ran the program in safe mode. I then restarted my computer and ran Hijackthis. I tried to post both the logs from the scans, but the AVG report was too long for these forums, so I will only post the Hijackthis report. I would like advice on how to proceed from here. Thanks in advance for any advice that will follow.

Logfile of HijackThis v1.99.1
Scan saved at 3:22:41 PM, on 4/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\System32\drivers\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
D:\Program Files\BitTorrent\bittorrent.exe
C:\PROGRA~1\FNTS~1\wucrtupd.exe
C:\Program Files\?icrosoft.NET\w?nword.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Documents and Settings\Kevin\Desktop\Olympus\DeviceDetector\DevDtct2.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Mozilla Firefox\firefox.exe
d:\Program Files\WinAce\WinAce.exe
C:\DOCUME~1\Kevin\LOCALS~1\Temp\~AceTemp\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {F169934B-55AC-797A-D34D-29909DA73E9E} - C:\WINDOWS\system32\zabnrv.dll
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ProfileWatcher] d:\Program Files\ProfileWatcher\profilewatcher.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [{E8CF13A0-07CE-1033-1105-021213040001}] "C:\Program Files\Common Files\{E8CF13A0-07CE-1033-1105-021213040001}\Update.exe" te-110-12-0000054
O4 - HKLM\..\Run: [Windows Firewall] C:\WINDOWS\System32\drivers\svchost.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Computer Stuff\Program Files\Search-&-Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Bej2Setup_TryGames.exe] C:\DOWNLO~1\BEJ2SE~1.EXE /r
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BitTorrent] "D:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [Windows Firewall] C:\WINDOWS\System32\drivers\svchost.exe
O4 - HKCU\..\Run: [zzfk] C:\Program Files\InetGet2\stub_109_4_0_4_0.exe
O4 - HKCU\..\Run: [Aest] "C:\PROGRA~1\FNTS~1\wucrtupd.exe" -vt yazb
O4 - HKCU\..\Run: [Csqrgoxf] "C:\Program Files\?icrosoft.NET\w?nword.exe" 99001122
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Device Detector 3.lnk = C:\Documents and Settings\Kevin\Desktop\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{45EDC88D-A29A-4FDA-BE24-012F4BAB686A}: NameServer = 192.168.0.1,192.168.0.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{45EDC88D-A29A-4FDA-BE24-012F4BAB686A}: NameServer = 192.168.0.1,192.168.0.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{45EDC88D-A29A-4FDA-BE24-012F4BAB686A}: NameServer = 192.168.0.1,192.168.0.2
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\S2V2aW4\command.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)
Hi and welcome to the forums. :) I'm Markka and I will be helping you with your malware issues. I'll check your HijackThis log. Right now I'm MRU Undergrad, everything that I post to you must be checked by teachers of Malware Removal University. Please be patient. :)
Excellent! Its good to hear that helping me will be helping you as well. Take your time and I will be looking forward to hearing from you again.
Hello :)


We need to disable TeaTimer as it can blocks fixes:

1) Run Spybot-S&D
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts
5) Restart your computer.


Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please download ATF-cleaner and save it to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

    If you use Firefox browser:

  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser:

  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
  • Click Exit on the Main menu to close the program.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall




Post:
- A fresh HijackThis log
- Contents of C:\Combofix.txt
- Logfile of SDfix (contents of Report.txt)
Logfile of HijackThis v1.99.1
Scan saved at 9:00:34 PM, on 4/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
D:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Documents and Settings\Kevin\Desktop\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Kevin\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {F169934B-55AC-797A-D34D-29909DA73E9E} - C:\WINDOWS\system32\zabnrv.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ProfileWatcher] d:\Program Files\ProfileWatcher\profilewatcher.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Bej2Setup_TryGames.exe] C:\DOWNLO~1\BEJ2SE~1.EXE /r
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BitTorrent] "D:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [zzfk] C:\Program Files\InetGet2\stub_109_4_0_4_0.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Device Detector 3.lnk = C:\Documents and Settings\Kevin\Desktop\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{45EDC88D-A29A-4FDA-BE24-012F4BAB686A}: NameServer = 192.168.0.1,192.168.0.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{45EDC88D-A29A-4FDA-BE24-012F4BAB686A}: NameServer = 192.168.0.1,192.168.0.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{45EDC88D-A29A-4FDA-BE24-012F4BAB686A}: NameServer = 192.168.0.1,192.168.0.2
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)
"Kevin" - 07-04-15 20:58:36 Service Pack 2
ComboFix 07-04-05.Rev3 - Running from: "C:\Program Files\Mozilla Firefox"


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\outerinfo
C:\WINDOWS\S2V2aW4
C:\Program Files\Common Files\{E8CF1~1
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\DOCUME~1\Kevin
C:\qoobox\purity\DOCUME~1\Kevin\APPLIC~1
C:\qoobox\purity\DOCUME~1\Kevin\APPLIC~1\from.txt
C:\qoobox\purity\DOCUME~1\Kevin\APPLIC~1\SCURIT~1
C:\qoobox\purity\Program Files\FNTS~1
C:\qoobox\purity\Program Files\ICROSO~1.NET
C:\qoobox\purity\Program Files\FNTS~1\F?nts
C:\qoobox\purity\WINDOWS\system32\STEM32~1


((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\cmdService
——-\nm
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\LEGACY_NM


((((((((((((((((((((((((((((((( Files Created from 2007-03-15 to 2007-04-15 ))))))))))))))))))))))))))))))))))


2007-04-12 22:13 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-04-01 23:51 d——– C:\Program Files\Microsoft ActiveSync
2007-04-01 18:54 d——– C:\DOCUME~1\Kevin\APPLIC~1\Pegasys Inc
2007-03-31 22:31 53,248 –a—— C:\WINDOWS\system32\GenSvcInst.exe
2007-03-31 22:31 33,408 –a—— C:\WINDOWS\system32\drivers\CDRBSDRV.SYS
2007-03-31 22:31 118,784 –a—— C:\WINDOWS\system32\bgsvcgen.exe
2007-03-31 14:24 d——– C:\DOCUME~1\Kevin\APPLIC~1\Publish Providers
2007-03-31 14:21 d——– C:\DOCUME~1\Kevin\APPLIC~1\Sony
2007-03-31 14:19 d——– C:\Program Files\Vstplugins
2007-03-31 14:19 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony
2007-03-31 06:36 d——– C:\DOCUME~1\Kevin\APPLIC~1\Sony Setup
2007-03-30 16:36 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-04-15 18:20 ——– d——– C:\DOCUME~1\Kevin\APPLIC~1\bittorrent
2007-04-05 20:13 ——– d——– C:\DOCUME~1\Kevin\APPLIC~1\limewire
2007-03-29 23:00 1124 –a—— C:\DOCUME~1\Kevin\APPLIC~1\wklnhst.dat
2007-03-17 09:43 292864 –a—— C:\WINDOWS\system32\winsrv.dll
2007-03-08 11:36 577536 –a—— C:\WINDOWS\system32\user32.dll
2007-03-08 11:36 40960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-03-08 11:36 281600 –a—— C:\WINDOWS\system32\gdi32.dll
2007-03-08 09:47 1843584 –a—— C:\WINDOWS\system32\win32k.sys
2007-03-07 23:55 ——– d——– C:\Program Files\Common Files\blizzard entertainment
2007-03-05 15:03 ——– d——– C:\Program Files\winpcap
2007-03-03 20:56 1648 –a—— C:\WINDOWS\mozver.dat
2007-03-01 16:53 ——– d——– C:\Program Files\Common Files\lightscribe
2007-02-27 19:27 37270 –a—— C:\WINDOWS\system32\oggdsuninst.exe
2007-02-25 17:22 ——– d——– C:\DOCUME~1\Kevin\APPLIC~1\vso
2007-02-23 00:29 524288 –a—— C:\WINDOWS\system32\divxsm.exe
2007-02-23 00:29 3596288 –a—— C:\WINDOWS\system32\qt-dx331.dll
2007-02-23 00:29 200704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-02-23 00:29 1044480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-02-23 00:25 823296 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2007-02-23 00:25 823296 –a—— C:\WINDOWS\system32\divx_xx07.dll
2007-02-23 00:25 802816 –a—— C:\WINDOWS\system32\divx_xx11.dll
2007-02-23 00:25 73728 –a—— C:\WINDOWS\system32\dpl100.dll
2007-02-23 00:25 639066 –a—— C:\WINDOWS\system32\divx.dll
2007-02-23 00:25 593920 –a—— C:\WINDOWS\system32\dpugui11.dll
2007-02-23 00:25 57344 –a—— C:\WINDOWS\system32\dpv11.dll
2007-02-23 00:25 53248 –a–c— C:\WINDOWS\system32\dpugui10.dll
2007-02-23 00:25 344064 –a—— C:\WINDOWS\system32\dpus11.dll
2007-02-23 00:25 294912 –a–c— C:\WINDOWS\system32\dpu10.dll
2007-02-23 00:25 294912 –a—— C:\WINDOWS\system32\dpu11.dll
2007-02-23 00:25 196608 –a—— C:\WINDOWS\system32\dtu100.dll
2007-02-22 23:04 ——– d——– C:\Program Files\Common Files\wise installation wizard
2007-02-20 23:34 76440 –a—— C:\WINDOWS\war3unin.dat
2007-02-20 14:38 2829 –a—— C:\WINDOWS\war3unin.pif
2007-02-20 14:38 139264 –a—— C:\WINDOWS\war3unin.exe
2007-02-20 12:15 ——– d–h—– C:\Program Files\installshield installation information
2007-02-20 00:30 81920 –a—— C:\DOCUME~1\Kevin\APPLIC~1\ezpinst.exe
2007-02-20 00:30 7176 –a—— C:\DOCUME~1\Kevin\APPLIC~1\pcouffin.cat
2007-02-20 00:30 47360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2007-02-20 00:30 47360 –a—— C:\DOCUME~1\Kevin\APPLIC~1\pcouffin.sys
2007-02-20 00:30 34 –a—— C:\DOCUME~1\Kevin\APPLIC~1\pcouffin.log
2007-02-20 00:30 1144 –a—— C:\DOCUME~1\Kevin\APPLIC~1\pcouffin.inf
2007-02-20 00:23 ——– d——– C:\Program Files\yahoo!
2007-02-17 22:23 6 –a—— C:\DOCUME~1\Kevin\APPLIC~1\dm.ini
2007-02-17 22:23 1222 –a—— C:\DOCUME~1\Kevin\APPLIC~1\adobedlm.log
2007-02-17 18:06 14 –a—— C:\WINDOWS\system32\systeminfo3.dll
2007-02-17 18:06 ——– d——– C:\DOCUME~1\Kevin\APPLIC~1\dvdxstudio
2007-02-17 16:20 ——– d——– C:\DOCUME~1\Kevin\APPLIC~1\dvdcss
2007-02-16 22:19 295 –a—— C:\WINDOWS\ereg072.dat
2007-02-16 20:09 ——– d——– C:\DOCUME~1\Kevin\APPLIC~1\help
2007-02-15 21:40 124472 –a—— C:\WINDOWS\system32\divxcodecupdatechecker.exe
2007-02-13 14:29 147456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-02-05 16:17 185344 –a—— C:\WINDOWS\system32\upnphost.dll
2007-01-25 21:19 129784 ——— C:\WINDOWS\system32\pxafs.dll
2007-01-25 21:19 118520 ——— C:\WINDOWS\system32\pxinsi64.exe
2007-01-25 21:19 116472 ——— C:\WINDOWS\system32\pxcpyi64.exe
2007-01-25 12:17 10022 –ahsc— C:\WINDOWS\system32\kgygaavl.sys
2007-01-16 18:50 1755 –a—— C:\DOCUME~1\Kevin\APPLIC~1\sas7_000.dat


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Skype"="\"D:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"Bej2Setup_TryGames.exe"="C:\\DOWNLO~1\\BEJ2SE~1.EXE /r"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"BitTorrent"="\"D:\\Program Files\\BitTorrent\\bittorrent.exe\" –force_start_minimized"
"zzfk"="C:\\Program Files\\InetGet2\\stub_109_4_0_4_0.exe"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb07.exe"
"UserFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,75,00
"StorageGuard"="\"C:\\Program Files\\VERITAS Software\\Update Manager\\sgtray.exe\" /r"
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"ProfileWatcher"=hex(2):64,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,65,73,5c,50,\
72,6f,66,69,6c,65,57,61,74,63,68,65,72,5c,70,72,6f,66,69,6c,65,77,61,74,63,\
68,65,72,2e,65,78,65,00
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"iTunesHelper"="\"D:\\Program Files\\iTunes\\iTunesHelper.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"!AVG Anti-Spyware"="\"D:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfee Guardian]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CMGrdian"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\McAfee\\McAfee Shared Components\\Guardian\\CMGrdian.exe\" /SU"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfee.InstantUpdate.Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RuLaunch"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\McAfee\\McAfee Shared Components\\Instant Updater\\RuLaunch.exe\" /STARTMONITOR"
"inimapping"="0"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\
Security Packages REG_MULTI_SZ kerberosmsv1_0schannelwdigest\
Notification Packages REG_MULTI_SZ scecli\

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService REG_MULTI_SZ DnsCache\
rpcss REG_MULTI_SZ RpcSs\
imgsvc REG_MULTI_SZ StiSvc\
termsvcs REG_MULTI_SZ TermService\
HTTPFilter REG_MULTI_SZ HTTPFilter\
DcomLaunch REG_MULTI_SZ DcomLaunchTermService\



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Symantec NetDetect.job


********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-04-15 20:59:49
C:\ComboFix-quarantined-files.txt … 07-04-15 20:59
"Kevin" - 07-04-15 20:58:36 Service Pack 2
ComboFix 07-04-05.Rev3 - Running from: "C:\Program Files\Mozilla Firefox"


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\outerinfo
C:\WINDOWS\S2V2aW4
C:\Program Files\Common Files\{E8CF1~1
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\DOCUME~1\Kevin
C:\qoobox\purity\DOCUME~1\Kevin\APPLIC~1
C:\qoobox\purity\DOCUME~1\Kevin\APPLIC~1\from.txt
C:\qoobox\purity\DOCUME~1\Kevin\APPLIC~1\SCURIT~1
C:\qoobox\purity\Program Files\FNTS~1
C:\qoobox\purity\Program Files\ICROSO~1.NET
C:\qoobox\purity\Program Files\FNTS~1\F?nts
C:\qoobox\purity\WINDOWS\system32\STEM32~1


((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\cmdService
——-\nm
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\LEGACY_NM


((((((((((((((((((((((((((((((( Files Created from 2007-03-15 to 2007-04-15 ))))))))))))))))))))))))))))))))))


2007-04-12 22:13 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-04-01 23:51 d——– C:\Program Files\Microsoft ActiveSync
2007-04-01 18:54 d——– C:\DOCUME~1\Kevin\APPLIC~1\Pegasys Inc
2007-03-31 22:31 53,248 –a—— C:\WINDOWS\system32\GenSvcInst.exe
2007-03-31 22:31 33,408 –a—— C:\WINDOWS\system32\drivers\CDRBSDRV.SYS
2007-03-31 22:31 118,784 –a—— C:\WINDOWS\system32\bgsvcgen.exe
2007-03-31 14:24 d——– C:\DOCUME~1\Kevin\APPLIC~1\Publish Providers
2007-03-31 14:21 d——– C:\DOCUME~1\Kevin\APPLIC~1\Sony
2007-03-31 14:19 d——– C:\Program Files\Vstplugins
2007-03-31 14:19 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony
2007-03-31 06:36 d——– C:\DOCUME~1\Kevin\APPLIC~1\Sony Setup
2007-03-30 16:36 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-04-15 18:20 ——– d——– C:\DOCUME~1\Kevin\APPLIC~1\bittorrent
2007-04-05 20:13 ——– d——– C:\DOCUME~1\Kevin\APPLIC~1\limewire
2007-03-29 23:00 1124 –a—— C:\DOCUME~1\Kevin\APPLIC~1\wklnhst.dat
2007-03-17 09:43 292864 –a—— C:\WINDOWS\system32\winsrv.dll
2007-03-08 11:36 577536 –a—— C:\WINDOWS\system32\user32.dll
2007-03-08 11:36 40960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-03-08 11:36 281600 –a—— C:\WINDOWS\system32\gdi32.dll
2007-03-08 09:47 1843584 –a—— C:\WINDOWS\system32\win32k.sys
2007-03-07 23:55 ——– d——– C:\Program Files\Common Files\blizzard entertainment
2007-03-05 15:03 ——– d——– C:\Program Files\winpcap
2007-03-03 20:56 1648 –a—— C:\WINDOWS\mozver.dat
2007-03-01 16:53 ——– d——– C:\Program Files\Common Files\lightscribe
2007-02-27 19:27 37270 –a—— C:\WINDOWS\system32\oggdsuninst.exe
2007-02-25 17:22 ——– d——– C:\DOCUME~1\Kevin\APPLIC~1\vso
2007-02-23 00:29 524288 –a—— C:\WINDOWS\system32\divxsm.exe
2007-02-23 00:29 3596288 –a—— C:\WINDOWS\system32\qt-dx331.dll
2007-02-23 00:29 200704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-02-23 00:29 1044480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-02-23 00:25 823296 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2007-02-23 00:25 823296 –a—— C:\WINDOWS\system32\divx_xx07.dll
2007-02-23 00:25 802816 –a—— C:\WINDOWS\system32\divx_xx11.dll
2007-02-23 00:25 73728 –a—— C:\WINDOWS\system32\dpl100.dll
2007-02-23 00:25 639066 –a—— C:\WINDOWS\system32\divx.dll
2007-02-23 00:25 593920 –a—— C:\WINDOWS\system32\dpugui11.dll
2007-02-23 00:25 57344 –a—— C:\WINDOWS\system32\dpv11.dll
2007-02-23 00:25 53248 –a–c— C:\WINDOWS\system32\dpugui10.dll
2007-02-23 00:25 344064 –a—— C:\WINDOWS\system32\dpus11.dll
2007-02-23 00:25 294912 –a–c— C:\WINDOWS\system32\dpu10.dll
2007-02-23 00:25 294912 –a—— C:\WINDOWS\system32\dpu11.dll
2007-02-23 00:25 196608 –a—— C:\WINDOWS\system32\dtu100.dll
2007-02-22 23:04 ——– d——– C:\Program Files\Common Files\wise installation wizard
2007-02-20 23:34 76440 –a—— C:\WINDOWS\war3unin.dat
2007-02-20 14:38 2829 –a—— C:\WINDOWS\war3unin.pif
2007-02-20 14:38 139264 –a—— C:\WINDOWS\war3unin.exe
2007-02-20 12:15 ——– d–h—– C:\Program Files\installshield installation information
2007-02-20 00:30 81920 –a—— C:\DOCUME~1\Kevin\APPLIC~1\ezpinst.exe
2007-02-20 00:30 7176 –a—— C:\DOCUME~1\Kevin\APPLIC~1\pcouffin.cat
2007-02-20 00:30 47360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2007-02-20 00:30 47360 –a—— C:\DOCUME~1\Kevin\APPLIC~1\pcouffin.sys
2007-02-20 00:30 34 –a—— C:\DOCUME~1\Kevin\APPLIC~1\pcouffin.log
2007-02-20 00:30 1144 –a—— C:\DOCUME~1\Kevin\APPLIC~1\pcouffin.inf
2007-02-20 00:23 ——– d——– C:\Program Files\yahoo!
2007-02-17 22:23 6 –a—— C:\DOCUME~1\Kevin\APPLIC~1\dm.ini
2007-02-17 22:23 1222 –a—— C:\DOCUME~1\Kevin\APPLIC~1\adobedlm.log
2007-02-17 18:06 14 –a—— C:\WINDOWS\system32\systeminfo3.dll
2007-02-17 18:06 ——– d——– C:\DOCUME~1\Kevin\APPLIC~1\dvdxstudio
2007-02-17 16:20 ——– d——– C:\DOCUME~1\Kevin\APPLIC~1\dvdcss
2007-02-16 22:19 295 –a—— C:\WINDOWS\ereg072.dat
2007-02-16 20:09 ——– d——– C:\DOCUME~1\Kevin\APPLIC~1\help
2007-02-15 21:40 124472 –a—— C:\WINDOWS\system32\divxcodecupdatechecker.exe
2007-02-13 14:29 147456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-02-05 16:17 185344 –a—— C:\WINDOWS\system32\upnphost.dll
2007-01-25 21:19 129784 ——— C:\WINDOWS\system32\pxafs.dll
2007-01-25 21:19 118520 ——— C:\WINDOWS\system32\pxinsi64.exe
2007-01-25 21:19 116472 ——— C:\WINDOWS\system32\pxcpyi64.exe
2007-01-25 12:17 10022 –ahsc— C:\WINDOWS\system32\kgygaavl.sys
2007-01-16 18:50 1755 –a—— C:\DOCUME~1\Kevin\APPLIC~1\sas7_000.dat


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Skype"="\"D:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"Bej2Setup_TryGames.exe"="C:\\DOWNLO~1\\BEJ2SE~1.EXE /r"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"BitTorrent"="\"D:\\Program Files\\BitTorrent\\bittorrent.exe\" –force_start_minimized"
"zzfk"="C:\\Program Files\\InetGet2\\stub_109_4_0_4_0.exe"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb07.exe"
"UserFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,75,00
"StorageGuard"="\"C:\\Program Files\\VERITAS Software\\Update Manager\\sgtray.exe\" /r"
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"ProfileWatcher"=hex(2):64,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,65,73,5c,50,\
72,6f,66,69,6c,65,57,61,74,63,68,65,72,5c,70,72,6f,66,69,6c,65,77,61,74,63,\
68,65,72,2e,65,78,65,00
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"iTunesHelper"="\"D:\\Program Files\\iTunes\\iTunesHelper.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"!AVG Anti-Spyware"="\"D:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfee Guardian]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CMGrdian"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\McAfee\\McAfee Shared Components\\Guardian\\CMGrdian.exe\" /SU"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfee.InstantUpdate.Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RuLaunch"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\McAfee\\McAfee Shared Components\\Instant Updater\\RuLaunch.exe\" /STARTMONITOR"
"inimapping"="0"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\
Security Packages REG_MULTI_SZ kerberosmsv1_0schannelwdigest\
Notification Packages REG_MULTI_SZ scecli\

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService REG_MULTI_SZ DnsCache\
rpcss REG_MULTI_SZ RpcSs\
imgsvc REG_MULTI_SZ StiSvc\
termsvcs REG_MULTI_SZ TermService\
HTTPFilter REG_MULTI_SZ HTTPFilter\
DcomLaunch REG_MULTI_SZ DcomLaunchTermService\



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Symantec NetDetect.job


********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-04-15 20:59:49
C:\ComboFix-quarantined-files.txt … 07-04-15 20:59
Hello :) You ran only combofix and you need to also run SDfix. That's way run sdfix and after that post a fresh HijackThis log and logfile of SDfix (contents of Report.txt). ~Markka~
Ooops sorry. posted one of them twice. SDFix: Version 1.78 Run by [removed] Microsoft Windows XP [Version 5.1.2600] Running From: C:\DOCUME~1\Kevin\Desktop\SDFix Safe Mode: Checking Services: Restoring Windows Registry Values Restoring Windows Default Hosts File Rebooting… Normal Mode: Checking Files: No Trojan Files Found… Removing Temp Files ADS Check: Checking if ADS is attached to system32 Folder C:\WINDOWS\system32 No streams found. Checking if ADS is attached to svchost.exe C:\WINDOWS\system32\svchost.exe No streams found. Final Check: Remaining Services: —————— Authorized Application Key Export: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "D:\\Program Files\\LimeWire\\LimeWire.exe"="D:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire" "D:\\Program Files\\BitTorrent\\bittorrent.exe"="D:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:bittorrent" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" Remaining Files: ————— Checking For Files with Hidden Attributes: C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe C:\WINDOWS\system32\KGyGaAvL.sys C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\f0c43c883b45dd5bc3e231479dfed214\BITC.tmp C:\WINDOWS\system32\config\default.tmp.LOG C:\WINDOWS\system32\config\software.tmp.LOG C:\WINDOWS\system32\config\system.tmp.LOG Finished
Logfile of HijackThis v1.99.1
Scan saved at 1:55:22 AM, on 4/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Documents and Settings\Kevin\Desktop\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
d:\Program Files\WinAce\WinAce.exe
C:\Documents and Settings\Kevin\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {F169934B-55AC-797A-D34D-29909DA73E9E} - C:\WINDOWS\system32\zabnrv.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ProfileWatcher] d:\Program Files\ProfileWatcher\profilewatcher.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Bej2Setup_TryGames.exe] C:\DOWNLO~1\BEJ2SE~1.EXE /r
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BitTorrent] "D:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [zzfk] C:\Program Files\InetGet2\stub_109_4_0_4_0.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Device Detector 3.lnk = C:\Documents and Settings\Kevin\Desktop\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{45EDC88D-A29A-4FDA-BE24-012F4BAB686A}: NameServer = 192.168.0.1,192.168.0.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{45EDC88D-A29A-4FDA-BE24-012F4BAB686A}: NameServer = 192.168.0.1,192.168.0.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{45EDC88D-A29A-4FDA-BE24-012F4BAB686A}: NameServer = 192.168.0.1,192.168.0.2
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)
You don't have a firewall on your computer. Here are free and good firewalls: (Install only one)

Comodo
OutPost
Kerio
Sygate
ZoneAlarm


You don't have an antivirus-software on your computer. Here are free and good antivirus-softwares: (Install only one)

Antivir
Avast!
AVG

Make sure that SpyBot S&D is dsabled !

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.


Move HijakThis.exe into an own folder -> C:\HJT\

Open HijackThis, Click Do a system scan only, checkmark these. Then close all others windows except HijackThis and press fix checked.

O3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {F169934B-55AC-797A-D34D-29909DA73E9E} - C:\WINDOWS\system32\zabnrv.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O4 - HKCU\..\Run: [Bej2Setup_TryGames.exe] C:\DOWNLO~1\BEJ2SE~1.EXE /r
O4 - HKCU\..\Run: [zzfk] C:\Program Files\InetGet2\stub_109_4_0_4_0.exe
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\



Delete these files: (if found)
C:\DOWNLO~1\Bej2Setup_TryGames.exe
C:\Program Files\InetGet2\stub_109_4_0_4_0.exe



Make your hidden files visible:
  • Click start
  • Click my computer
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labeled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and shutdown My Computer.

Please download ATF-cleaner and save it to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

    If you use Firefox browser:

  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser:

  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
  • Click Exit on the Main menu to close the program.

Please then reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.



Post:
- A fresh HijackThis log
- AVG's log
Before I continue with these new instructions I would like to know if it is really important to move the files you listed above from my D: drive to my C: I have partitioned out my computer so that only the operating system is on C: and that drive has limited space. I could pry fit them in C: but I try to avoid putting as much as I can onto that drive.
——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 5:55:06 PM 4/17/2007 + Scan result: D:\System Volume Information\_restore{25684326-DE0F-41AF-8FA6-DF50FE24E735}\RP639\A0079450.exe -> Adware.Agent : Cleaned. C:\System Volume Information\_restore{25684326-DE0F-41AF-8FA6-DF50FE24E735}\RP639\A0079447.exe -> Adware.PurityScan : Cleaned. C:\System Volume Information\_restore{25684326-DE0F-41AF-8FA6-DF50FE24E735}\RP639\A0079448.dll -> Adware.PurityScan : Cleaned. C:\System Volume Information\_restore{25684326-DE0F-41AF-8FA6-DF50FE24E735}\RP639\A0079446.dll -> Adware.Softomate : Cleaned. C:\System Volume Information\_restore{25684326-DE0F-41AF-8FA6-DF50FE24E735}\RP639\A0079449.exe -> Adware.ValueAd : Cleaned. C:\System Volume Information\_restore{25684326-DE0F-41AF-8FA6-DF50FE24E735}\RP639\A0079442.exe -> Backdoor.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{25684326-DE0F-41AF-8FA6-DF50FE24E735}\RP639\A0079439.exe -> Downloader.Age : Cleaned with backup (quarantined). C:\System Volume Information\_restore{25684326-DE0F-41AF-8FA6-DF50FE24E735}\RP639\A0079443.exe -> Downloader.Agent.bfu : Cleaned with backup (quarantined). C:\System Volume Information\_restore{25684326-DE0F-41AF-8FA6-DF50FE24E735}\RP639\A0079438.exe -> Downloader.PurityScan.eh : Cleaned with backup (quarantined). :mozilla.196:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.175:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.176:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.202:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.101:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.204:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.207:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.208:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.209:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.88:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.89:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.90:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.91:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.48:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.152:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned. :mozilla.21:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.22:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.23:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.188:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.189:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.190:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.191:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.25:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.80:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.81:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.36:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.205:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.206:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.212:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.233:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.235:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.236:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.237:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.49:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.50:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.51:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.52:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.53:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.54:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.55:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.56:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.57:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.203:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.82:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.83:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.84:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.86:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.87:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\kv524un7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. D:\System Volume Information\_restore{25684326-DE0F-41AF-8FA6-DF50FE24E735}\RP639\A0079444.exe -> Trojan.Feutel.av : Cleaned with backup (quarantined). D:\System Volume Information\_restore{25684326-DE0F-41AF-8FA6-DF50FE24E735}\RP639\A0079445.exe -> Trojan.Feutel.av : Cleaned with backup (quarantined). C:\System Volume Information\_restore{25684326-DE0F-41AF-8FA6-DF50FE24E735}\RP639\A0079440.vbs -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{25684326-DE0F-41AF-8FA6-DF50FE24E735}\RP639\A0079441.exe -> Trojan.Small : Cleaned with backup (quarantined). ::Report end
Both C:\DOWNLO~1\Bej2Setup_TryGames.exe and C:\Program Files\InetGet2\stub_109_4_0_4_0.exe were found and checked. New log:

Logfile of HijackThis v1.99.1
Scan saved at 6:08:19 PM, on 4/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\bgsvcgen.exe
D:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
D:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Messenger\msmsgs.exe
D:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Documents and Settings\Kevin\Desktop\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
D:\Program Files\Nero 7\Nero ShowTime\ShowTime.exe
C:\Documents and Settings\Kevin\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {F169934B-55AC-797A-D34D-29909DA73E9E} - C:\WINDOWS\system32\zabnrv.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ProfileWatcher] d:\Program Files\ProfileWatcher\profilewatcher.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [COMODO Firewall Pro] "D:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BitTorrent] "D:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Device Detector 3.lnk = C:\Documents and Settings\Kevin\Desktop\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{45EDC88D-A29A-4FDA-BE24-012F4BAB686A}: NameServer = 192.168.0.1,192.168.0.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{45EDC88D-A29A-4FDA-BE24-012F4BAB686A}: NameServer = 192.168.0.1,192.168.0.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{45EDC88D-A29A-4FDA-BE24-012F4BAB686A}: NameServer = 192.168.0.1,192.168.0.2
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - D:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)
Open HijackThis, Click Do a system scan only, checkmark these. Then close all others windows except HijackThis and press fix checked.

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {F169934B-55AC-797A-D34D-29909DA73E9E} - C:\WINDOWS\system32\zabnrv.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)



Your java is out of date. Update your java.

Instruction:
  • -> Go to Control panel -> Add/remove programs
  • -> Find java(s) from the list
  • -> Delete this java version via add/remove programs:
    jre1.5.0_11
  • -> Please download from here a new java and install it.
  • -> The latest java version is: Java Runtime Environment (JRE) 6u1


Please download ATF-cleaner and save it to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

    If you use Firefox browser:

  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser:

  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
  • Click Exit on the Main menu to close the program.

Kaspersky online scanner works only with IE!


Please run an online scanner with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:

    o Scan using the following Anti-Virus database:

    + Extended (If available otherwise Standard)

    o Scan Options:

    + Scan Archives
    + Scan Mail Bases

  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.




Post:

- A fresh HijackThis log
- Report of Kaspersky

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI