This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Internet Virus

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I launch ie i always get a pop-up on startup. I then get a pop up every few minutes while running ie. And also when im not running ie I get a pop up every few hours. I ahve downloaded firefox and now sometimes get pop-ups with it..the popups direct me to other sites telling me to download virus protection antispyware, etc. Here is my log

Logfile of HijackThis v1.99.1
Scan saved at 7:22:16 PM, on 6/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Xfire\xfire.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://srch-us6.hpwis.com/
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [abynipkx.exe] C:\Documents and Settings\All Users\Application Data\abynipkx.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu2000352.exe 61A847B5BBF72810329B385577FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SC2] C:\WINDOWS\system32\scchk32.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\cjvywoil.dll",forkonce
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Shell explorer driver] C:\WINDOWS\csrss.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Kuma_Tray.lnk = C:\Program Files\Kuma Games\kgsystray\Kuma_tray.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182306321608
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182306315186
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
I also think I should add in I ran a virus scan with avg, it found some trojan horses and I deleted them from the vault. Also after starting up windows I noticed some abnormal processes running so I ended them. Should I restart my computer and then get the log?

I also think I should add in I ran a virus scan with avg, it found some trojan horses and I deleted them from the vault. Also after starting up windows I noticed some abnormal processes running so I ended them. Should I restart my computer and then get the log?

Yes, reboot and post a new HJT log. :thumbup:
OK I rebooted and here is the new log:

Logfile of HijackThis v1.99.1
Scan saved at 12:51:47 AM, on 7/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Documents and Settings\All Users\Application Data\abynipkx.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\scchk32.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\csrss.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kuma Games\kgsystray\Kuma_tray.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://srch-us6.hpwis.com/
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [abynipkx.exe] C:\Documents and Settings\All Users\Application Data\abynipkx.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu2000352.exe 61A847B5BBF72810329B385577FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SC2] C:\WINDOWS\system32\scchk32.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\rlgcbtao.dll",forkonce
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Shell explorer driver] C:\WINDOWS\csrss.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Kuma_Tray.lnk = C:\Program Files\Kuma Games\kgsystray\Kuma_tray.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182306321608
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182306315186
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
ComboFix 07-06-18.2 - C:\Documents and Settings\Owner\Desktop\ComboFix.exe
"Owner" - 2007-07-02 12:01:10 - Service Pack 2 NTFS


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\pjpecrxp.dll
C:\WINDOWS\system32\winowl32.dll
C:\WINDOWS\system32\pxrcepjp.ini
C:\WINDOWS\system32\cdeeg.bak1
C:\WINDOWS\system32\cdeeg.bak2
C:\WINDOWS\system32\cdeeg.ini


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\csrss.exe
C:\WINDOWS\system32\stem32~1
C:\WINDOWS\wr.txt


((((((((((((((((((((((((( Files Created from 2007-06-02 to 2007-07-02 )))))))))))))))))))))))))))))))


2007-07-02 12:00 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-07-02 01:42 d——– C:\WINDOWS\CAVTemp
2007-07-02 01:05 1,021,504 –a—— C:\WINDOWS\system32\vete.dll
2007-07-02 00:45 128,576 –a—— C:\WINDOWS\system32\rlgcbtao.dll
2007-07-02 00:34 4,212 —h—– C:\WINDOWS\system32\zllictbl.dat
2007-07-02 00:33 77,824 –a—— C:\WINDOWS\system32\driverif.dll
2007-07-02 00:33 75,776 –a—— C:\WINDOWS\zllsputility.exe
2007-07-02 00:33 645,904 –a—— C:\WINDOWS\system32\drivers\vetmonnt.sys
2007-07-02 00:33 21,605 –a—— C:\WINDOWS\system32\drivers\vet-filt.sys
2007-07-02 00:33 15,668 –a—— C:\WINDOWS\system32\drivers\vet-rec.sys
2007-07-02 00:33 12,288 –a—— C:\WINDOWS\system32\vetntmsg.dll
2007-07-02 00:33 115,088 –a—— C:\WINDOWS\system32\drivers\vetfddnt.sys
2007-07-02 00:33 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2007-07-02 00:32 d——– C:\WINDOWS\system32\ZoneLabs
2007-07-02 00:32 d——– C:\WINDOWS\Internet Logs
2007-06-29 14:31 23,552 –a—— C:\WINDOWS\system32\wmimgr32.dll
2007-06-27 01:02 d——– C:\Program Files\KONAMI
2007-06-26 18:29 d——– C:\Program Files\Hide My IP 2007
2007-06-26 09:56 66,112 –a—— C:\WINDOWS\system32\ulmcckao.dll
2007-06-26 01:43 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\pcgdemo
2007-06-26 01:40 d——– C:\Program Files\PC Guard for Win32 V5 DEMO
2007-06-26 01:32 d——– C:\Program Files\LICENCE PROTECTOR
2007-06-26 01:27 20,480 –a—— C:\WINDOWS\system32\H@tKeysH@@k.DLL
2007-06-26 01:25 d——– C:\myLicenses
2007-06-26 01:15 d——– C:\Program Files\Info2000
2007-06-26 01:15 d——– C:\Program Files\Common Files\Info2000Libraries
2007-06-25 12:17 684 –a—— C:\WINDOWS\mozver.dat
2007-06-24 16:52 5,888 ——— C:\WINDOWS\system32\drivers\imagedrv.sys
2007-06-24 16:52 127,488 ——— C:\WINDOWS\system32\drivers\imagesrv.sys
2007-06-24 16:51 476,320 ——— C:\WINDOWS\system32\ImagXpr7.dll
2007-06-24 16:51 471,040 ——— C:\WINDOWS\system32\ImagXRA7.dll
2007-06-24 16:51 364,544 ——— C:\WINDOWS\system32\TwnLib4.dll
2007-06-24 16:51 262,144 ——— C:\WINDOWS\system32\ImagXR7.dll
2007-06-24 16:51 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2007-06-24 16:51 106,496 –a—— C:\WINDOWS\system32\TwnLib20.dll
2007-06-24 16:51 1,568,768 ——— C:\WINDOWS\system32\ImagX7.dll
2007-06-24 16:51 d——– C:\Program Files\Common Files\Ahead
2007-06-24 12:50 d——– C:\WINDOWS\network diagnostic
2007-06-24 12:49 d——– C:\79e5c1ed49feef10305c
2007-06-24 12:28 d——– C:\DOCUME~1\Owner\Incomplete
2007-06-24 12:28 d——– C:\DOCUME~1\Owner\APPLIC~1\Google
2007-06-24 12:04 d——– C:\Program Files\Cucusoft
2007-06-24 11:17 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-06-24 11:17 d——– C:\WINDOWS\system32\LogFiles
2007-06-24 03:30 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-06-24 00:09 d——– C:\DOCUME~1\Owner\APPLIC~1\LimeWire
2007-06-24 00:05 d——– C:\Program Files\LimeWire
2007-06-23 23:43 56 -r-hs—- C:\WINDOWS\system32\AE8D220D52.sys
2007-06-23 23:43 5,852 –ahs—- C:\WINDOWS\system32\KGyGaAvL.sys
2007-06-23 23:43 d——– C:\Program Files\Google
2007-06-23 23:42 d——– C:\Program Files\DivX
2007-06-23 23:35 d——– C:\Program Files\WinAVI Video Converter
2007-06-23 23:30 d——– C:\WINDOWS\system32\rbaembmn
2007-06-23 23:10 99,072 –a—— C:\rbaembmn1.exe
2007-06-23 23:10 94,976 –a—— C:\rbaembmn3.exe
2007-06-23 23:10 286,720 –a—— C:\WINDOWS\system32\scchk32.exe
2007-06-23 23:10 100,096 –a—— C:\rbaembmn2.exe
2007-06-23 23:07 d——– C:\Program Files\SmartDVDCreatorPro
2007-06-23 20:38 d——– C:\Program Files\AviSynth 2.5
2007-06-23 20:37 d——– C:\Program Files\Avi2Dvd
2007-06-23 17:31 d——– C:\Program Files\Ahead
2007-06-23 09:39 4,672 –a—— C:\WINDOWS\system32\jwjwenue.exe
2007-06-22 23:51 d——– C:\Program Files\KGC Website
2007-06-22 23:48 d——– C:\Program Files\FTP Commander Pro
2007-06-22 23:19 d——– C:\Program Files\Easy Graphic Converter
2007-06-22 23:08 d——– C:\Program Files\Common Files\Adobe Systems Shared
2007-06-22 23:08 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
2007-06-22 21:33 266,336 –a—— C:\WINDOWS\system32\geedc.dll
2007-06-22 21:28 31,254 –a—— C:\WINDOWS\system32\pmnnoom.dll
2007-06-22 21:28 17,408 –a—— C:\qfalpjip.exe
2007-06-22 21:27 57,344 –a—— C:\DOCUME~1\ALLUSE~1\APPLIC~1\abynipkx.exe
2007-06-22 21:27 31,254 –a—— C:\WINDOWS\system32\urqonlj.dll
2007-06-22 21:27 31,254 –a—— C:\WINDOWS\system32\mljigec.dll
2007-06-22 20:11 d–h—– C:\WINDOWS\$hf_mig$
2007-06-22 20:04 d——– C:\DOCUME~1\Owner\APPLIC~1\Ahead
2007-06-22 20:04 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
2007-06-22 20:02 545,280 –a—— C:\WINDOWS\system32\win47812.dll
2007-06-22 20:00 d——– C:\Program Files\Nero
2007-06-22 19:58 d——– C:\WINDOWS\RegisteredPackages
2007-06-22 16:04 545,280 –a—— C:\WINDOWS\system32\win5014.dll
2007-06-22 12:02 545,280 –a—— C:\WINDOWS\system32\win42334.dll
2007-06-22 08:00 545,280 –a—— C:\WINDOWS\system32\win10275.dll
2007-06-22 04:04 545,280 –a—— C:\WINDOWS\system32\win20399.dll
2007-06-22 00:02 545,280 –a—— C:\WINDOWS\system32\win61219.dll
2007-06-21 21:50 d——– C:\DOCUME~1\Owner\APPLIC~1\dvdcss
2007-06-21 20:05 545,280 –a—— C:\WINDOWS\system32\win15245.dll
2007-06-21 19:56 d——– C:\DOCUME~1\Owner\APPLIC~1\teamspeak2
2007-06-21 16:34 545,280 –a—— C:\WINDOWS\system32\win64776.dll
2007-06-21 16:28 950,272 –a—— C:\WINDOWS\system32\INetFlashDll.dll
2007-06-21 16:28 40,960 –a—— C:\WINDOWS\system32\FlxGdFR.dll
2007-06-21 16:28 158,213 –a—— C:\WINDOWS\system32\MSCmCDE.dll
2007-06-21 16:28 141,312 –a—— C:\WINDOWS\system32\MSCmCFR.dll
2007-06-21 16:28 d——– C:\Program Files\SWF Viewer
2007-06-21 09:50 d——– C:\Program Files\Ares
2007-06-21 09:43 d——– C:\WINDOWS\system32\AGEIA
2007-06-21 09:43 d——– C:\Program Files\AGEIA Technologies
2007-06-20 18:56 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-06-20 17:26 d——– C:\DOCUME~1\Owner\APPLIC~1\vlc


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-27 05:02:53 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-06-24 18:53:03 ——– d—–w C:\DOCUME~1\Owner\APPLIC~1\VERITAS
2007-06-23 03:00:24 ——– d—–w C:\Program Files\Common Files\InstallShield
2007-06-20 03:29:59 ——– d—–w C:\Program Files\Messenger
2007-06-20 03:29:41 ——– d—–w C:\Program Files\Movie Maker
2007-06-20 03:27:45 ——– d—–w C:\Program Files\Windows NT
2007-06-20 02:31:35 ——– d—–w C:\Program Files\Common Files\Symantec Shared
2007-06-20 02:31:17 ——– d—–w C:\Program Files\Symantec
2007-06-20 02:24:34 ——– d–h–w C:\Program Files\WindowsUpdate
2007-06-20 02:16:29 ——– d—–w C:\Program Files\Arcsoft
2007-04-23 00:15:18 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2007-04-23 00:15:18 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2007-04-17 02:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:43:44 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:43:40 208,248 —-a-w C:\WINDOWS\system32\muweb.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-03-02 22:02]
{0B1C8103-1696-4835-A115-50DB52D2A72F}=C:\WINDOWS\system32\geedc.dll [2007-06-22 21:33]
{1F6581D5-AA53-4b73-A6F9-41420C6B61F1}=C:\WINDOWS\system32\ulmcckao.dll [2007-06-26 09:56]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{7C24493F-3D23-4258-9426-42C5FC3B8211}=C:\WINDOWS\system32\mljigec.dll [2007-06-22 21:27]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" []
"nwiz"="nwiz.exe" [2002-05-03 20:06 C:\WINDOWS\system32\nwiz.exe]
"CamMonitor"="c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [2002-06-18 02:11]
"KBD"="C:\HP\KBD\KBD.EXE" [2001-07-07 00:56]
"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [2002-05-09 11:01]
"DDCM"="C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" [2002-06-08 04:18]
"DDCActiveMenu"="C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" [2002-06-08 04:20]
"ATIPTA"="atiptaxx.exe" [2002-06-21 16:17 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 C:\WINDOWS\ALCXMNTR.EXE]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 16:41]
"abynipkx.exe"="C:\Documents and Settings\All Users\Application Data\abynipkx.exe" [2007-06-22 21:27]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-06-22 21:35]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2006-05-31 17:52]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 03:56]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" []
"Shell explorer driver"="C:\WINDOWS\csrss.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{7C24493F-3D23-4258-9426-42C5FC3B8211}"="C:\WINDOWS\system32\mljigec.dll" [2007-06-22 21:27]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedc]
C:\WINDOWS\system32\geedc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljigec]
mljigec.dll


Contents of the 'Scheduled Tasks' folder
2002-07-27 03:33:50 C:\WINDOWS\tasks\Symantec NetDetect.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-02 12:15:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-02 12:31:26 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-02 12:31

— E O F —
Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe


Launch Notepad (Start>All Programs>Accessories), and copy/paste all the Quoted REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: * files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{0B1C8103-1696-4835-A115-50DB52D2A72F}"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{1F6581D5-AA53-4b73-A6F9-41420C6B61F1}"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{7C24493F-3D23-4258-9426-42C5FC3B8211}"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\abynipkx.exe]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\]
"Shell explorer driver"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{7C24493F-3D23-4258-9426-42C5FC3B8211}"=-

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedc]

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljigec]

Save this as fix.reg Choose to save as *all files and place it on your desktop.
It should look like this: [external image: Posted Image]
Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.
(In case you are unsure how to create a reg file, take a look here with screenshots.)


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
I let my computer start up and Zone Alarm automatically starts a scan. It picks up this virus still. When I click done it restarts, the scan may still be running when I click it. I think I shut it down before I ran the log because my computer was going really slow.
This was what the scan always picks up in the first few seconds:
[external image: Posted Image]
Shot at 2007-07-02

After closing the scan out I started internet explorer and I still get redirected asking me to install spyware dr, antivirus, etc.
[external image: Posted Image]
Shot at 2007-07-02



Logfile of HijackThis v1.99.1
Scan saved at 9:17:22 PM, on 7/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Documents and Settings\All Users\Application Data\abynipkx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kuma Games\kgsystray\Kuma_tray.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [abynipkx.exe] C:\Documents and Settings\All Users\Application Data\abynipkx.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\rrugagyd.dll",forkonce
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Kuma_Tray.lnk = C:\Program Files\Kuma Games\kgsystray\Kuma_tray.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182306321608
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182306315186
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Open the HijackThis Folder. Find the file HijackThis.exe, Right Click on the file and Select Rename. Rename Hijackthis.exe to Spyware.exe.


Next:
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt.Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
I clicked on the link below your name and downloaded Spybot search and destroy. It fixed these problems: AdRevolver Advertising.com Avenue A, Inc BlackCore CasaleMedia CureOCSolution DirectTrack DoubleClick ErrorProtectore ErrorSafe FastClick HitBox ReliableStats Smithfraud-C.Toolbar888 Statcounter SystemDoctor2006 TagASaurus Virtumonde VistaActivation.Trojan WildTangent Win32.Small.ddx Winsoftware.WinAntiVirusPro2006 Winsoftware Zedo Im going to go and do what you said now and get you a log.
ComboFix Log-

ComboFix 07-06-18.2 - C:\Documents and Settings\Owner\Desktop\ComboFix.exe
"Owner" - 2007-07-02 22:17:13 - Service Pack 2 NTFS


((((((((((((((((((((((((( Files Created from 2007-06-03 to 2007-07-03 )))))))))))))))))))))))))))))))


2007-07-02 21:44 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-02 21:10 d——– C:\WINDOWS\LastGood
2007-07-02 20:44 d——– C:\Program Files\ERUNT BACKUP
2007-07-02 13:25 128,576 –a—— C:\WINDOWS\system32\rrugagyd.dll
2007-07-02 13:14 1,843,956 —hs—- C:\WINDOWS\system32\cdeeg.bak1
2007-07-02 12:00 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-07-02 01:42 d——– C:\WINDOWS\CAVTemp
2007-07-02 01:05 1,021,504 –a—— C:\WINDOWS\system32\vete.dll
2007-07-02 00:45 128,576 –a—— C:\WINDOWS\system32\rlgcbtao.dll
2007-07-02 00:34 4,212 —h—– C:\WINDOWS\system32\zllictbl.dat
2007-07-02 00:33 77,824 –a—— C:\WINDOWS\system32\driverif.dll
2007-07-02 00:33 75,776 –a—— C:\WINDOWS\zllsputility.exe
2007-07-02 00:33 645,904 –a—— C:\WINDOWS\system32\drivers\vetmonnt.sys
2007-07-02 00:33 21,605 –a—— C:\WINDOWS\system32\drivers\vet-filt.sys
2007-07-02 00:33 15,668 –a—— C:\WINDOWS\system32\drivers\vet-rec.sys
2007-07-02 00:33 12,288 –a—— C:\WINDOWS\system32\vetntmsg.dll
2007-07-02 00:33 115,088 –a—— C:\WINDOWS\system32\drivers\vetfddnt.sys
2007-07-02 00:33 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2007-07-02 00:32 d——– C:\WINDOWS\system32\ZoneLabs
2007-07-02 00:32 d——– C:\WINDOWS\Internet Logs
2007-06-29 14:31 23,552 –a—— C:\WINDOWS\system32\wmimgr32.dll
2007-06-27 01:02 d——– C:\Program Files\KONAMI
2007-06-26 18:29 d——– C:\Program Files\Hide My IP 2007
2007-06-26 09:56 66,112 –a—— C:\WINDOWS\system32\ulmcckao.dll
2007-06-26 01:43 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\pcgdemo
2007-06-26 01:40 d——– C:\Program Files\PC Guard for Win32 V5 DEMO
2007-06-26 01:32 d——– C:\Program Files\LICENCE PROTECTOR
2007-06-26 01:25 d——– C:\myLicenses
2007-06-26 01:15 d——– C:\Program Files\Info2000
2007-06-26 01:15 d——– C:\Program Files\Common Files\Info2000Libraries
2007-06-25 12:17 684 –a—— C:\WINDOWS\mozver.dat
2007-06-24 16:52 5,888 ——— C:\WINDOWS\system32\drivers\imagedrv.sys
2007-06-24 16:52 127,488 ——— C:\WINDOWS\system32\drivers\imagesrv.sys
2007-06-24 16:51 476,320 ——— C:\WINDOWS\system32\ImagXpr7.dll
2007-06-24 16:51 471,040 ——— C:\WINDOWS\system32\ImagXRA7.dll
2007-06-24 16:51 364,544 ——— C:\WINDOWS\system32\TwnLib4.dll
2007-06-24 16:51 262,144 ——— C:\WINDOWS\system32\ImagXR7.dll
2007-06-24 16:51 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2007-06-24 16:51 106,496 –a—— C:\WINDOWS\system32\TwnLib20.dll
2007-06-24 16:51 1,568,768 ——— C:\WINDOWS\system32\ImagX7.dll
2007-06-24 16:51 d——– C:\Program Files\Common Files\Ahead
2007-06-24 12:50 d——– C:\WINDOWS\network diagnostic
2007-06-24 12:49 d——– C:\79e5c1ed49feef10305c
2007-06-24 12:28 d——– C:\DOCUME~1\Owner\Incomplete
2007-06-24 12:28 d——– C:\DOCUME~1\Owner\APPLIC~1\Google
2007-06-24 12:04 d——– C:\Program Files\Cucusoft
2007-06-24 11:17 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-06-24 11:17 d——– C:\WINDOWS\system32\LogFiles
2007-06-24 03:30 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-06-24 00:09 d——– C:\DOCUME~1\Owner\APPLIC~1\LimeWire
2007-06-24 00:05 d——– C:\Program Files\LimeWire
2007-06-23 23:43 56 -r-hs—- C:\WINDOWS\system32\AE8D220D52.sys
2007-06-23 23:43 5,852 –ahs—- C:\WINDOWS\system32\KGyGaAvL.sys
2007-06-23 23:43 d——– C:\Program Files\Google
2007-06-23 23:42 d——– C:\Program Files\DivX
2007-06-23 23:35 d——– C:\Program Files\WinAVI Video Converter
2007-06-23 23:30 d——– C:\WINDOWS\system32\rbaembmn
2007-06-23 23:10 99,072 –a—— C:\rbaembmn1.exe
2007-06-23 23:10 94,976 –a—— C:\rbaembmn3.exe
2007-06-23 23:10 286,720 –a—— C:\WINDOWS\system32\scchk32.exe
2007-06-23 23:10 100,096 –a—— C:\rbaembmn2.exe
2007-06-23 23:07 d——– C:\Program Files\SmartDVDCreatorPro
2007-06-23 20:38 d——– C:\Program Files\AviSynth 2.5
2007-06-23 20:37 d——– C:\Program Files\Avi2Dvd
2007-06-23 17:31 d——– C:\Program Files\Ahead
2007-06-23 09:39 4,672 –a—— C:\WINDOWS\system32\jwjwenue.exe
2007-06-22 23:51 d——– C:\Program Files\KGC Website
2007-06-22 23:48 d——– C:\Program Files\FTP Commander Pro
2007-06-22 23:19 d——– C:\Program Files\Easy Graphic Converter
2007-06-22 23:08 d——– C:\Program Files\Common Files\Adobe Systems Shared
2007-06-22 23:08 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
2007-06-22 21:33 266,336 –a—— C:\WINDOWS\system32\geedc.dll
2007-06-22 21:28 31,254 –a—— C:\WINDOWS\system32\pmnnoom.dll
2007-06-22 21:28 17,408 –a—— C:\qfalpjip.exe
2007-06-22 21:27 31,254 –a—— C:\WINDOWS\system32\urqonlj.dll
2007-06-22 21:27 31,254 –a—— C:\WINDOWS\system32\mljigec.dll
2007-06-22 20:11 d–h—– C:\WINDOWS\$hf_mig$
2007-06-22 20:04 d——– C:\DOCUME~1\Owner\APPLIC~1\Ahead
2007-06-22 20:04 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
2007-06-22 20:02 545,280 –a—— C:\WINDOWS\system32\win47812.dll
2007-06-22 20:00 d——– C:\Program Files\Nero
2007-06-22 19:58 d——– C:\WINDOWS\RegisteredPackages
2007-06-22 16:04 545,280 –a—— C:\WINDOWS\system32\win5014.dll
2007-06-22 12:02 545,280 –a—— C:\WINDOWS\system32\win42334.dll
2007-06-22 08:00 545,280 –a—— C:\WINDOWS\system32\win10275.dll
2007-06-22 04:04 545,280 –a—— C:\WINDOWS\system32\win20399.dll
2007-06-22 00:02 545,280 –a—— C:\WINDOWS\system32\win61219.dll
2007-06-21 21:50 d——– C:\DOCUME~1\Owner\APPLIC~1\dvdcss
2007-06-21 20:05 545,280 –a—— C:\WINDOWS\system32\win15245.dll
2007-06-21 19:56 d——– C:\DOCUME~1\Owner\APPLIC~1\teamspeak2
2007-06-21 16:34 545,280 –a—— C:\WINDOWS\system32\win64776.dll
2007-06-21 16:28 950,272 –a—— C:\WINDOWS\system32\INetFlashDll.dll
2007-06-21 16:28 40,960 –a—— C:\WINDOWS\system32\FlxGdFR.dll
2007-06-21 16:28 158,213 –a—— C:\WINDOWS\system32\MSCmCDE.dll
2007-06-21 16:28 141,312 –a—— C:\WINDOWS\system32\MSCmCFR.dll
2007-06-21 16:28 d——– C:\Program Files\SWF Viewer
2007-06-21 09:50 d——– C:\Program Files\Ares
2007-06-21 09:43 d——– C:\WINDOWS\system32\AGEIA


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-27 05:02:53 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-06-24 18:53:03 ——– d—–w C:\DOCUME~1\Owner\APPLIC~1\VERITAS
2007-06-23 03:00:24 ——– d—–w C:\Program Files\Common Files\InstallShield
2007-06-20 03:29:59 ——– d—–w C:\Program Files\Messenger
2007-06-20 03:29:41 ——– d—–w C:\Program Files\Movie Maker
2007-06-20 03:27:45 ——– d—–w C:\Program Files\Windows NT
2007-06-20 02:31:35 ——– d—–w C:\Program Files\Common Files\Symantec Shared
2007-06-20 02:31:17 ——– d—–w C:\Program Files\Symantec
2007-06-20 02:24:34 ——– d–h–w C:\Program Files\WindowsUpdate
2007-06-20 02:16:29 ——– d—–w C:\Program Files\Arcsoft
2007-04-23 00:15:18 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2007-04-23 00:15:18 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2007-04-17 02:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:43:44 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:43:40 208,248 —-a-w C:\WINDOWS\system32\muweb.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-03-02 22:02]
{1F6581D5-AA53-4b73-A6F9-41420C6B61F1}=C:\WINDOWS\system32\ulmcckao.dll [2007-06-26 09:56]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{7854CD09-84FD-4100-BD79-60331692E036}=C:\WINDOWS\system32\geedc.dll [2007-06-22 21:33]
{7C24493F-3D23-4258-9426-42C5FC3B8211}=C:\WINDOWS\system32\mljigec.dll [2007-06-22 21:27]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" []
"nwiz"="nwiz.exe" [2002-05-03 20:06 C:\WINDOWS\system32\nwiz.exe]
"CamMonitor"="c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [2002-06-18 02:11]
"KBD"="C:\HP\KBD\KBD.EXE" [2001-07-07 00:56]
"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [2002-05-09 11:01]
"DDCM"="C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" [2002-06-08 04:18]
"DDCActiveMenu"="C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" [2002-06-08 04:20]
"ATIPTA"="atiptaxx.exe" [2002-06-21 16:17 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 C:\WINDOWS\ALCXMNTR.EXE]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 16:41]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-06-22 21:35]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2006-05-31 17:52]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 03:56]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{7C24493F-3D23-4258-9426-42C5FC3B8211}"="C:\WINDOWS\system32\mljigec.dll" [2007-06-22 21:27]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedc]
C:\WINDOWS\system32\geedc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljigec]
mljigec.dll


Contents of the 'Scheduled Tasks' folder
2002-07-27 03:33:50 C:\WINDOWS\tasks\Symantec NetDetect.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-02 22:24:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-02 22:29:52
C:\ComboFix-quarantined-files.txt … 2007-07-02 12:31
C:\ComboFix2.txt … 2007-07-02 12:31

— E O F —











HiJackThis Log -


Logfile of HijackThis v1.99.1
Scan saved at 10:34:02 PM, on 7/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kuma Games\kgsystray\Kuma_tray.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\Spyware.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1F6581D5-AA53-4b73-A6F9-41420C6B61F1} - C:\WINDOWS\system32\ulmcckao.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7854CD09-84FD-4100-BD79-60331692E036} - C:\WINDOWS\system32\geedc.dll
O2 - BHO: (no name) - {7C24493F-3D23-4258-9426-42C5FC3B8211} - C:\WINDOWS\system32\mljigec.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Kuma_Tray.lnk = C:\Program Files\Kuma Games\kgsystray\Kuma_tray.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182306321608
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182306315186
O20 - Winlogon Notify: geedc - C:\WINDOWS\system32\geedc.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: mljigec - C:\WINDOWS\SYSTEM32\mljigec.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Open notepad and copy/paste the text in the quotebox below into it: Make sure word wrap is unchecked.

File::
C:\WINDOWS\system32\rrugagyd.dll
c:\intvuvmp.exe
C:\WINDOWS\system32\cdeeg.bak1
C:\WINDOWS\system32\rlgcbtao.dll
C:\WINDOWS\system32\wmimgr32.dll
C:\WINDOWS\system32\ulmcckao.dll
C:\79e5c1ed49feef10305c
C:\WINDOWS\system32\AE8D220D52.sys
C:\rbaembmn1.exe
C:\rbaembmn3.exe
C:\WINDOWS\system32\scchk32.exe
C:\rbaembmn2.exe
C:\WINDOWS\system32\jwjwenue.exe
C:\WINDOWS\system32\geedc.dll
C:\WINDOWS\system32\pmnnoom.dll
C:\qfalpjip.exe
C:\WINDOWS\system32\urqonlj.dll
C:\WINDOWS\system32\mljigec.dll
C:\WINDOWS\system32\win47812.dll
C:\WINDOWS\system32\win5014.dll
C:\WINDOWS\system32\win42334.dll
C:\WINDOWS\system32\win10275.dll
C:\WINDOWS\system32\win20399.dll
C:\WINDOWS\system32\win61219.dll
C:\WINDOWS\system32\win15245.dll
C:\WINDOWS\system32\win64776.dll

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1F6581D5-AA53-4b73-A6F9-41420C6B61F1}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7854CD09-84FD-4100-BD79-60331692E036}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C24493F-3D23-4258-9426-42C5FC3B8211}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{7C24493F-3D23-4258-9426-42C5FC3B8211}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedc]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljigec]


Save this as ComboFix-Do.txt


[external image: Posted Image]

Refering to the picture above, drag ComboFix-Do.txt into ComboFix.exe

Post the new combo scan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI