This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Need Help Finishing Cleanup

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So far ran AVG free spyware and antivirus, Vundo cleaner, CWS shredder, Spybot, Superantispyware — this is what is left - Computer takes about 20 min to boot up (128 mb memory does not help, but should be quicker than this)

Computer has not been updated with service packs (in safe mode. OS comes up as Whistler!)

I want to get it clean before installing the servive packs.

I know TVMedia is a nasty and they have a registry fixer which I believe to be a rogue program.

here is the are HJT log and Panda Scan log:

Logfile of HijackThis v1.99.1
Scan saved at 7:47:49 AM, on 7/30/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\WINDOWS\wt\updater\wcmdmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us3.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [HPGamesActiveMenu] C:\Program Files\WildTangent\ActiveMenu\HP\Games\ActiveMenu.exe
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZCxdm484YYUS
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {2F003D51-39FD-4D18-9016-95CF70B92ABE} - http://download.movienetworks.com/install/US/altpmtscab.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1185642789920
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Panda Scan:


Incident Status Location

Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\mcmillionz@2o7[1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\mcmillionz@adultfriendfinder[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\mcmillionz@advertising[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\mcmillionz@atdmt[2].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\mcmillionz@casalemedia[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\mcmillionz@doubleclick[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\mcmillionz@questionmarket[2].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\[removed][1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\[removed][1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\mcmillionz@trafficmp[1].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\mcmillionz@winantivirus[1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\mcmillionz@zedo[2].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@2o7[1].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@advertising[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@atdmt[2].txt
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@bfast[2].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@bluestreak[1].txt
Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@centrport[1].txt
Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\[removed][2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@doubleclick[1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\[removed][1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\[removed][2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@fastclick[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@fastclick[3].txt
Spyware:Cookie/Gator Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@gator[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@go[1].txt
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\[removed][2].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\[removed][2].txt
Spyware:Cookie/LinkExchange Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@linkexchange[1].txt
Spyware:Cookie/Linksynergy Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@linksynergy[2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@mediaplex[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@overture[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@questionmarket[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\[removed][1].txt
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\[removed][1].txt
Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@targetnet[2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@trafficmp[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@tribalfusion[1].txt
Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@valueclick[1].txt
Spyware:Cookie/Eyeblaster Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\[removed]-ds[1].txt
Spyware:Cookie/X10 Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@x10[1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\MCMILLIONZ\Cookies\owner@zedo[2].txt
Adware:adware/tvmedia Not disinfected C:\Documents and Settings\Owner\Application Data\tvmcwrd.dll
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Owner\Cookies\owner@atdmt[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Owner\Cookies\owner@com[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Owner\Cookies\owner@mediaplex[1].txt
Adware:Adware/TVMedia Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\tvmupdater.exe
Adware:adware/gator Not disinfected C:\GatorPatch.log
Potentially unwanted tool:Application/KillApp.B Not disinfected C:\hp\bin\KillIt.exe
Potentially unwanted tool:Application/KillWind Not disinfected C:\hp\bin\KillWind.exe
Potentially unwanted tool:Application/KillApp.A Not disinfected C:\hp\bin\Terminator.exe
Adware:Adware/TVMedia Not disinfected C:\Program Files\TV Media\Tvm.exe
Adware:Adware/TVMedia Not disinfected C:\Program Files\TV Media\TvmCore.dll
Adware:Adware/TVMedia Not disinfected C:\Program Files\TV Media\u187.tmp
Adware:Adware/TVMedia Not disinfected C:\Program Files\TV Media\u188.tmp
Possible Virus. Not disinfected C:\VundoFix Backups\jkhff.dll.bad
Adware:adware/isearch Not disinfected C:\WINDOWS\delprot.ini
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWA6P_0001_N822M1605NetInstaller.exe
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UWA6P_0001_N822M1605NetInstaller.exe
Potentially unwanted tool:Application/FunWeb Not disinfected C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf
Adware:Adware/TVMedia Not disinfected C:\WINDOWS\Downloaded Program Files\Install.inf
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N822M1605NetInstaller.exe
Adware:Adware/SAHAgent Not disinfected C:\WINDOWS\Downloaded Program Files\xmltok_.dll
Adware:Adware/LocalNRD Not disinfected C:\WINDOWS\INF\localNrd.inf
Adware:Adware/ISearch Not disinfected C:\WINDOWS\isrvs\isearch.xpi
Potentially unwanted tool:application/bestoffer Not disinfected C:\WINDOWS\smdat32m.sys
Adware:adware/cydoor Not disinfected C:\WINDOWS\SYSTEM32\cd_clint.dll
Spyware:Spyware/CWS.Olehelp Not disinfected C:\WINDOWS\SYSTEM32\commcoss.dll
Spyware:Cookie/Go Not disinfected C:\WINDOWS\SYSTEM32\config\systemprofile\Cookies\owner@go[1].txt
Spyware:Cookie/Humanclick Not disinfected C:\WINDOWS\SYSTEM32\config\systemprofile\Cookies\[removed][2].txt
Spyware:Cookie/LinkExchange Not disinfected C:\WINDOWS\SYSTEM32\config\systemprofile\Cookies\owner@linkexchange[1].txt
Spyware:Cookie/Eyeblaster Not disinfected C:\WINDOWS\SYSTEM32\config\systemprofile\Cookies\[removed]-ds[1].txt
Virus:Trj/Agent.DIL Disinfected C:\WINDOWS\SYSTEM32\drivers\delprot.sys
Adware:adware/keenvalue Not disinfected C:\WINDOWS\SYSTEM32\drivers\etc\hosts.bho
Spyware:Spyware/CWS.Olehelp Not disinfected C:\WINDOWS\SYSTEM32\inetdctr.dll
Spyware:Spyware/Spydeleter Not disinfected C:\WINDOWS\SYSTEM32\sd.exe
Adware:Adware/MyDailyHoroscope Not disinfected C:\WINDOWS\SYSTEM32\setup_silent_26198.exe
Adware:Adware/SAHAgent Not disinfected C:\WINDOWS\SYSTEM32\xmltok.dll
Hi! Welcome to the Tom Coyote forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.


You are currently using an unpatched version of Microsoft XP. It is CRITICAL that you update to Service Pack 1a
Please visit this link:
Microsoft Service Pack 1a

and install Service Pack 1a. If you run into troubles, please post them here.

IMPORTANT: DO NOT update to Service pack 2. Doing so before your computer is clean can cause Windows to become unstable.
We will update to SP2 when you are clean.



Please post back with a HJT log and your computer running with Service pack 1a, or with any problems you are having updating.
Ad-Aware SE Personal
Adobe Acrobat 5.0
America Online
AOL Coach Version 1.0(Build:20020823.1)
Atomic Pop
AVG Anti-Spyware 7.5
Avira AntiVir PersonalEdition Classic
BlasterBall Wild
Comcast High-Speed Internet Install Wizard
ComcastSUPPORT
DarkOrbit
Detto Migration Kit
Easy Internet Sign-up
GemMaster
HijackThis 1.99.1
hp center
HP Instant Support
HP Photo Printing Software
Inactive HP Printer Drivers (Remove only)
Inactive HP ScanJet Drivers (Remove only)
KazooStudio
KBD
Lernout & Hauspie TruVoice American English TTS Engine
Microsoft Works 6.0
Microsoft Works and Money 2001 Setup Launcher
MSN Messenger 7.5
MUSICMATCH Jukebox
My Photo Center
Nero Suite
NVIDIA Windows 2000/XP Display Drivers
Panda ActiveScan
PC-Doctor for Windows
PigPen
PowerDVD
PS2
Python 1.5 combined Win32 extensions
Python 1.5.2 (final)
Quicken Financial Center
RealPlayer Basic
S3 Gamma
S3 Savage4 Family Display Switch2 Utility
SabreWing 2
Seagate DiscWizard
Speedway
Spybot - Search & Destroy 1.4
SUPERAntiSpyware Free Edition
Tcl 8.0.5 for Windows
Viewpoint Media Player (Remove Only)
WD Diagnostics
WildTangent Updater
WildTangent Web Driver
Windows XP Hotfix - KB823559
Windows XP Hotfix - KB828741
Windows XP Hotfix - KB835732
Windows XP Hotfix - KB842773
Windows XP Hotfix (SP2) [See Q329048 for more information]
Windows XP Hotfix (SP2) [See Q329115 for more information]
Windows XP Hotfix (SP2) [See Q329390 for more information]
Windows XP Hotfix (SP2) [See Q329834 for more information]
Windows XP Hotfix (SP2) Q328310
Windows XP Hotfix (SP2) Q329170
Windows XP Hotfix (SP2) Q329441
Windows XP Hotfix (SP2) Q810577
Windows XP Hotfix (SP2) Q810833
Windows XP Hotfix (SP2) Q815021
Windows XP Service Pack 1a

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Logfile of HijackThis v1.99.1
Scan saved at 1:34:34 AM, on 8/4/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\wanmpsvc.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us3.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [HPGamesActiveMenu] C:\Program Files\WildTangent\ActiveMenu\HP\Games\ActiveMenu.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Startup: Download Plus.lnk = C:\Documents and Settings\Owner\Application Data\DownloadPlus.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZCxdm484YYUS
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {2F003D51-39FD-4D18-9016-95CF70B92ABE} - http://download.movienetworks.com/install/US/altpmtscab.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1185642789920
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1186201194015
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hi

You have a few dubious programs installed.

tgcmd (Tioga software_support.com) is part of Tioga Software’s remote support and management tools (Tioga.com, Support.com, and SupportSoft.com are one and the same company) and is installed by the setup CD of the @Home ISP (@Home and MediaOne are now part of Comcast, with the ComcastSupport software being the main culprit for introducing T G C M D on a PC). The Tioga/SupportSoft.com software is also included in the Sony Support software that comes with some Sony Vaio’s and HP Pavillion’s. The original intention of T G C M D is to have your @Home service or systems software automatically updated when you are online, to provide a remote support technician with setup information about your PC, and, in some cases, to allow the remote support technician to connect to your PC and see what you are doing – in short, technical support is indeed the original intention; unfortunately, its features are also very useful to advertisers. This is considered a valid program but spyware by some. It is not just Comcast that installs this but also BellSouth.

its features are also very useful to advertisers and so, depending on who supplied it, T G C M D will also collect information from your PC, which web pages you have visited, what you have downloaded, and permission based information about your system, its software, its settings, etc…,


I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto‑updating for the Viewpoint Manager ‑‑ the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.


Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware.
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight >>Viewpoint component<< , click Remove.
  • Do the same for each Viewpoint component.
I see you are using Wild Tangent. It is not malware, but is sometimes thought to bring malware along. Wild Tangent is a video game software company specializing in online games. It has even made a partnership with AOL to include itself as part of the AOL Instant Messenger for their AIM games section. The WildTangent Web Driver is their technology that allows you to play 3D games over the Internet. Although it’s not technically considered spyware, it does have built in components to update itself and gather information about the computer system including
  • Operating System Version
  • CPU Type and Speed
  • Memory Amount
    Video Card type and Driver Version
  • Sound Card type and Driver Version
  • DirectX Version
    Location that the Web Driver was installed from
  • It is also a MAJOR resource hog.
For more information, see WildTangent Removal Instructions and Help and Inside Wild Tangent-Delivering High-End 3-D Content To A Web Site Near You.
Unless you are an extremely avid games player, I recommend you uninstall Wild Tangent: To uninstall Wild Tangent:
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight Wild Tangent, click Remove.
  • Close the Add or Remove Programs and the Control Panel windows.
Download and Run ComboFix
  • Download this file from below:

    Here
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
Ok, give me a day or so - I turned off the power prematurely and now I have a corrupted windows/system32/config/system I need to work through this first
Actually - I ran combofix while I was waiting for a response (before my last HJT log):

ComboFix 07-06-18.2 - C:\Documents and Settings\Owner\Desktop\ComboFix.exe
"Owner" - 2007-08-02 23:24:59 NTFS


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\msxml3a.dll


((((((((((((((((((((((((( Files Created from 2007-07-03 to 2007-08-03 )))))))))))))))))))))))))))))))


2007-08-02 23:23 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-08-02 22:04 d——– C:\Program Files\RogueRemover FREE
2007-08-01 23:11 d——– C:\DOCUME~1\Owner\APPLIC~1\Lavasoft
2007-07-30 22:07 3,968 –a—— C:\WINDOWS\SYSTEM32\drivers\AvgArCln.sys
2007-07-30 21:12 8,576 –a—— C:\WINDOWS\SYSTEM32\drivers\sfuxfbhtchab.sys
2007-07-30 18:08 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-30 18:07 d——– C:\Program Files\SUPERAntiSpyware
2007-07-30 18:07 d——– C:\DOCUME~1\Owner\APPLIC~1\SUPERAntiSpyware.com
2007-07-29 23:39 8,576 –a—— C:\WINDOWS\SYSTEM32\drivers\ymoosmswmmft.sys
2007-07-29 23:14 d——– C:\WINDOWS\SYSTEM32\ActiveScan
2007-07-29 23:07 d——– C:\Program Files\YourWare Solutions
2007-07-29 21:18 d——– C:\Program Files\Western Digital Technologies
2007-07-29 21:01 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-28 19:35 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Seagate
2007-07-28 19:10 392,320 –a—— C:\WINDOWS\SYSTEM32\drivers\timntr.sys
2007-07-28 19:10 32,768 –a—— C:\WINDOWS\SYSTEM32\drivers\tifsfilt.sys
2007-07-28 19:10 120,992 –a—— C:\WINDOWS\SYSTEM32\drivers\snapman.sys
2007-07-28 19:08 d——– C:\Program Files\Common Files\Seagate
2007-07-28 19:07 d——– C:\Program Files\Seagate
2007-07-28 15:54 d——– C:\DOCUME~1\Owner\DoctorWeb
2007-07-28 15:45 d——– C:\WINDOWS\LastGood
2007-07-28 12:18 d——– C:\WINDOWS\SYSTEM32\bits
2007-07-28 12:16 7,680 ——— C:\WINDOWS\SYSTEM32\bitsprx2.dll
2007-07-28 12:16 7,168 ——— C:\WINDOWS\SYSTEM32\bitsprx3.dll
2007-07-28 12:16 331,776 –a—— C:\WINDOWS\SYSTEM32\winhttp.dll
2007-07-28 12:16 17,408 –a—— C:\WINDOWS\SYSTEM32\qmgrprxy.dll
2007-07-28 12:16 158,720 ——— C:\WINDOWS\SYSTEM32\xpob2res.dll
2007-07-28 12:14 549,720 –a—— C:\WINDOWS\SYSTEM32\wuapi.dll
2007-07-28 12:14 43,352 –a—— C:\WINDOWS\SYSTEM32\wups2.dll
2007-07-28 12:14 36,864 –a—— C:\WINDOWS\SYSTEM32\mf3216.dll
2007-07-28 12:14 33,624 –a—— C:\WINDOWS\SYSTEM32\wups.dll
2007-07-28 12:14 325,976 –a—— C:\WINDOWS\SYSTEM32\wucltui.dll
2007-07-28 12:13 593,408 –a—— C:\WINDOWS\SYSTEM32\h323msp.dll
2007-07-28 12:13 550,400 –a—— C:\WINDOWS\SYSTEM32\rtcdll.dll
2007-07-28 12:13 48,640 –a—— C:\WINDOWS\SYSTEM32\browser.dll
2007-07-28 12:13 454,656 –a—— C:\WINDOWS\SYSTEM32\ipnathlp.dll
2007-07-28 12:13 d——– C:\WINDOWS\SoftwareDistribution
2007-07-28 12:08 977,920 –a—— C:\WINDOWS\SYSTEM32\msdtctm.dll
2007-07-28 12:08 97,280 –a—— C:\WINDOWS\SYSTEM32\txflog.dll
2007-07-28 12:08 82,432 –a—— C:\WINDOWS\SYSTEM32\mtxoci.dll
2007-07-28 12:08 64,512 –a—— C:\WINDOWS\SYSTEM32\mtxclu.dll
2007-07-28 12:08 64,512 –a—— C:\WINDOWS\SYSTEM32\colbact.dll
2007-07-28 12:08 596,480 –a—— C:\WINDOWS\SYSTEM32\catsrvut.dll
2007-07-28 12:08 499,200 –a—— C:\WINDOWS\SYSTEM32\comuid.dll
2007-07-28 12:08 442,880 –a—— C:\WINDOWS\SYSTEM32\rpcrt4.dll
2007-07-28 12:08 365,568 –a—— C:\WINDOWS\SYSTEM32\msdtcprx.dll
2007-07-28 12:08 226,816 –a—— C:\WINDOWS\SYSTEM32\es.dll
2007-07-28 12:08 225,280 –a—— C:\WINDOWS\SYSTEM32\catsrv.dll
2007-07-28 12:08 214,528 –a—— C:\WINDOWS\SYSTEM32\rpcss.dll
2007-07-28 12:08 150,528 –a—— C:\WINDOWS\SYSTEM32\msdtcuiu.dll
2007-07-28 12:08 110,080 –a—— C:\WINDOWS\SYSTEM32\clbcatex.dll
2007-07-28 12:08 1,177,088 –a—— C:\WINDOWS\SYSTEM32\comsvcs.dll
2007-07-28 12:08 1,105,408 –a—— C:\WINDOWS\SYSTEM32\ole32.dll
2007-07-28 12:07 6,550 –a—— C:\WINDOWS\jautoexp.dat
2007-07-28 12:07 46,352 –a—— C:\WINDOWS\setdebug.exe
2007-07-28 12:07 313,856 –a—— C:\WINDOWS\SYSTEM32\dx3j.dll
2007-07-28 12:07 171,280 –a—— C:\WINDOWS\SYSTEM32\jit.dll
2007-07-28 12:07 139,536 –a—— C:\WINDOWS\SYSTEM32\javaee.dll
2007-07-28 12:06 947,472 –a—— C:\WINDOWS\SYSTEM32\msjava.dll
2007-07-28 12:06 63,248 –a—— C:\WINDOWS\SYSTEM32\javaprxy.dll
2007-07-28 12:06 49,424 –a—— C:\WINDOWS\SYSTEM32\clspack.exe
2007-07-28 12:06 404,752 –a—— C:\WINDOWS\SYSTEM32\javart.dll
2007-07-28 12:06 286,992 –a—— C:\WINDOWS\SYSTEM32\vmhelper.dll
2007-07-28 12:06 21,264 –a—— C:\WINDOWS\SYSTEM32\msjdbc10.dll
2007-07-28 12:06 187,152 –a—— C:\WINDOWS\SYSTEM32\javacypt.dll
2007-07-28 12:06 172,304 –a—— C:\WINDOWS\SYSTEM32\jview.exe
2007-07-28 12:06 171,792 –a—— C:\WINDOWS\SYSTEM32\wjview.exe
2007-07-28 12:06 154,384 –a—— C:\WINDOWS\SYSTEM32\msawt.dll
2007-07-28 12:06 15,120 –a—— C:\WINDOWS\SYSTEM32\jdbgmgr.exe
2007-07-28 12:06 113 –a—— C:\WINDOWS\SYSTEM32\zonedon.reg
2007-07-28 12:06 113 –a—— C:\WINDOWS\SYSTEM32\zonedoff.reg
2007-07-28 11:57 218,624 –a—— C:\WINDOWS\SYSTEM32\srrstr.dll
2007-07-28 11:46 d——– C:\WINDOWS\LastGood.Tmp
2007-07-28 11:39 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-07-28 09:04 3,968 –a—— C:\WINDOWS\SYSTEM32\drivers\AvgAsCln.sys
2007-07-28 08:22 24,576 –a—— C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
2007-07-28 08:16 d——– C:\VundoFix Backups


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-02 04:10:48 ——– d—–w C:\Program Files\Lavasoft
2007-07-28 17:14:19 ——– d–h–w C:\Program Files\WindowsUpdate
2007-07-28 14:06:54 ——– d—–w C:\Program Files\License_Manager
2007-07-28 13:27:29 ——– d—–w C:\Program Files\MSN Messenger
2001-07-22 02:45:40 94,784 –sh–w C:\WINDOWS\twain.dll
2001-08-18 05:36:34 46,592 –sh–w C:\WINDOWS\twain_32.dll
2001-08-18 05:36:20 995,383 –sh–w C:\WINDOWS\SYSTEM32\mfc42.dll
2001-08-18 05:36:26 50,688 –sh–w C:\WINDOWS\SYSTEM32\msvcirt.dll
2001-08-18 05:36:26 401,462 –sh–w C:\WINDOWS\SYSTEM32\msvcp60.dll
2001-08-18 05:36:28 569,344 –sh–w C:\WINDOWS\SYSTEM32\oleaut32.dll
2001-08-18 05:36:28 106,496 –sh–w C:\WINDOWS\SYSTEM32\olepro32.dll
2001-08-18 05:36:54 9,728 –sh–w C:\WINDOWS\SYSTEM32\regsvr32.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-03-02 14:02]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 01:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KBD"="C:\HP\KBD\KBD.EXE" [2001-07-06 16:56]
"tgcmd"="C:\Program Files\support.com\bin\tgcmd.exe" [2002-04-24 20:37]
"HPGamesActiveMenu"="C:\Program Files\WildTangent\ActiveMenu\HP\Games\ActiveMenu.exe" [2001-06-13 17:40]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-07-28 09:06]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-07-28 11:32]
"DiscWizardMonitor.exe"="C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2007-04-19 21:24]
"AcronisTimounterMonitor"="C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe" [2007-04-19 21:38]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [2007-04-19 21:29]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeRAM XP"="C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 00:13]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-08-15 19:25]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-07-28 09:06]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 relog_ap

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM95\aim.exe -cnetwait.odl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\System32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
C:\Program Files\Microsoft Works\WkDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE NvQTwk,NvCplDaemon initialize

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"


Contents of the 'Scheduled Tasks' folder
2006-05-20 01:00:00 C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
2006-02-21 00:16:34 C:\WINDOWS\tasks\Registration reminder 1.job
2007-08-03 04:37:01 C:\WINDOWS\tasks\Symantec NetDetect.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-02 23:39:48
Windows 5.1.2600 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
tgcmd = "C:\Program Files\support.com\bin\tgcmd.exe" /server?cmd.exe" /server

scanning hidden files …

**************************************************************************

Completion time: 2007-08-02 23:43:05
C:\ComboFix-quarantined-files.txt … 2007-08-02 23:42

— E O F —
Also ran DSS:

Deckard's System Scanner v20070611.50
Run by [removed] on 2007-08-03 at 00:01:38
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
6: 2007-08-03 05:01:58 UTC - RP6 - Deckard's System Scanner Restore Point
5: 2007-08-02 04:49:43 UTC - RP5 - System Checkpoint
4: 2007-07-30 23:07:09 UTC - RP4 - Installed SUPERAntiSpyware Free Edition
3: 2007-07-30 02:18:14 UTC - RP3 - Installed WD Diagnostics
2: 2007-07-28 23:58:05 UTC - RP2 - Installed Seagate DiscWizard


– First Restore Point –
1: 2007-07-28 23:01:50 UTC - RP1 - System Checkpoint


Backed up registry hives.

Performed disk cleanup.


– HijackThis (run as Owner.exe) ———————————————–

Logfile of HijackThis v1.99.1
Scan saved at 12:04:26 AM, on 8/3/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\wt\updater\wcmdmgr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Owner\Desktop\dss.exe
C:\DOCUME~1\Owner\Desktop\Owner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us3.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [HPGamesActiveMenu] C:\Program Files\WildTangent\ActiveMenu\HP\Games\ActiveMenu.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Startup: Download Plus.lnk = C:\Documents and Settings\Owner\Application Data\DownloadPlus.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZCxdm484YYUS
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {2F003D51-39FD-4D18-9016-95CF70B92ABE} - http://download.movienetworks.com/install/US/altpmtscab.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1185642789920
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


– HijackThis Fixed Entries (C:\DOCUME~1\Owner\Desktop\backups\) —————

backup-20070728-155134-897 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
backup-20070728-155134-980 O2 - BHO: (no name) - {583F4D8E-3E88-4212-AC1C-A47DF48341E4} - C:\WINDOWS\System32\jkhff.dll (file missing)

– File Associations ———————————————————–

.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R0 timounter (Acronis True Image Backup Archive Explorer) - c:\windows\system32\drivers\timntr.sys
Hi I appreciate the logs but they can be confusing as they are mixed up. Once you have the pc up and running could you run Deckard's and paste the log in your next reply?
here it is (chkdsk /r and last known good config option saved my butt)

BTW - its not my machine so I don't want to uninstall the comcast agent or wild tangent. I may uninstall viewpoint or tell them to uninstall but I don't think any of them would interfere in a SP2 upgrade, correct?

Deckard's System Scanner v20070611.50
Run by [removed] on 2007-08-04 at 15:45:17
Computer is in Normal Mode.
——————————————————————————–



– HijackThis (run as Owner.exe) ———————————————–

Logfile of HijackThis v1.99.1
Scan saved at 3:45:52 PM, on 8/4/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\wanmpsvc.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Documents and Settings\Owner\Desktop\cureit.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\RarSFX1\_start.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\RarSFX1\cureit.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\dss.exe
C:\DOCUME~1\Owner\Desktop\Owner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us3.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [HPGamesActiveMenu] C:\Program Files\WildTangent\ActiveMenu\HP\Games\ActiveMenu.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZCxdm484YYUS
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {2F003D51-39FD-4D18-9016-95CF70B92ABE} - http://download.movienetworks.com/install/US/altpmtscab.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1185642789920
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1186201194015
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


– Files created between 2007-07-04 and 2007-08-04 —————————–

2007-08-04 13:52:05 0 d——– C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
2007-08-04 13:50:00 0 d——– C:\WINDOWS\LastGood
2007-08-04 13:13:11 18 –a—— C:\SYSREST
2007-08-04 01:57:38 0 d——– C:\WINDOWS\System32\PreInstall
2007-08-04 01:57:22 0 d–h—– C:\WINDOWS\$hf_mig$
2007-08-04 01:52:14 0 d——– C:\WINDOWS\System32\CatRoot2
2007-08-04 01:10:20 0 d——– C:\Documents and Settings\All Users\Application Data\Avg7
2007-08-04 00:51:05 0 d——– C:\WINDOWS\Prefetch
2007-08-04 00:05:39 0 d——– C:\WINDOWS\ServicePackFiles
2007-08-04 00:05:39 0 d——– C:\WINDOWS\ehome
2007-08-02 22:04:08 0 d——– C:\Program Files\RogueRemover FREE
2007-08-01 23:11:17 0 d——– C:\Documents and Settings\Owner\Application Data\Lavasoft
2007-07-30 21:12:20 8576 –a—— C:\WINDOWS\System32\drivers\sfuxfbhtchab.sys
Hi

Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\WINDOWS\SYSTEM32\drivers\ymoosmswmmft.sys
C:\WINDOWS\SYSTEM32\drivers\sfuxfbhtchab.sys
C:\WINDOWS\jautoexp.dat
C:\WINDOWS\SYSTEM32\drivers\etc\hosts.bho 
C:\WINDOWS\SYSTEM32\xmltok.dll
C:\WINDOWS\SYSTEM32\setup_silent_26198.exe
C:\WINDOWS\SYSTEM32\sd.exe
C:\WINDOWS\SYSTEM32\inetdctr.dll 
C:\WINDOWS\SYSTEM32\drivers\delprot.sys
C:\WINDOWS\SYSTEM32\commcoss.dll
C:\WINDOWS\SYSTEM32\cd_clint.dll
C:\WINDOWS\smdat32m.sys
C:\WINDOWS\isrvs\isearch.xpi
C:\WINDOWS\INF\localNrd.inf 
C:\WINDOWS\Downloaded Program Files\xmltok_.dll
C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N822M1605NetInstaller.exe
C:\WINDOWS\Downloaded Program Files\Install.inf 
C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UWA6P_0001_N822M1605NetInstaller.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWA6P_0001_N822M1605NetInstaller.exe
C:\WINDOWS\delprot.ini
C:\Documents and Settings\Owner\Local Settings\Temp\tvmupdater.exe
C:\Documents and Settings\Owner\Application Data\tvmcwrd.dll

Folder::
C:\VundoFix Backups
C:\Program Files\TV Media

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.

Run SuperAntiSpyware and post the resultant log too, please.
Here are the logs = What are the exe files that start with "A" in the restore points? Superspyware found one, but Avira found several more

ComboFix 07-06-18.2 - C:\Documents and Settings\Owner\Desktop\ComboFix.exe
"Owner" - 2007-08-04 20:10:05 - Service Pack 1 NTFS
Command switches used :: C:\Documents and Settings\Owner\Desktop\cfscript.txt


((((((((((((((((((((((((( Files Created from 2007-07-05 to 2007-08-05 )))))))))))))))))))))))))))))))


2007-08-04 15:31 271,224 –a—— C:\WINDOWS\SYSTEM32\mucltui.dll
2007-08-04 13:52 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AntiVir PersonalEdition Classic
2007-08-04 13:50 d——– C:\WINDOWS\LastGood
2007-08-04 01:57 22,752 –a—— C:\WINDOWS\SYSTEM32\spupdsvc.exe
2007-08-04 01:57 d–h—– C:\WINDOWS\$hf_mig$
2007-08-04 01:57 d——– C:\WINDOWS\SYSTEM32\PreInstall
2007-08-04 01:52 d——– C:\WINDOWS\SYSTEM32\CatRoot2
2007-08-04 00:51 d——– C:\WINDOWS\Prefetch
2007-08-04 00:05 d——– C:\WINDOWS\ServicePackFiles
2007-08-04 00:05 d——– C:\WINDOWS\ehome
2007-08-03 23:51 9,216 –a—— C:\WINDOWS\SYSTEM32\wuauserv.dll
2007-08-03 23:51 86,016 –a—— C:\WINDOWS\SYSTEM32\xactsrv.dll
2007-08-03 23:51 77,824 –a—— C:\WINDOWS\SYSTEM32\wmpstub.exe
2007-08-03 23:51 77,824 –a—— C:\WINDOWS\SYSTEM32\wmpshell.dll
2007-08-03 23:51 56,832 –a—— C:\WINDOWS\SYSTEM32\wzcdlg.dll
2007-08-03 23:51 446,464 –a—— C:\WINDOWS\SYSTEM32\wmvdmoe.dll
2007-08-03 23:51 38,912 –a—— C:\WINDOWS\SYSTEM32\wsnmp32.dll
2007-08-03 23:51 311,327 –a—— C:\WINDOWS\SYSTEM32\wmv8dmod.dll
2007-08-03 23:51 296,448 –a—— C:\WINDOWS\SYSTEM32\wmstream.dll
2007-08-03 23:51 294,912 –a—— C:\WINDOWS\SYSTEM32\wmvdmod.dll
2007-08-03 23:51 264,704 –a—— C:\WINDOWS\SYSTEM32\wzcsvc.dll
2007-08-03 23:51 247,808 –a—— C:\WINDOWS\SYSTEM32\wow32.dll
2007-08-03 23:51 23,552 ——— C:\WINDOWS\SYSTEM32\wzcsapi.dll
2007-08-03 23:51 172,664 –a—— C:\WINDOWS\SYSTEM32\xenroll.dll
2007-08-03 23:51 171,008 –a—— C:\WINDOWS\SYSTEM32\sccsccp.dll
2007-08-03 23:51 17,408 –a—— C:\WINDOWS\SYSTEM32\wtsapi32.dll
2007-08-03 23:51 13,312 –a—— C:\WINDOWS\SYSTEM32\wship6.dll
2007-08-03 23:51 118,784 –a—— C:\WINDOWS\SYSTEM32\wmsdmoe.dll
2007-08-03 23:51 110,592 –a—— C:\WINDOWS\SYSTEM32\wmsdmod.dll
2007-08-03 23:51 1,998,848 –a—— C:\WINDOWS\SYSTEM32\wmploc.dll
2007-08-03 23:51 1,404,928 –a—— C:\WINDOWS\SYSTEM32\wmpui.dll
2007-08-03 23:50 91,136 –a—— C:\WINDOWS\SYSTEM32\rastls.dll
2007-08-03 23:50 9,856 ——— C:\WINDOWS\SYSTEM32\drivers\tunmp.sys
2007-08-03 23:50 88,064 –a—— C:\WINDOWS\SYSTEM32\tscfgwmi.dll
2007-08-03 23:50 87,304 –a—— C:\WINDOWS\SYSTEM32\rdpdd.dll
2007-08-03 23:50 86,528 –a—— C:\WINDOWS\SYSTEM32\wlnotify.dll
2007-08-03 23:50 82,944 –a—— C:\WINDOWS\SYSTEM32\smlogsvc.exe
2007-08-03 23:50 81,920 –a—— C:\WINDOWS\SYSTEM32\trkwks.dll
2007-08-03 23:50 8,192 –a—— C:\WINDOWS\SYSTEM32\scrnsave.scr
2007-08-03 23:50 75,912 –a—— C:\WINDOWS\SYSTEM32\rdpwsx.dll
2007-08-03 23:50 74,240 –a—— C:\WINDOWS\SYSTEM32\rtcshare.exe
2007-08-03 23:50 71,168 –a—— C:\WINDOWS\SYSTEM32\sdbinst.exe
2007-08-03 23:50 71,168 ——— C:\WINDOWS\SYSTEM32\telnet.exe
2007-08-03 23:50 71,168 ——— C:\WINDOWS\SYSTEM32\storprop.dll
2007-08-03 23:50 674,816 –a—— C:\WINDOWS\SYSTEM32\sxs.dll
2007-08-03 23:50 667,648 –a—— C:\WINDOWS\SYSTEM32\ss3dfo.scr
2007-08-03 23:50 66,560 –a—— C:\WINDOWS\SYSTEM32\spoolss.dll
2007-08-03 23:50 66,048 –a—— C:\WINDOWS\SYSTEM32\sigverif.exe
2007-08-03 23:50 638,976 –a—— C:\WINDOWS\SYSTEM32\sstext3d.scr
2007-08-03 23:50 63,488 –a—— C:\WINDOWS\SYSTEM32\srclient.dll
2007-08-03 23:50 62,976 –a—— C:\WINDOWS\SYSTEM32\shgina.dll
2007-08-03 23:50 61,952 –a—— C:\WINDOWS\SYSTEM32\webclnt.dll
2007-08-03 23:50 61,952 –a—— C:\WINDOWS\SYSTEM32\sti.dll
2007-08-03 23:50 60,416 –a—— C:\WINDOWS\SYSTEM32\wextract.exe
2007-08-03 23:50 60,416 –a—— C:\WINDOWS\SYSTEM32\shimeng.dll
2007-08-03 23:50 6,144 –a—— C:\WINDOWS\SYSTEM32\sensapi.dll
2007-08-03 23:50 57,856 –a—— C:\WINDOWS\SYSTEM32\raschap.dll
2007-08-03 23:50 569,344 –a—— C:\WINDOWS\SYSTEM32\sspipes.scr
2007-08-03 23:50 56,320 –a—— C:\WINDOWS\SYSTEM32\remotepg.dll
2007-08-03 23:50 52,224 –a—— C:\WINDOWS\SYSTEM32\secur32.dll
2007-08-03 23:50 511,488 –a—— C:\WINDOWS\SYSTEM32\qedit.dll
2007-08-03 23:50 51,200 –a—— C:\WINDOWS\SYSTEM32\wmerrenu.dll
2007-08-03 23:50 5,504 ——— C:\WINDOWS\SYSTEM32\drivers\smbali.sys
2007-08-03 23:50 49,664 –a—— C:\WINDOWS\SYSTEM32\vfwwdm32.dll
2007-08-03 23:50 48,640 –a—— C:\WINDOWS\SYSTEM32\vdmredir.dll
2007-08-03 23:50 48,128 –a—— C:\WINDOWS\SYSTEM32\winsta.dll
2007-08-03 23:50 48,128 –a—— C:\WINDOWS\SYSTEM32\reg.exe
2007-08-03 23:50 479,261 –a—— C:\WINDOWS\SYSTEM32\vbscript.dll
2007-08-03 23:50 47,616 –a—— C:\WINDOWS\SYSTEM32\utilman.exe
2007-08-03 23:50 442,398 –a—— C:\WINDOWS\SYSTEM32\wmadmoe.dll
2007-08-03 23:50 44,032 –a—— C:\WINDOWS\SYSTEM32\regapi.dll
2007-08-03 23:50 44,032 –a—— C:\WINDOWS\SYSTEM32\rdpclip.exe
2007-08-03 23:50 43,008 –a—— C:\WINDOWS\SYSTEM32\ssdpsrv.dll
2007-08-03 23:50 420,864 –a—— C:\WINDOWS\SYSTEM32\shimgvw.dll
2007-08-03 23:50 409,088 –a—— C:\WINDOWS\SYSTEM32\vssapi.dll
2007-08-03 23:50 40,960 –a—— C:\WINDOWS\SYSTEM32\tscupgrd.exe
2007-08-03 23:50 385,024 –a—— C:\WINDOWS\SYSTEM32\sqlsrv32.dll
2007-08-03 23:50 384,000 –a—— C:\WINDOWS\SYSTEM32\themeui.dll
2007-08-03 23:50 364,544 –a—— C:\WINDOWS\SYSTEM32\ssflwbox.scr
2007-08-03 23:50 36,352 –a—— C:\WINDOWS\SYSTEM32\sens.dll
2007-08-03 23:50 357,376 –a—— C:\WINDOWS\SYSTEM32\qdvd.dll
2007-08-03 23:50 34,304 –a—— C:\WINDOWS\SYSTEM32\rcimlby.exe
2007-08-03 23:50 339,456 –a—— C:\WINDOWS\SYSTEM32\usp10.dll
2007-08-03 23:50 334,848 –a—— C:\WINDOWS\SYSTEM32\smlogcfg.dll
2007-08-03 23:50 33,280 –a—— C:\WINDOWS\SYSTEM32\shmgrate.exe
2007-08-03 23:50 32,256 –a—— C:\WINDOWS\SYSTEM32\umandlg.dll
2007-08-03 23:50 3,338 –a—— C:\WINDOWS\SYSTEM32\redir.exe
2007-08-03 23:50 297,984 –a—— C:\WINDOWS\SYSTEM32\scesrv.dll
2007-08-03 23:50 274,432 –a—— C:\WINDOWS\SYSTEM32\wmasf.dll
2007-08-03 23:50 27,136 –a—— C:\WINDOWS\SYSTEM32\ssdpapi.dll
2007-08-03 23:50 266,752 –a—— C:\WINDOWS\winhlp32.exe
2007-08-03 23:50 253,952 –a—— C:\WINDOWS\SYSTEM32\wmpcd.dll
2007-08-03 23:50 253,952 –a—— C:\WINDOWS\SYSTEM32\wmnetmgr.dll
2007-08-03 23:50 251,904 –a—— C:\WINDOWS\SYSTEM32\strmdll.dll
2007-08-03 23:50 24,064 –a—— C:\WINDOWS\SYSTEM32\skeys.exe
2007-08-03 23:50 233,984 –a—— C:\WINDOWS\SYSTEM32\tapisrv.dll
2007-08-03 23:50 231,424 –a—— C:\WINDOWS\SYSTEM32\upnpui.dll
2007-08-03 23:50 22,528 –a—— C:\WINDOWS\SYSTEM32\slayerxp.dll
2007-08-03 23:50 22,528 –a—— C:\WINDOWS\SYSTEM32\shfolder.dll
2007-08-03 23:50 22,016 –a—— C:\WINDOWS\SYSTEM32\udhisapi.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-04 05:09:07 ——– d—–w C:\Program Files\Messenger
2007-08-04 05:05:13 ——– d—–w C:\Program Files\Movie Maker
2007-08-03 07:19:30 ——– d—–w C:\Program Files\Microsoft Works
2007-08-02 04:10:48 ——– d—–w C:\Program Files\Lavasoft
2007-07-28 17:14:19 ——– d–h–w C:\Program Files\WindowsUpdate
2007-07-28 14:06:54 ——– d—–w C:\Program Files\License_Manager
2007-07-28 13:27:29 ——– d—–w C:\Program Files\MSN Messenger
2001-07-22 02:45:40 94,784 –sh–w C:\WINDOWS\twain.dll
2001-08-18 05:36:34 46,592 –sh–w C:\WINDOWS\twain_32.dll
2001-08-18 05:36:20 995,383 –sh–w C:\WINDOWS\SYSTEM32\mfc42.dll
2001-08-18 05:36:26 50,688 –sh–w C:\WINDOWS\SYSTEM32\msvcirt.dll
2002-08-29 10:41:10 569,344 –sh–w C:\WINDOWS\SYSTEM32\oleaut32.dll
2001-08-18 05:36:28 106,496 –sh–w C:\WINDOWS\SYSTEM32\olepro32.dll
2001-08-18 05:36:54 9,728 –sh–w C:\WINDOWS\SYSTEM32\regsvr32.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-03-02 14:02]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 01:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KBD"="C:\HP\KBD\KBD.EXE" [2001-07-06 16:56]
"tgcmd"="C:\Program Files\support.com\bin\tgcmd.exe" [2002-04-24 20:37]
"HPGamesActiveMenu"="C:\Program Files\WildTangent\ActiveMenu\HP\Games\ActiveMenu.exe" [2001-06-13 17:40]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-07-28 09:06]
"DiscWizardMonitor.exe"="C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2007-04-19 21:24]
"AcronisTimounterMonitor"="C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe" [2007-04-19 21:38]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [2007-04-19 21:29]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-02 10:35]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeRAM XP"="C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 00:13]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-08-15 19:25]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-07-28 09:06]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 relog_ap

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM95\aim.exe -cnetwait.odl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\System32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
C:\Program Files\Microsoft Works\WkDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE NvQTwk,NvCplDaemon initialize

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

*Newly Created Service* - ANTIVIRSCHEDULER
*Newly Created Service* - ANTIVIRSERVICE
*Newly Created Service* - AVGNTDD
*Newly Created Service* - AVGNTMGR
*Newly Created Service* - AVIPBB

Contents of the 'Scheduled Tasks' folder
2007-08-04 01:00:00 C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
2006-02-21 00:16:34 C:\WINDOWS\tasks\Registration reminder 1.job
2007-08-05 01:12:00 C:\WINDOWS\tasks\Symantec NetDetect.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-04 20:13:04
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

cmd.exe [1048]


scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
tgcmd = "C:\Program Files\support.com\bin\tgcmd.exe" /server?cmd.exe" /server

scanning hidden files …

**************************************************************************

Completion time: 2007-08-04 20:14:47
C:\ComboFix-quarantined-files.txt … 2007-08-04 20:14
C:\ComboFix2.txt … 2007-08-02 23:43

— E O F —
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
++++++++++++++++++++++++++++++++++++++
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
++++++++++++++++++++++++++++++++++++++
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/04/2007 at 09:56 PM

Application Version : 3.9.1008

Core Rules Database Version : 3279
Trace Rules Database Version: 1290

Scan type : Complete Scan
Total Scan Time : 01:38:04

Memory items scanned : 345
Memory threats detected : 0
Registry items scanned : 4591
Registry threats detected : 0
File items scanned : 53612
File threats detected : 10

Adware.Tracking Cookie
C:\Documents and Settings\Owner\Cookies\owner@advertising[2].txt
C:\Documents and Settings\Owner\Cookies\owner@tacoda[1].txt
C:\Documents and Settings\Owner\Cookies\[removed][2].txt
C:\Documents and Settings\Owner\Cookies\owner@2o7[2].txt
C:\Documents and Settings\Owner\Cookies\owner@atdmt[2].txt
C:\Documents and Settings\Owner\Cookies\owner@pandasoftware.112.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@atwola[1].txt

Adware.MovieLand/MediaPipe
C:\PROGRAM FILES\FSUPPORT\NOTIFIER.EXE

TargetSaver, Inc. Process
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593172EE-14D9-4262-8426-24BF2115D284}\RP4\A0002079.EXE

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
++++++++++++++++++++++++++++++++++++++++++
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
++++++++++++++++++++++++++++++++++++++++++

Logfile of HijackThis v1.99.1
Scan saved at 11:10:38 PM, on 8/4/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\HP\KBD\KBD.EXE
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us3.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [HPGamesActiveMenu] C:\Program Files\WildTangent\ActiveMenu\HP\Games\ActiveMenu.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZCxdm484YYUS
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {2F003D51-39FD-4D18-9016-95CF70B92ABE} - http://download.movienetworks.com/install/US/altpmtscab.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1185642789920
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1186201194015
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hi

Of the programs I asked you to consider uninstalling, if I were you, I would urge your friend to remove WildTangent. As you will see in a moment, we will flush out the infected restore points.

Now you can delete the Combofix.exe icon from the Desktop.

Navigate to and delete the following files and/or folders (if they are present):

Folders:
C:\Combofix
C:\Qoobox
C:\PROGRAM FILES\FSUPPORT

I would advise updating Adobe Reader, as the latest version clears up any vulnerabilities of previous versions.
First uninstall the version you have on your computer then download and install Adobe Reader 8.1.

Consider upgrading to Windows XP Service Pack 2, more information can be found
here. My advice is to upgrade as SP2 contains all the latest security patches and has bugs ironed out.


This is my usual speech for when you are clean, which you appear to be.
  • Please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable
    and reenable system restore to make sure there are no infected files found in a restore point.

    You can find instructions on how to enable and reenable system restore here:

    Managing Windows Millenium System Restore

    or

    Windows XP System Restore Guide

    Re-enable system restore with instructions from tutorial above

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Set correct settings for files that should be hidden in Windows XP
  • Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
  • Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
  • If unchecked please checkHide protected operating system files (Recommended)
  • If necessary check "Display content of system folders"
  • If necessary Uncheck Hide file extensions for known file types.
  • Click OK
And take a look at this LINKY for further recommendations and tips to stay clean.

Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI