This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help Needed

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I think something got into my computer.
Please help me.
Thanks!

HJT Log:
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\essspk.exe
C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\Doron\Desktop\utorrent.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\lcrss.exe
C:\Program Files\Eset\nod32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - HKCU\..\RunOnce: [SWHelper] "C:\WINDOWS\system32\Macromed\Shockwave 10\PostUpdate.exe" 1014020
O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {98C53984-8BF8-4D11-9B1C-C324FCA9CADE} (Loader Class v3) - http://qcenter/qcbin/Spider90.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: MSAPI32Svc - Unknown owner - C:\WINDOWS\system32\lcrss.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\system32\PCTKRNT.SYS
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Hello doron and welcome to the TomCoyote Forums

My name is Trevuren and I will be helping you with your problem.

There is a file in your log of which I am unsure. For that reason, I need you to submit it to Jotti's for analysis.

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

C:\WINDOWS\system32\lcrss.exe

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.

Regards,

Trevuren
Hi Trevuren, Thanks for the fast replay. This is the results of the scan: File: lcrss.exe Status: POSSIBLY INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) (Note: this file was only classified as malware by scanners known to generate more false positives than the average scanner. Do not consider these results definately accurate. Also, because of this, results of this scan will not be recorded in the database.) MD5: a7dab3a0de3fb0935db7d6f9a89801e3 Packers detected: - Bit9 reports: File not found A-Squared Found nothing AntiVir Found TR/Agent.1309184.1 ArcaVir Found nothing Avast Found Win32:SdBot-3700 AVG Antivirus Found nothing BitDefender Found DeepScan:Generic.Malware.G!I!!FLWX!!Bprng.768FDE7D ClamAV Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Rising Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing
A. Download Suspicious File Packer from here.

Unzip it to your desktop. Open it and copy and paste in thee file below.
When it has created the archive on your desktop please upload that to the forum. here.

C:\WINDOWS\system32\lcrss.exe

Here are the directions for uploading the file:

Just click "New Topic", fill in the needed details and post a link to your thread here. Click the "Browse" button. Navigate to the file on your computer. When the file is listed in the window click "Post" to upload the file.

Be sure you post the link to this thread in that topic.



B. I need to get you to run the following tool just to ensure that there is no rootkit as this is a "NEW" file on the bloc:

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log

Regards,

Trevuren
Hi,

This is the link were I uploaded the file:

http://www.thespykiller.co.uk/index.php?topic=4484.0

This is the SDfix log:


SDFix: Version 1.88

Run by [removed] on Sat 06/30/2007 at 08:01 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix\SDFix

Safe Mode:
Checking Services:






Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

No Trojan Files Found




Removing Temp Files…

ADS Check:

Checking C:\WINDOWS
C:\WINDOWS
No streams found.

Checking C:\WINDOWS\system32
C:\WINDOWS\system32
No streams found.

Checking C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.

Checking C:\WINDOWS\system32\ntoskrnl.exe
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Doron\\Desktop\\utorrent.exe"="C:\\Documents and Settings\\Doron\\Desktop\\utorrent.exe:*:Enabled:æTorrent"
"D:\\Temp\\Emule_Ketamine_2006\\Emule Ketamine 2006\\emule.exe"="D:\\Temp\\Emule_Ketamine_2006\\Emule Ketamine 2006\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Emule Ketamine 2006\\emule.exe"="C:\\Program Files\\Emule Ketamine 2006\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe:*:Enabled:VPN-1 SecuRemote/SecureClient service"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe:*:Enabled:VPN-1 SecuRemote/SecureClient application"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe:*:Enabled:VPN-1 SecuRemote/SecureClient command line"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe:*:Enabled:VPN-1 SecuRemote/SecureClient SDS agent"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe:*:Enabled:VPN-1 SecuRemote/SecureClient diagnostics"
"C:\\Program Files\\THQ\\Company of Heroes\\BugReport\\BugReport.exe"="C:\\Program Files\\THQ\\Company of Heroes\\BugReport\\BugReport.exe:*:Enabled:BugReport"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\\Program Files\\Microsoft Visual Studio\\Common\\Tools\\VS-Ent98\\Vanalyzr\\VARPC.EXE"="C:\\Program Files\\Microsoft Visual Studio\\Common\\Tools\\VS-Ent98\\Vanalyzr\\VARPC.EXE:*:Enabled:Microsoft ® Visual Studio VSA RPC Event Creator"
"C:\\WINDOWS\\system32\\java.exe"="C:\\WINDOWS\\system32\\java.exe:*:Enabled:Java™ 2 Platform Standard Edition binary"
"C:\\Program Files\\Microsoft Visual Studio\\Common\\MSDev98\\Bin\\msdev.exe"="C:\\Program Files\\Microsoft Visual Studio\\Common\\MSDev98\\Bin\\msdev.exe:*:Enabled:Microsoft ® Developer Studio"
"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\javaw.exe"="C:\\Program Files\\Java\\jre1.5.0_11\\bin\\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary"
"C:\\WINDOWS\\system32\\fxsclnt.exe"="C:\\WINDOWS\\system32\\fxsclnt.exe:*:Enabled:Microsoft Fax Console"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Wolfram Research\\Mathematica\\5.2\\Mathematica.exe"="C:\\Program Files\\Wolfram Research\\Mathematica\\5.2\\Mathematica.exe:*:Enabled:Mathematica 5.2 for Students"
"C:\\Program Files\\Wolfram Research\\Mathematica\\5.2\\MathKernel.exe"="C:\\Program Files\\Wolfram Research\\Mathematica\\5.2\\MathKernel.exe:*:Enabled:Mathematica 5.2 for Students Kernel"
"C:\\Program Files\\Wolfram Research\\Mathematica\\5.2\\math.exe"="C:\\Program Files\\Wolfram Research\\Mathematica\\5.2\\math.exe:*:Enabled:math.exe"
"D:\\Portable\\MirandaPortable\\App\\miranda\\miranda32.exe"="D:\\Portable\\MirandaPortable\\App\\miranda\\miranda32.exe:*:Enabled:Miranda IM"
"C:\\Documents and Settings\\Doron\\Desktop\\Server_Thread\\Debug\\Server.exe"="C:\\Documents and Settings\\Doron\\Desktop\\Server_Thread\\Debug\\Server.exe:*:Enabled:Server"
"C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.3\\cnc3game.dat"="C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.3\\cnc3game.dat:*:Enabled:Command & Conquer 3 Tiberium Wars"
"C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.4\\cnc3game.dat"="C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.4\\cnc3game.dat:*:Enabled:Command & Conquer 3 Tiberium Wars"
"C:\\totalcmd\\Totalcmd_.exe"="C:\\totalcmd\\Totalcmd_.exe:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"D:\\Study\\™„ ‚\\‘Ž‘ˆ˜ \\š‹…š ˜™š…š\\’…ƒ„ 3\\Given TCP implementation\\Debug\\test.exe"="D:\\Study\\™„ ‚\\‘Ž‘ˆ˜ \\š‹…š ˜™š…š\\’…ƒ„ 3\\Given TCP implementation\\Debug\\test.exe:*:Enabled:test"
"D:\\Study\\™„ ‚\\‘Ž‘ˆ˜ \\š‹…š ˜™š…š\\’…ƒ„ 3\\Given TCP implementation\\Debug\\test1.exe"="D:\\Study\\™„ ‚\\‘Ž‘ˆ˜ \\š‹…š ˜™š…š\\’…ƒ„ 3\\Given TCP implementation\\Debug\\test1.exe:*:Enabled:test1"
"D:\\Study\\™„ ‚\\‘Ž‘ˆ˜ \\š‹…š ˜™š…š\\’…ƒ„ 3\\Given TCP implementation\\Debug\\client.exe"="D:\\Study\\™„ ‚\\‘Ž‘ˆ˜ \\š‹…š ˜™š…š\\’…ƒ„ 3\\Given TCP implementation\\Debug\\client.exe:*:Enabled:client"
"D:\\Study\\™„ ‚\\‘Ž‘ˆ˜ \\š‹…š ˜™š…š\\’…ƒ„ 3\\Given TCP implementation\\Debug\\server.exe"="D:\\Study\\™„ ‚\\‘Ž‘ˆ˜ \\š‹…š ˜™š…š\\’…ƒ„ 3\\Given TCP implementation\\Debug\\server.exe:*:Enabled:server"
"D:\\C Programs\\ex3\\Given TCP implementation\\Given TCP implementation\\Debug\\s.exe"="D:\\C Programs\\ex3\\Given TCP implementation\\Given TCP implementation\\Debug\\s.exe:*:Enabled:s"
"D:\\C Programs\\ex3\\Given TCP implementation\\Given TCP implementation\\Debug\\test.exe"="D:\\C Programs\\ex3\\Given TCP implementation\\Given TCP implementation\\Debug\\test.exe:*:Enabled:test"
"D:\\C Programs\\ex3\\Given TCP implementation\\Given TCP implementation\\Debug\\tests.exe"="D:\\C Programs\\ex3\\Given TCP implementation\\Given TCP implementation\\Debug\\tests.exe:*:Enabled:tests"
"D:\\C Programs\\ex3\\Given TCP implementation\\Given TCP implementation\\Debug\\testc.exe"="D:\\C Programs\\ex3\\Given TCP implementation\\Given TCP implementation\\Debug\\testc.exe:*:Enabled:testc"
"C:\\Program Files\\ICQLite\\ICQLite.exe"="C:\\Program Files\\ICQLite\\ICQLite.exe:*:Enabled:ICQ Lite"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe:*:Enabled:VPN-1 SecuRemote/SecureClient service"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe:*:Enabled:VPN-1 SecuRemote/SecureClient application"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe:*:Enabled:VPN-1 SecuRemote/SecureClient command line"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe:*:Enabled:VPN-1 SecuRemote/SecureClient SDS agent"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe:*:Enabled:VPN-1 SecuRemote/SecureClient diagnostics"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Remaining Files:
—————


Listing Files with Hidden Attributes:

C:\WINDOWS\system32\AVSredirect.dll
C:\WINDOWS\system32\cygwin1.dll
C:\WINDOWS\system32\cygz.dll
C:\WINDOWS\system32\smab.dll
C:\Documents and Settings\Doron\Application Data\U3\temp\Launchpad Removal.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\lcrss.exe
C:\WINDOWS\system32\x.264.exe

Listing User Accounts:


Administrator ASPNET Doron
Guest HelpAssistant LogMeInRemoteUser
SUPPORT_388945a0 VUSR_DS


Finished



HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 20:09:44, on 30/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\WINDOWS\system32\lcrss.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\essspk.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {98C53984-8BF8-4D11-9B1C-C324FCA9CADE} (Loader Class v3) - http://qcenter/qcbin/Spider90.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: MSAPI32Svc - Unknown owner - C:\WINDOWS\system32\lcrss.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\system32\PCTKRNT.SYS
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe


Thanks
A. To disable SpySweeper Shields
  • Open SpySweeper.
  • Click Shield Settings on the right
    (or Shields on the left, depending what screen you're on).
  • Click Internet Explorer and uncheck all items.
  • Click Windows System and uncheck all items.
  • Click Hosts File and uncheck all items.
  • Click Startup Programs and uncheck all items.
  • Close SpySweeper.

B. 1. Go to Start->Run and type in notepad and hit OK.

2. Then copy and paste the content of the following codebox into Notepad:

sc stop MSAPI32Svc
sc delete MSAPI32Svc
del delete.bat

3. Save the file as "delete.bat". Make sure to save it with the quotes.

4. Double click delete.bat.


C. Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order in which they are mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.
  • First we need to make all files and folders VISIBLE:
    • Go to start>control panel>folder options>view
    • Choose to "show hidden files and folders,"
    • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
    • Close the window with ok
  • Please RUN HijackThis.
    . Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\


  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

  • Reboot Your System in Safe Mode

    How to use the F8 method to Start Your Computer in Safe Mode

    • Restart the computer.
    • As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
    • Use the arrow keys to select the Safe mode menu item
    • Press Enter.
  • Using Windows Explorer (Windows Key + E), locate the following files, and DELETE them (if still present):

    C:\WINDOWS\system32\lcrss.exe
    C:\WINDOWS\system32\smab.dll

  • Exit Explorer, and REBOOT BACK INTO NORMAL MODE

  • Finally, RUN Hijackthis again and produce a new HJT log. Post it in the forum so we can check how everything looks now.
Regards,

Trevuren
New HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 20:54:03, on 30/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\essspk.exe
C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {98C53984-8BF8-4D11-9B1C-C324FCA9CADE} (Loader Class v3) - http://qcenter/qcbin/Spider90.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\system32\PCTKRNT.SYS
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Let us try and get rid of that 020 again.

A. Ensure that SpySweeper is still disabled

B. Run HijackThis, Scan and place a checkmark beside the following entry:

O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\

Now, with all browsers and windows closed other that HJT, click Fix checked and Exit the program.


C.
Restart your system.

D. Please post a fresh HJT log for review.

Trevuren
Logfile of HijackThis v1.99.1
Scan saved at 21:35:41, on 30/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\essspk.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {98C53984-8BF8-4D11-9B1C-C324FCA9CADE} (Loader Class v3) - http://qcenter/qcbin/Spider90.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\system32\PCTKRNT.SYS
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
A. Your log looks good . I think we should check the entire system now, just to make sure.


First download AVG AntiSpyware from HERE and save that file to your desktop.
This is a 30 day trial of the program
  • Once you have downloaded AVG AntiSpyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete, run AVG AntiSpyware and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG AntiSpyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or programs while AVG AntiSpyware is scanning, it may interfere with the scanning proccess:
  • Launch AVG AntiSpyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • AVG AntiSpyware will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close AVG AntiSpyware and reboot your system back into Normal Mode and post the results of the report scan along with a fresh HJT log for review.

Please also tell me how things are now running.

Regards,

Trevuren
Hi,


AVG log file:
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 16:59:18 01/07/2007

+ Scan result:



D:\Portable\Nero\nero_portable.exe -> Backdoor.Bifrost : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{3E9A666A-12C1-4245-B838-86455AD703F7}\RP176\A0034034.exe -> Backdoor.Bifrost : Cleaned with backup (quarantined).
D:\Temp\EvID4226Patch223d-en.zip/EvID4226Patch.exe -> Not-A-Virus.Hacktool.EvID : Cleaned with backup (quarantined).
D:\Temp\EvID4226Patch223d-en\EvID4226Patch.exe -> Not-A-Virus.Hacktool.EvID : Cleaned with backup (quarantined).
D:\Temp\make your copy of windows 100 genuine in 2 seconds.rar/Make Your Copy of Windows 100% Genuine in 2 Seconds\Port_RockXP_v4.exe/RockXP4.exe -> Not-A-Virus.PSWTool.Win32.RAS.a : Cleaned with backup (quarantined).
D:\Temp\make your copy of windows 100 genuine in 2 seconds\Make Your Copy of Windows 100% Genuine in 2 Seconds\Port_RockXP_v4.exe/RockXP4.exe -> Not-A-Virus.PSWTool.Win32.RAS.a : Cleaned with backup (quarantined).
D:\Emule\Done\אוסף.מדריכים.נאסף.על.ידי.דניאל.קוגן.[L1oNetwork.Net].rar/š…‹…š ”˜‰–„.rar/eliserver_new.exe -> Not-A-Virus.RemoteAdmin.Win32.RAdmin.21 : Cleaned with backup (quarantined).
D:\Emule\Done\אוסף.מדריכים.נאסף.על.ידי.דניאל.קוגן.[L1oNetwork.Net]\תוכנות פריצה.rar/eliserver_new.exe -> Not-A-Virus.RemoteAdmin.Win32.RAdmin.21 : Cleaned with backup (quarantined).
D:\Emule\Done\אוסף.מדריכים.נאסף.על.ידי.דניאל.קוגן.[L1oNetwork.Net]\תוכנות פריצה\eliserver_new.exe -> Not-A-Virus.RemoteAdmin.Win32.RAdmin.21 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6AC12D27-96D4-4DC6-8DE3-4640CC4F5299}\RP126\A0016559.dll -> Not-A-Virus.RemoteAdmin.Win32.RemotelyAnywhere.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6AC12D27-96D4-4DC6-8DE3-4640CC4F5299}\RP127\A0016579.dll -> Not-A-Virus.RemoteAdmin.Win32.RemotelyAnywhere.a : Cleaned with backup (quarantined).
:mozilla.189:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.190:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.191:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.192:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.428:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.480:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.629:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.88:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.89:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.90:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.91:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.92:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.364:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.365:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.366:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.371:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.372:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.528:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.529:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.363:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.367:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.368:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.369:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.370:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.207:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.669:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
C:\Documents and Settings\Doron\Cookies\doron@bfast[1].txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.703:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.780:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.50:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.51:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.52:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.241:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.242:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.243:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.244:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.245:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.246:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.247:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.845:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Castup : Cleaned.
C:\Documents and Settings\Doron\Cookies\doron@castup[1].txt -> TrackingCookie.Castup : Cleaned.
:mozilla.871:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.923:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.924:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.64:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.53:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.326:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.327:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.234:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.235:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.236:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.237:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.238:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.239:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Doron\Cookies\doron@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Doron\Cookies\[removed][1].txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.353:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.531:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.532:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.538:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.736:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.737:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.738:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.20:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.22:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.828:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Information : Cleaned.
:mozilla.43:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.210:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.211:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.12:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.13:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.438:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.208:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.349:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.350:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.193:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.194:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.195:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.827:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.523:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.524:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.525:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.526:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.534:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.546:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Doron\Cookies\doron@skype[1].txt -> TrackingCookie.Skype : Cleaned.
:mozilla.93:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.94:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.95:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.96:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.138:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.139:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.140:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.141:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.142:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.143:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.144:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.145:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.146:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.147:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.148:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.149:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.150:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.151:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.152:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.153:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.154:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.155:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.156:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.157:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.158:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.159:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.160:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.161:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.162:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.163:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.361:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Statistik-gallup : Cleaned.
C:\Documents and Settings\Doron\Cookies\doron@statistik-gallup[1].txt -> TrackingCookie.Statistik-gallup : Cleaned.
:mozilla.44:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.45:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.46:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.47:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.48:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.49:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.19:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Total-media : Cleaned.
C:\Documents and Settings\Doron\Cookies\[removed]-media[1].txt -> TrackingCookie.Total-media : Cleaned.
:mozilla.347:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.348:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.54:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.492:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.764:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.479:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.356:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.267:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.268:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.269:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.270:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.111:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.112:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.113:C:\Documents and Settings\Doron\Application Data\Mozilla\Firefox\Profiles\vermhcza.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
D:\Emule\Done\אוסף מדריכים ענק-נאסף על ידי דניאל קוג.rar/rotter - ‹‰…‰ Žš…†Ž ™Œ „އ™.mht -> Trojan.ExitWindows.e : Cleaned with backup (quarantined).
D:\Emule\Done\אוסף מדריכים ענק-נאסף על ידי דניאל קוג\rotter - כיבוי מתוזמן של המחשב.mht -> Trojan.ExitWindows.e : Cleaned with backup (quarantined).


::Report end



HJT log file:

Logfile of HijackThis v1.99.1
Scan saved at 17:03:00, on 01/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\essspk.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\mdm.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {98C53984-8BF8-4D11-9B1C-C324FCA9CADE} (Loader Class v3) - http://qcenter/qcbin/Spider90.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\system32\PCTKRNT.SYS
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
I still have some doubts about bugs remaining on your system:

Please download this file - combofix.exe by sUBs
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

Regards,

Trevuren
ComboFix log:

"Doron" - 2007-07-01 19:11:59 - ComboFix 07-07-01.3 - Service Pack 2 NTFS


((((((((((((((((((((((((( Files Created from 2007-06-01 to 2007-07-01 )))))))))))))))))))))))))))))))


2007-07-01 19:11 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-07-01 18:56 524,288 –ah—– C:\DOCUME~1\test\NTUSER.DAT
2007-07-01 08:56 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-01 00:48 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
2007-06-30 21:01 d——– C:\NVIDIA
2007-06-30 20:30 255,848 –a—— C:\WINDOWS\system32\xactengine2_6.dll
2007-06-30 20:20 d–hs—- C:\WINDOWS\ftpcache
2007-06-30 20:18 d——– C:\DOCUME~1\Doron\APPLIC~1\DAEMON Tools Pro
2007-06-29 13:19 d——– C:\Program Files\DAEMON Tools Pro
2007-06-29 13:19 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\DAEMON Tools Pro
2007-06-27 20:47 dr——- C:\DOCUME~1\Doron\My Documents?
2007-06-27 20:46 d——– C:\Program Files\ICQLite
2007-06-27 20:46 d——– C:\DOCUME~1\Doron\APPLIC~1\ICQLite
2007-06-13 15:21 29,704 –a—— C:\WINDOWS\system32\uxtuneup.dll
2007-06-10 23:19 9,464 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-06-10 23:19 9,336 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-06-10 23:19 43,528 ——— C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-06-10 23:19 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2007-06-10 23:19 d——– C:\Program Files\Winamp
2007-06-05 22:55 d——– C:\DOCUME~1\Doron\APPLIC~1\dvdcss
2007-06-04 23:38 d——– C:\Program Files\Ghostgum
2007-06-04 23:36 d——– C:\gs
2007-06-03 22:29 d——– C:\Program Files\Photodex Presenter
2007-06-03 22:29 d——– C:\Program Files\Photodex
2007-06-03 22:29 d——– C:\DOCUME~1\Doron\APPLIC~1\Netscape
2007-06-03 22:28 d——– C:\DOCUME~1\Doron\APPLIC~1\Photodex
2007-06-03 09:20 d——– C:\Program Files\Common Files\Skype


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-01 15:49:01 ——– d—–w C:\Program Files\PowerArchiver
2007-07-01 06:58:49 ——– d—–w C:\Program Files\LogMeIn
2007-07-01 00:51:31 ——– d—–w C:\Program Files\Emule Ketamine 2006
2007-06-30 18:27:20 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-06-30 17:56:29 ——– d—–w C:\DOCUME~1\Doron\APPLIC~1\uTorrent
2007-06-30 17:48:33 ——– d—–w C:\DOCUME~1\Doron\APPLIC~1\Skype
2007-06-29 10:35:12 ——– d—–w C:\Program Files\Visual Assist X
2007-06-27 13:04:59 ——– d—–w C:\Program Files\TuneUp Utilities 2007
2007-06-27 08:13:53 685,816 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-06-26 22:08:06 ——– d—–w C:\DOCUME~1\Doron\APPLIC~1\U3
2007-06-26 18:57:09 360,704 —-a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2007-06-03 07:20:21 ——– d—–w C:\Program Files\Skype
2007-05-30 18:16:51 ——– d—–w C:\Program Files\Google
2007-05-30 15:25:04 73 —-a-w C:\WINDOWS\system32\ssprs.dll
2007-05-30 15:24:55 205 —-a-w C:\WINDOWS\system32\lsprst7.dll
2007-05-28 08:39:07 1,903 —-a-w C:\WINDOWS\mozver.dat
2007-05-26 21:49:37 83,552 —-a-w C:\WINDOWS\system32\LMIRfsClientNP.dll
2007-05-26 21:49:30 26,176 —-a-w C:\WINDOWS\system32\LMIport.dll
2007-05-26 21:49:29 10,304 —-a-w C:\WINDOWS\system32\LMImirr2.dll
2007-05-26 21:49:28 24,000 —-a-w C:\WINDOWS\system32\LMImirr.dll
2007-05-26 21:49:27 63,040 —-a-w C:\WINDOWS\system32\LMIinit.dll
2007-05-24 13:57:11 ——– d—–w C:\DOCUME~1\Doron\APPLIC~1\Command & Conquer 3 Tiberium Wars
2007-05-16 15:32:55 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-01 08:25:56 ——– d—–w C:\Program Files\IrfanView
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-19 12:14:14 208,896 —-a-w C:\WINDOWS\system32\NVUNINST.EXE
2007-04-19 12:14:14 208,896 —-a-w C:\WINDOWS\system32\nvudisp.exe
2007-04-19 11:26:00 888,832 —-a-w C:\WINDOWS\system32\nvmobls.dll
2007-04-19 11:26:00 86,016 —-a-w C:\WINDOWS\system32\nvmctray.dll
2007-04-19 11:26:00 81,920 —-a-w C:\WINDOWS\system32\nvwddi.dll
2007-04-19 11:26:00 794,624 —-a-w C:\WINDOWS\system32\nvcplui.exe
2007-04-19 11:26:00 7,700,480 —-a-w C:\WINDOWS\system32\nvcpl.dll
2007-04-19 11:26:00 581,632 —-a-w C:\WINDOWS\system32\nvhwvid.dll
2007-04-19 11:26:00 5,644,288 —-a-w C:\WINDOWS\system32\nvoglnt.dll
2007-04-19 11:26:00 5,619,712 —-a-w C:\WINDOWS\system32\nvdisps.dll
2007-04-19 11:26:00 466,944 —-a-w C:\WINDOWS\system32\nvshell.dll
2007-04-19 11:26:00 45,056 —-a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-04-19 11:26:00 442,368 —-a-w C:\WINDOWS\system32\nvappbar.exe
2007-04-19 11:26:00 425,984 —-a-w C:\WINDOWS\system32\keystone.exe
2007-04-19 11:26:00 4,543,616 —-a-w C:\WINDOWS\system32\nv4_disp.dll
2007-04-19 11:26:00 35,840 —-a-w C:\WINDOWS\system32\nvcodins.dll
2007-04-19 11:26:00 35,840 —-a-w C:\WINDOWS\system32\nvcod.dll
2007-04-19 11:26:00 311,296 —-a-w C:\WINDOWS\system32\nvexpbar.dll
2007-04-19 11:26:00 3,035,136 —-a-w C:\WINDOWS\system32\nvgames.dll
2007-04-19 11:26:00 286,720 —-a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-04-19 11:26:00 229,376 —-a-w C:\WINDOWS\system32\nvmccs.dll
2007-04-19 11:26:00 212,992 —-a-w C:\WINDOWS\system32\nvapi.dll
2007-04-19 11:26:00 2,924,544 —-a-w C:\WINDOWS\system32\nvvitvs.dll
2007-04-19 11:26:00 188,416 —-a-w C:\WINDOWS\system32\nvmccss.dll
2007-04-19 11:26:00 159,810 —-a-w C:\WINDOWS\system32\nvsvc32.exe
2007-04-19 11:26:00 147,456 —-a-w C:\WINDOWS\system32\nvcolor.exe
2007-04-19 11:26:00 1,703,936 —-a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-04-19 11:26:00 1,626,112 —-a-w C:\WINDOWS\system32\nwiz.exe
2007-04-19 11:26:00 1,474,560 —-a-w C:\WINDOWS\system32\nview.dll
2007-04-19 11:26:00 1,339,392 —-a-w C:\WINDOWS\system32\nvdspsch.exe
2007-04-19 11:26:00 1,236,992 —-a-w C:\WINDOWS\system32\nvwss.dll
2007-04-19 11:26:00 1,019,904 —-a-w C:\WINDOWS\system32\nvwimg.dll
2007-04-19 11:26:00 1,011,712 —-a-w C:\WINDOWS\system32\nvcpluir.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-16 20:44:20 271,224 —-a-w C:\WINDOWS\system32\mucltui.dll
2007-04-16 20:44:18 208,248 —-a-w C:\WINDOWS\system32\muweb.dll
2007-04-10 21:13:53 364,544 —-a-w C:\WINDOWS\system32\vobsub.dll
2005-07-14 10:31:20 27,648 –sha-r C:\WINDOWS\system32\AVSredirect.dll
2005-06-26 13:32:28 616,448 –sha-r C:\WINDOWS\system32\cygwin1.dll
2005-06-21 20:37:42 45,568 –sha-r C:\WINDOWS\system32\cygz.dll
2005-02-28 11:16:22 240,128 –sha-r C:\WINDOWS\system32\x.264.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 –a—— C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"="SkyTel.EXE" [2006-05-17 10:04 C:\WINDOWS\SkyTel.exe]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-02-11 14:43]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-15 09:21 C:\WINDOWS\RTHDCPL.exe]
"Alcmtr"="ALCMTR.EXE" [2005-05-04 10:43 C:\WINDOWS\Alcmtr.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 14:03]
"EssSpkPhone"="essspk.exe" [2001-08-21 10:36 C:\WINDOWS\essspk.exe]
"nwiz"="nwiz.exe" [2007-04-19 13:26 C:\WINDOWS\system32\nwiz.exe]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 18:53]
"NvMediaCenter"="NvMCTray.dll" [2007-04-19 13:26 C:\WINDOWS\system32\nvmctray.dll]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TuneUp MemOptimizer"="C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" [2007-04-27 06:50]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2005-06-14 14:00]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 13:49]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 14:29]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"High Definition Audio Property Page Shortcut"=HDAShCut.exe
"nwiz"=nwiz.exe /install
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - netsvcs
UxTuneUp


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e2fa24d4-d649-11db-bf5e-0016762b0163}]
AutoRun\command- H:\autorun.exe


Contents of the 'Scheduled Tasks' folder
2007-06-29 15:16:06 C:\WINDOWS\tasks\1-Click Maintenance.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-01 19:12:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-01 19:13:22

— E O F —


HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 19:14:38, on 01/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\essspk.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {98C53984-8BF8-4D11-9B1C-C324FCA9CADE} (Loader Class v3) - http://qcenter/qcbin/Spider90.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\system32\PCTKRNT.SYS
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
A. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\ssprs.dll
C:\WINDOWS\system32\x.264.exe


3. Save the above as ComboFix-Do.txt

4. Then drag the ComboFix-Do.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

6. Please tell me if your are still experiencing any problems. If everything is OK, we will commence the final cleanup procedures.

Trevuren
"Doron" - 2007-07-02 0:57:25 - ComboFix 07-07-01.3 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\Doron\Desktop\ComboFix-Do.txt


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\ssprs.dll
C:\WINDOWS\system32\x.264.exe


((((((((((((((((((((((((( Files Created from 2007-06-01 to 2007-07-01 )))))))))))))))))))))))))))))))


2007-07-01 19:11 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-07-01 08:56 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-01 00:48 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
2007-06-30 21:01 d——– C:\NVIDIA
2007-06-30 20:30 255,848 –a—— C:\WINDOWS\system32\xactengine2_6.dll
2007-06-30 20:20 d–hs—- C:\WINDOWS\ftpcache
2007-06-30 20:18 d——– C:\DOCUME~1\Doron\APPLIC~1\DAEMON Tools Pro
2007-06-29 13:19 d——– C:\Program Files\DAEMON Tools Pro
2007-06-29 13:19 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\DAEMON Tools Pro
2007-06-27 20:47 dr——- C:\DOCUME~1\Doron\My Documents?
2007-06-27 20:46 d——– C:\Program Files\ICQLite
2007-06-27 20:46 d——– C:\DOCUME~1\Doron\APPLIC~1\ICQLite
2007-06-13 15:21 29,704 –a—— C:\WINDOWS\system32\uxtuneup.dll
2007-06-10 23:19 9,464 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-06-10 23:19 9,336 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-06-10 23:19 43,528 ——— C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-06-10 23:19 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2007-06-10 23:19 d——– C:\Program Files\Winamp
2007-06-05 22:55 d——– C:\DOCUME~1\Doron\APPLIC~1\dvdcss
2007-06-04 23:38 d——– C:\Program Files\Ghostgum
2007-06-04 23:36 d——– C:\gs
2007-06-03 22:29 d——– C:\Program Files\Photodex Presenter
2007-06-03 22:29 d——– C:\Program Files\Photodex
2007-06-03 22:29 d——– C:\DOCUME~1\Doron\APPLIC~1\Netscape
2007-06-03 22:28 d——– C:\DOCUME~1\Doron\APPLIC~1\Photodex
2007-06-03 09:20 d——– C:\Program Files\Common Files\Skype


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-01 22:55:03 ——– d—–w C:\DOCUME~1\Doron\APPLIC~1\Skype
2007-07-01 15:49:01 ——– d—–w C:\Program Files\PowerArchiver
2007-07-01 06:58:49 ——– d—–w C:\Program Files\LogMeIn
2007-07-01 00:51:31 ——– d—–w C:\Program Files\Emule Ketamine 2006
2007-06-30 18:27:20 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-06-30 17:56:29 ——– d—–w C:\DOCUME~1\Doron\APPLIC~1\uTorrent
2007-06-29 10:35:12 ——– d—–w C:\Program Files\Visual Assist X
2007-06-27 13:04:59 ——– d—–w C:\Program Files\TuneUp Utilities 2007
2007-06-27 08:13:53 685,816 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-06-26 22:08:06 ——– d—–w C:\DOCUME~1\Doron\APPLIC~1\U3
2007-06-26 18:57:09 360,704 —-a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2007-06-03 07:20:21 ——– d—–w C:\Program Files\Skype
2007-05-30 18:16:51 ——– d—–w C:\Program Files\Google
2007-05-30 15:24:55 205 —-a-w C:\WINDOWS\system32\lsprst7.dll
2007-05-28 08:39:07 1,903 —-a-w C:\WINDOWS\mozver.dat
2007-05-26 21:49:37 83,552 —-a-w C:\WINDOWS\system32\LMIRfsClientNP.dll
2007-05-26 21:49:30 26,176 —-a-w C:\WINDOWS\system32\LMIport.dll
2007-05-26 21:49:29 10,304 —-a-w C:\WINDOWS\system32\LMImirr2.dll
2007-05-26 21:49:28 24,000 —-a-w C:\WINDOWS\system32\LMImirr.dll
2007-05-26 21:49:27 63,040 —-a-w C:\WINDOWS\system32\LMIinit.dll
2007-05-24 13:57:11 ——– d—–w C:\DOCUME~1\Doron\APPLIC~1\Command & Conquer 3 Tiberium Wars
2007-05-16 15:32:55 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-01 08:25:56 ——– d—–w C:\Program Files\IrfanView
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-19 12:14:14 208,896 —-a-w C:\WINDOWS\system32\NVUNINST.EXE
2007-04-19 12:14:14 208,896 —-a-w C:\WINDOWS\system32\nvudisp.exe
2007-04-19 11:26:00 888,832 —-a-w C:\WINDOWS\system32\nvmobls.dll
2007-04-19 11:26:00 86,016 —-a-w C:\WINDOWS\system32\nvmctray.dll
2007-04-19 11:26:00 81,920 —-a-w C:\WINDOWS\system32\nvwddi.dll
2007-04-19 11:26:00 794,624 —-a-w C:\WINDOWS\system32\nvcplui.exe
2007-04-19 11:26:00 7,700,480 —-a-w C:\WINDOWS\system32\nvcpl.dll
2007-04-19 11:26:00 581,632 —-a-w C:\WINDOWS\system32\nvhwvid.dll
2007-04-19 11:26:00 5,644,288 —-a-w C:\WINDOWS\system32\nvoglnt.dll
2007-04-19 11:26:00 5,619,712 —-a-w C:\WINDOWS\system32\nvdisps.dll
2007-04-19 11:26:00 466,944 —-a-w C:\WINDOWS\system32\nvshell.dll
2007-04-19 11:26:00 45,056 —-a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-04-19 11:26:00 442,368 —-a-w C:\WINDOWS\system32\nvappbar.exe
2007-04-19 11:26:00 425,984 —-a-w C:\WINDOWS\system32\keystone.exe
2007-04-19 11:26:00 4,543,616 —-a-w C:\WINDOWS\system32\nv4_disp.dll
2007-04-19 11:26:00 35,840 —-a-w C:\WINDOWS\system32\nvcodins.dll
2007-04-19 11:26:00 35,840 —-a-w C:\WINDOWS\system32\nvcod.dll
2007-04-19 11:26:00 311,296 —-a-w C:\WINDOWS\system32\nvexpbar.dll
2007-04-19 11:26:00 3,035,136 —-a-w C:\WINDOWS\system32\nvgames.dll
2007-04-19 11:26:00 286,720 —-a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-04-19 11:26:00 229,376 —-a-w C:\WINDOWS\system32\nvmccs.dll
2007-04-19 11:26:00 212,992 —-a-w C:\WINDOWS\system32\nvapi.dll
2007-04-19 11:26:00 2,924,544 —-a-w C:\WINDOWS\system32\nvvitvs.dll
2007-04-19 11:26:00 188,416 —-a-w C:\WINDOWS\system32\nvmccss.dll
2007-04-19 11:26:00 159,810 —-a-w C:\WINDOWS\system32\nvsvc32.exe
2007-04-19 11:26:00 147,456 —-a-w C:\WINDOWS\system32\nvcolor.exe
2007-04-19 11:26:00 1,703,936 —-a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-04-19 11:26:00 1,626,112 —-a-w C:\WINDOWS\system32\nwiz.exe
2007-04-19 11:26:00 1,474,560 —-a-w C:\WINDOWS\system32\nview.dll
2007-04-19 11:26:00 1,339,392 —-a-w C:\WINDOWS\system32\nvdspsch.exe
2007-04-19 11:26:00 1,236,992 —-a-w C:\WINDOWS\system32\nvwss.dll
2007-04-19 11:26:00 1,019,904 —-a-w C:\WINDOWS\system32\nvwimg.dll
2007-04-19 11:26:00 1,011,712 —-a-w C:\WINDOWS\system32\nvcpluir.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-16 20:44:20 271,224 —-a-w C:\WINDOWS\system32\mucltui.dll
2007-04-16 20:44:18 208,248 —-a-w C:\WINDOWS\system32\muweb.dll
2007-04-10 21:13:53 364,544 —-a-w C:\WINDOWS\system32\vobsub.dll
2005-07-14 10:31:20 27,648 –sha-r C:\WINDOWS\system32\AVSredirect.dll
2005-06-26 13:32:28 616,448 –sha-r C:\WINDOWS\system32\cygwin1.dll
2005-06-21 20:37:42 45,568 –sha-r C:\WINDOWS\system32\cygz.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 –a—— C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"="SkyTel.EXE" [2006-05-17 10:04 C:\WINDOWS\SkyTel.exe]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-02-11 14:43]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-15 09:21 C:\WINDOWS\RTHDCPL.exe]
"Alcmtr"="ALCMTR.EXE" [2005-05-04 10:43 C:\WINDOWS\Alcmtr.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 14:03]
"EssSpkPhone"="essspk.exe" [2001-08-21 10:36 C:\WINDOWS\essspk.exe]
"nwiz"="nwiz.exe" [2007-04-19 13:26 C:\WINDOWS\system32\nwiz.exe]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 18:53]
"NvMediaCenter"="NvMCTray.dll" [2007-04-19 13:26 C:\WINDOWS\system32\nvmctray.dll]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TuneUp MemOptimizer"="C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" [2007-04-27 06:50]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2005-06-14 14:00]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 13:49]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"ICQ Lite"=C:\Program Files\ICQLite\ICQLite.exe -trayboot

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 14:29]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"High Definition Audio Property Page Shortcut"=HDAShCut.exe
"nwiz"=nwiz.exe /install
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - netsvcs
UxTuneUp


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e2fa24d4-d649-11db-bf5e-0016762b0163}]
AutoRun\command- H:\autorun.exe


Contents of the 'Scheduled Tasks' folder
2007-06-29 15:16:06 C:\WINDOWS\tasks\1-Click Maintenance.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-02 00:58:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-02 0:59:21
C:\ComboFix-quarantined-files.txt … 2007-07-02 00:59
C:\ComboFix2.txt … 2007-07-01 19:13

— E O F —


HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 01:00:23, on 02/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\essspk.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\WINDOWS\system32\mdm.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {98C53984-8BF8-4D11-9B1C-C324FCA9CADE} (Loader Class v3) - http://qcenter/qcbin/Spider90.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\system32\PCTKRNT.SYS
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe


Thanks,
Doron

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI