This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trying To Remove Vundo

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am hoping someone can take a look and see if they think I might have gotten Vundo and whether or not I may have some other problems that may need worked on. I was primarily trying to nail pmkhh.dll and seemed to have found others. I am open to suggestions.
Thanks

VundoFix V6.5.6

Checking Java version…

Java version is 1.5.0.10

Scan started at 9:35:24 PM 8/2/2007

Listing files found while scanning….

C:\WINDOWS\System32\hhkmp.bak1
C:\WINDOWS\System32\hhkmp.bak2
C:\WINDOWS\System32\hhkmp.ini
C:\WINDOWS\System32\hhkmp.ini2
C:\WINDOWS\System32\hhkmp.tmp
C:\windows\system32\noqmdyrv.ini
C:\WINDOWS\System32\pmkhh.dll
C:\windows\system32\vrydmqon.dll
C:\WINDOWS\System32\weskibfk.dll

Beginning removal…

Attempting to delete C:\WINDOWS\System32\hhkmp.bak1
C:\WINDOWS\System32\hhkmp.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\System32\hhkmp.bak2
C:\WINDOWS\System32\hhkmp.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\System32\hhkmp.ini
C:\WINDOWS\System32\hhkmp.ini Has been deleted!

Attempting to delete C:\WINDOWS\System32\hhkmp.ini2
C:\WINDOWS\System32\hhkmp.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\System32\hhkmp.tmp
C:\WINDOWS\System32\hhkmp.tmp Has been deleted!

Attempting to delete C:\windows\system32\noqmdyrv.ini
C:\windows\system32\noqmdyrv.ini Has been deleted!

Attempting to delete C:\WINDOWS\System32\pmkhh.dll
C:\WINDOWS\System32\pmkhh.dll Has been deleted!

Attempting to delete C:\windows\system32\vrydmqon.dll
C:\windows\system32\vrydmqon.dll Has been deleted!

Attempting to delete C:\WINDOWS\System32\weskibfk.dll
C:\WINDOWS\System32\weskibfk.dll Has been deleted!

Performing Repairs to the registry.
Done!


Logfile of HijackThis v1.99.1
Scan saved at 10:44:11 PM, on 8/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Canon\MyPrinter\bak\BJMyPrt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0ABB5D1C-9058-4459-9C68-7CFD401BA950} - C:\WINDOWS\System32\pmkhh.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\found.SH!
O4 - Startup: HotSync Manager.lnk.disabled
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O4 - Global Startup: Adobe Reader Synchronizer.lnk.disabled
O4 - Global Startup: Camio Viewer 2000.lnk.disabled
O4 - Global Startup: Google Updater.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk.disabled
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk.disabled
O4 - Global Startup: Photo Express Calendar Checker SE.lnk.disabled
O4 - Global Startup: PI Monitor.lnk.disabled
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: *.onerateld.com (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200112…meInstaller.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…034/mcfscan.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!
Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!


:thumbup: Nice work. Looks as if you got it.

Yes vundo hides many files. Vundo fix is a great tool for fiding many of them.

______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked

O2 - BHO: (no name) - {0ABB5D1C-9058-4459-9C68-7CFD401BA950} - C:\WINDOWS\System32\pmkhh.dll (file missing)


_____________________________
You need to update SunJava for security reasons.
Updating Java:
Download the latest version of
Java Runtime Environment (JRE) 6u2
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u1… allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the [external image: Posted Image] icon next to it.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.
____________________________

Post a new HJT log for me and let me know if everything seems to be OK.
Bob,
Thanks for the time and help. Sorry it took me a little while to get back with my update. I have installed the java upgrade. I was having desktop, active desktop issues and was able to track down in the desktop display properties settings under the web tab a script being kicked off that is
C:\Program files\Windows Update\visoqokofs_html

I have unchecked that and it is not getting kicked off at startup now. Wanted to mention that. I realize that we should probably delete that sucker but thought I would wait to see how you thought we should proceed.

The following is my last HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 10:19:30 AM, on 8/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Canon\MyPrinter\bak\BJMyPrt.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\found.SH!
O4 - Startup: HotSync Manager.lnk.disabled
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O4 - Global Startup: Adobe Reader Synchronizer.lnk.disabled
O4 - Global Startup: Camio Viewer 2000.lnk.disabled
O4 - Global Startup: Google Updater.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk.disabled
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk.disabled
O4 - Global Startup: Photo Express Calendar Checker SE.lnk.disabled
O4 - Global Startup: PI Monitor.lnk.disabled
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: *.onerateld.com (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200112…meInstaller.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…034/mcfscan.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Let's get 1 more qwuick scan to see what might be left.

1. Download Combo fix from one of these locations.
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


Post the contents of combofix log. (C:/ComboFix.txt)
Bob, Thanks again! Wow, neat tool. While the script was ending just before auto-reboot McAfee firewall was prompting me to allow config modifications which I figure I should allow but am a little concerned I was too slow and did not get them all before the auto-reboot. Should I run combofix again?
Anyway, Here's the log:

ComboFix 07-08-04.3 - "MJM" 2007-08-04 12:29:06.1 [GMT -4:00] - NTFS
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.True


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\WindowsUpdate\visoqokofs.html
C:\tempb9
C:\tempb9\tmpTF.log
C:\Temp\aZ001.exe
C:\temp\iee
C:\temp\iee\tmpZTF.log
C:\temp\tn3
C:\WINDOWS\DOWNLO~1.\temp
C:\WINDOWS\stem~1
C:\WINDOWS\system32\A1
C:\WINDOWS\system32\A2
C:\WINDOWS\system32\A6
C:\WINDOWS\system32\A7
C:\WINDOWS\system32\axumvglv.dll
C:\WINDOWS\system32\cpywwdtt.exe
C:\WINDOWS\system32\djmorcqk.exe
C:\WINDOWS\system32\lxdntmko.exe
C:\WINDOWS\system32\nehqkbmd.exe
C:\WINDOWS\SYSTEM32\nqstv.bak1
C:\WINDOWS\SYSTEM32\nqstv.ini
C:\WINDOWS\SYSTEM32\nqstv.ini2
C:\WINDOWS\SYSTEM32\nqstv.tmp
C:\WINDOWS\system32\o02PrEz
C:\WINDOWS\system32\okgvrupa.exe
C:\WINDOWS\system32\ttghdole.exe
C:\WINDOWS\system32\win


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_MSUDP4
——-\LEGACY_NDNET1
——-\LEGACY_POOF
——-\LEGACY_RUNTIME
——-\LEGACY_RUNTIME2


((((((((((((((((((((((((( Files Created from 2007-07-04 to 2007-08-04 )))))))))))))))))))))))))))))))


2007-08-04 12:25 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-03 18:03 268,435,456 C:\WINDOWS\SYSTEM32\temppf.sys
2007-08-02 21:39 24,576 –a—— C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
2007-08-02 21:35 d——– C:\VundoFix Backups
2007-08-01 19:10 125,504 –a—— C:\WINDOWS\SYSTEM32\jbrluvwq.dll
2007-08-01 18:15 d——– C:\WINDOWS\network diagnostic
2007-08-01 18:14 33,792 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\custsat.dll
2007-07-29 18:41 126,016 –a—— C:\WINDOWS\SYSTEM32\wopydssh.dll
2007-07-29 18:33 126,016 –a—— C:\WINDOWS\SYSTEM32\owvlhyta.dll
2007-07-29 18:12 d——– C:\Program Files\MSXML 4.0
2007-07-29 18:11 23,040 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\fltmc.exe
2007-07-29 18:11 16,896 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\fltlib.dll
2007-07-29 18:11 128,896 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\fltmgr.sys
2007-07-28 15:44 d——– C:\WINDOWS\Prefetch
2007-07-28 15:10 221,184 –a—— C:\WINDOWS\SYSTEM32\wmpns.dll
2007-07-28 14:59 d——– C:\WINDOWS\provisioning
2007-07-28 14:59 d——– C:\WINDOWS\peernet
2007-07-28 13:31 126,016 –a—— C:\WINDOWS\SYSTEM32\hxfhcmvv.dll
2007-07-28 13:28 4,569 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\secupd.dat
2007-07-28 13:28 4,569 ——— C:\WINDOWS\SYSTEM32\secupd.dat
2007-07-28 13:28 11,776 ——— C:\WINDOWS\SYSTEM32\spnpinst.exe
2007-07-28 13:03 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-07-23 20:26 126,016 –a—— C:\WINDOWS\SYSTEM32\hhudpwso.dll
2007-07-23 18:27 126,016 –a—— C:\WINDOWS\SYSTEM32\kwsepgux.dll
2007-07-22 11:48 143,360 –a—— C:\WINDOWS\SYSTEM32\dunzip32.dll
2007-07-22 11:42 71,496 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys
2007-07-22 11:42 37,480 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys
2007-07-22 11:42 34,184 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys
2007-07-22 11:42 32,008 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys
2007-07-22 11:42 170,408 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\mfehidk.sys
2007-07-22 11:41 109,608 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\Mpfp.sys
2007-07-21 13:27 614,912 –a—— C:\WINDOWS\SYSTEM32\h323msp.dll
2007-07-21 13:27 40,960 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\evtgprov.dll
2007-07-21 13:27 331,264 –a—— C:\WINDOWS\SYSTEM32\ipnathlp.dll
2007-07-21 11:20 6,528 —hs—- C:\WINDOWS\SYSTEM32\yccdd.bak1
2007-07-21 10:42 d——– C:\DOCUME~1\MJM\APPLIC~1\Lavasoft


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-04 12:36 ——— d–h—– C:\Program Files\WindowsUpdate
2007-08-01 19:02 ——— d——– C:\Program Files\Common Files\AOL
2007-08-01 18:57 ——— d——– C:\DOCUME~1\MJM\APPLIC~1\AOL
2007-07-29 18:16 ——— d——– C:\Program Files\Messenger
2007-07-28 14:59 ——— d——– C:\Program Files\Movie Maker
2007-07-28 14:51 ——— d——– C:\Program Files\Windows NT
2007-07-24 18:33 ——— d——– C:\Program Files\Google
2007-07-22 14:08 ——— d——– C:\Program Files\McAfee
2007-07-22 11:48 ——— d——– C:\Program Files\Common Files\McAfee
2007-07-22 11:39 ——— d——– C:\Program Files\mcafee.com
2007-07-21 18:33 ——— d——– C:\Program Files\Common Files\Symantec Shared
2007-07-21 13:45 ——— d——– C:\Program Files\Spyware Doctor
2007-07-05 19:15 ——— d–hs—- C:\DOCUME~1\MJM\APPLIC~1\wsnpoem
2007-06-16 22:02 ——— d——– C:\Program Files\process explorer
2007-06-14 04:05 801 –a—— C:\WINDOWS\system32\drivers\system_stable_header_small.gif
2007-06-14 04:05 6533 –a—— C:\WINDOWS\system32\drivers\system_stable_box_small.jpg
2007-06-14 04:05 567 –a—— C:\WINDOWS\system32\drivers\users_rating.gif
2007-06-14 04:05 291 –a—— C:\WINDOWS\system32\drivers\v.gif
2007-06-14 04:05 283 –a—— C:\WINDOWS\system32\drivers\x.gif
2007-06-14 04:05 1636 –a—— C:\WINDOWS\system32\drivers\system_stable_header.gif
2007-06-14 04:05 15075 –a—— C:\WINDOWS\system32\drivers\system_stable_box.jpg
2007-06-14 04:04 841 –a—— C:\WINDOWS\system32\drivers\perfect_cleaner_header_small.gif
2007-06-14 04:04 811 –a—— C:\WINDOWS\system32\drivers\download_btn.gif
2007-06-14 04:04 746 –a—— C:\WINDOWS\system32\drivers\buy_btn.gif
2007-06-14 04:04 737 –a—— C:\WINDOWS\system32\drivers\logo_bg.gif
2007-06-14 04:04 580 –a—— C:\WINDOWS\system32\drivers\features.gif
2007-06-14 04:04 579 –a—— C:\WINDOWS\system32\drivers\spy_away_header_small.gif
2007-06-14 04:04 5097 –a—— C:\WINDOWS\system32\drivers\spy_away_box_small.jpg
2007-06-14 04:04 50088 –a—— C:\WINDOWS\system32\drivers\pt.htm
2007-06-14 04:04 4557 –a—— C:\WINDOWS\system32\drivers\perfect_cleaner_box_small.jpg
2007-06-14 04:04 427 –a—— C:\WINDOWS\system32\drivers\4_stars.gif
2007-06-14 04:04 365 –a—— C:\WINDOWS\system32\drivers\5_stars.gif
2007-06-14 04:04 3099 –a—— C:\WINDOWS\system32\drivers\logo.gif
2007-06-14 04:04 1804 –a—— C:\WINDOWS\system32\drivers\perfect_cleaner_header.gif
2007-06-14 04:04 14484 –a—— C:\WINDOWS\system32\drivers\protect.gif
2007-06-14 04:04 13618 –a—— C:\WINDOWS\system32\drivers\spy_away_box.jpg
2007-06-14 04:04 1139 –a—— C:\WINDOWS\system32\drivers\spy_away_header.gif
2007-06-14 04:04 10260 –a—— C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
2007-06-12 16:48 ——— d——– C:\DOCUME~1\MJM\APPLIC~1\Azureus
2007-06-11 23:01 ——— d——– C:\Program Files\Shockwave.com
2007-05-16 11:12 86528 ——— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 ——— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 ——— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 ——— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 ——— C:\WINDOWS\system32\dllcache\msoe.dll
2007-05-08 05:24 3583488 –a—— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-02-16 14:43 1443213 –a—— C:\DOCUME~1\MJM\APPLIC~1\MJMInstall.dat
2006-03-24 16:41 774144 –a—— C:\Program Files\RngInterstitial.dll
2003-12-18 17:35 11442408 –a—— C:\Program Files\TenPinChampionshipBowlingInstaller.exe
2003-10-24 20:58 4037592 –a—— C:\Program Files\zapSetup_40_146_029.exe
2003-08-07 22:41 3446309 –a—— C:\Program Files\iMeshV4.exe
2003-08-06 21:17 10737891 –a—— C:\Program Files\bpssr60.exe
2002-06-04 11:22 148752 –a—— C:\Program Files\kmd.exe
2002-03-21 23:48 8361472 –a—— C:\Program Files\mirascan_v3424p.exe
2002-03-17 13:53 8981440 –a—— C:\Program Files\ar505enu.exe
2001-11-30 12:09 49152 -ra—— C:\Program Files\Common Files\HDvAvi.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-05-20 23:01]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"DelayShred"="c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\found.SH!

C:\Documents and Settings\MJM\Start Menu\Programs\Startup\
DESKTOP.INI [2001-11-15 09:31:16]
HotSync Manager.lnk.disabled [2004-07-08 21:32:16]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
@=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
Source= C:\Program Files\WindowsUpdate\visoqokofs.html
FriendlyName=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"DefWatch"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Aida"=C:\Documents and Settings\MJM\Application Data\eetu.exe
"DealHelperDown"="C:\WINDOWS\Download.exe"
"WinPop"=C:\Program Files\WinPop\winpop.exe
"Microsoft Works Update Detection"=C:\Program Files\Microsoft Works\WkDetect.exe
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"AIM"=C:\Program Files\AIM\aim.exe -cnetwait.odl
"AOL Fast Start"="C:\Program Files\America Online 9.0b\AOL.EXE" -b
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"kdx"=C:\WINDOWS\kdx\KHost.exe -all
"odbc32"=C:\WINDOWS\System32\odbc32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"startdrv"=C:\WINDOWS\Temp\startdrv.exe
"SiS Mpc Service"=C:\WINDOWS\System32\mpcsvc.exe
"Winmplayer"="C:\WINDOWS\System32\KB_963493.exe"
"svchctrl"=c:\windows\system\svchctrl.exe
"mjmcsr"=csrrs.exe
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe"
"MemoryManager"=rundll32.exe "C:\WINDOWS\System32\hxfhcmvv.dll",sitypnow
"{99-9B-B7-7B-ZN}"=c:\windows\system32\dwdsregt.exe FI002
"AdaptecDirectCD"="C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
"AHQInit"=C:\Program Files\Creative\SBLive\Program\AHQInit.exe
"AOLDialer"=C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
"kzknepsn"=C:\WINDOWS\kzknepsn.exe
"LTWinModem1"=ltmsg.exe 9
"msclean"=C:\WINDOWS\msclean.exe
"NI.UWAS6_0001_N69M0703"="C:\WINDOWS\Downloaded Program Files\CONFLICT.5\UWAS6_0001_N69M0703NetInstaller.exe" -nag
"NvCplDaemon"=RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
"Pure Networks Port Magic"="C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
"sscRun"=C:\Program Files\Common Files\AOL\1108828930\ee\services\sscFirewallPlugin\ver1_10_3_1\SSCRun.exe
"Tsl"=C:\PROGRA~1\COMMON~1\tsa\tsl.exe
"stratas"=
"ViewMgr"=C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
"vptray"=C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
"PE2CKFNT SE"=C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
"POINTER"=point32.exe
"HostManager"=C:\Program Files\Common Files\AOL\1108828930\ee\AOLSoftware.exe
"AOLSPScheduler"=C:\Program Files\Common Files\AOL\1108828930\ee\services\sscAntiSpywarePlugin\ver1_10_3_1\AOLSP Scheduler.exe
"DellTouch"=C:\WINDOWS\DELLMMKB.EXE
"EmailScan"=C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
"OASClnt"=C:\Program Files\mcafee.com\antivirus\oasclnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"mjmcsr"=csrrs.exe

R1 Cdr4_xp;Cdr4_xp;C:\WINDOWS\system32\drivers\Cdr4_xp.sys
R1 cdudf_xp;cdudf_xp;C:\WINDOWS\system32\drivers\cdudf_xp.sys
R1 EPPSCSIx;EPPSCSIx;C:\WINDOWS\system32\drivers\EPPSCSI.SYS
R1 MPFP;MPFP;C:\WINDOWS\system32\Drivers\Mpfp.sys
R1 pwd_2K;pwd_2K;C:\WINDOWS\system32\drivers\pwd_2K.sys
R1 UdfReadr_xp;UdfReadr_xp;C:\WINDOWS\system32\drivers\UdfReadr_xp.sys
R2 MxlW2k;MxlW2k;C:\WINDOWS\system32\drivers\MxlW2k.sys
R2 Nhksrv;Netropa NHK Server;C:\WINDOWS\Nhksrv.exe
R3 DM9102;DAVICOM 9102(A) PCI Fast Ethernet Based NT Driver;C:\WINDOWS\system32\DRIVERS\DM9PCI5.SYS
R3 IPFilter;Microsoft IntelliPoint Features driver;C:\WINDOWS\system32\DRIVERS\IPFilter.sys
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
R3 ltmodem5;Lucent Modem Driver;C:\WINDOWS\system32\DRIVERS\ltmdmxp.sys
R3 mmc_2K;mmc_2K;C:\WINDOWS\system32\drivers\mmc_2K.sys
R3 Msikbd2k;DellTouch;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys
R3 wanatw;WAN Miniport (ATW);C:\WINDOWS\system32\DRIVERS\wanatw4.sys
S2 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
S2 MKEMUSB;Panasonic Digital Palmcorder;C:\WINDOWS\system32\Drivers\Mkemusb.sys
S2 Pcr36;Pcr36;C:\WINDOWS\system32\Pcr36.sys
S3 bvrp_pci;bvrp_pci;C:\WINDOWS\system32\drivers\bvrp_pci.sys
S3 DCamUSBMke;USB Video Camera for Panasonic Digital Palmcorder;C:\WINDOWS\system32\Drivers\Mkeusbi.sys
S3 dvd_2K;dvd_2K;C:\WINDOWS\system32\drivers\dvd_2K.sys
S3 dwusbdnt;dwusbdnt;C:\WINDOWS\system32\DRIVERS\dwusbdnt.sys
S3 EntDrv51;EntDrv51;\??\C:\WINDOWS\System32\drivers\EntDrv51.sys
S3 IKFileFlt;File Filter Driver;C:\WINDOWS\system32\drivers\ikfileflt.sys
S3 IKFileSec;File Security Driver;C:\WINDOWS\system32\drivers\ikfilesec.sys
S3 IkSysFlt;System Filter Driver;C:\WINDOWS\system32\drivers\iksysflt.sys
S3 IKSysSec;System Security Driver;C:\WINDOWS\system32\drivers\iksyssec.sys
S3 MSDV;Microsoft DV Camera and VCR;C:\WINDOWS\system32\DRIVERS\msdv.sys
S3 PalmUSBD;PalmUSBD;C:\WINDOWS\system32\drivers\PalmUSBD.sys
S3 ROOTMODEM;Microsoft Legacy Modem Driver;C:\WINDOWS\system32\Drivers\RootMdm.sys
S4 hpt3xx;hpt3xx;C:\WINDOWS\system32\DRIVERS\hpt3xx.sys


Contents of the 'Scheduled Tasks' folder
2007-07-30 10:24:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-07-22 15:39:49 C:\WINDOWS\Tasks\McDefragTask.job - c:\program files\mcafee\mqc\QcConsol.exe
2007-08-01 21:55:14 C:\WINDOWS\Tasks\McQcTask.job - c:\program files\mcafee\mqc\QcConsol.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-04 12:40:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-04 12:43:29 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-04 12:42

— E O F —
This machine is seriously infected.

!!!!!!!!!!!!!! PLEASE READ THIS CAREFULLY !!!!!!!!!!

If your helping someone with this machine they need to know this NOW!


It looks like you have been infected by several backdoor trojans.

These allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we can't guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found
here

I suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.
If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities.
But I make no promises for this one.

Should you have any questions, please feel free to ask.



Should you decide to clean this machine start by doing the following.

In all honesty If this were a machine in my care I would reformat this thing.


______________________________


Is you McAfee program up to date with a current subscription ?


_________________________________


Download SDFix and save it to your Desktop.

Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop. Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • In Safe Mode, right click the SDFix.zip folder and choose Extract All,
  • Open the extracted folder and double click RunThis.bat to start the script.
  • Type Y to begin the script.
  • It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • Your system will take longer that normal to restart as the fixtool will be running and removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
  • Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log
____________________________________



Please download the OTMoveIt by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\SYSTEM32\yccdd.bak1
    C:\WINDOWS\system32\drivers\perfect_cleaner_header_small.gif
    C:\WINDOWS\system32\drivers\system_stable_box.jpg
    C:\WINDOWS\system32\drivers\system_stable_header.gif
    C:\WINDOWS\system32\drivers\users_rating.gif
    C:\WINDOWS\system32\drivers\v.gif
    C:\WINDOWS\system32\drivers\x.gif
    C:\WINDOWS\system32\drivers\spy_away_box_small.jpg
    C:\WINDOWS\system32\drivers\spy_away_header_small.gif
    C:\WINDOWS\system32\drivers\4_stars.gif C:\WINDOWS\system32\drivers\5_stars.gif C:\WINDOWS\system32\drivers\logo.gif
    C:\WINDOWS\system32\drivers\perfect_cleaner_header.gif
    C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
    C:\WINDOWS\System32\KB_963493.exe
    C:\WINDOWS\System32\mpcsvc.exe
    C:\WINDOWS\SYSTEM32\hxfhcmvv.dll
    C:\WINDOWS\SYSTEM32\jbrluvwq.dll
    c:\windows\system32\dwdsregt.exe


  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
*If a file or folder cannot be moved immediately, you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine, choose Yes.
  • Close OTMoveIt
**If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")



________________________________________________




_________________________________
Please do an online scan with Kaspersky Online Scanner
Click on Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer


Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.



The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:

Save the file to your desktop.

Copy and paste that information in your next post.

___________________________________



_____________________________
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths: 1 at a time.


C:\Program Files\WindowsUpdate\visoqokofs.html

C:\WINDOWS\kzknepsn.exe



Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html


_________________________________


In your next reply I would like to see:
  • A new HJT log
  • The report from Kasperskys
  • The report from OTMOVE IT
  • The report from Kasperskys
  • Let me know if McAfee is upto date with a current subscription.
Bob.
Decided to keep going, and taking precautions.

In your reply you put the following:

In your next reply I would like to see:
A new HJT log
The report from Kasperskys (I will provide the SDFix log for this one)
The report from OTMOVE IT
The report from Kasperskys
Let me know if McAfee is upto date with a current subscription.

The McAfee version should be up to date (have been doing regular updates) and is a free version downloaded via AOL.

I will provide the reports and logs in the order executed:


SDFix: Version 1.95

Run by [removed] on Sun 08/05/2007 at 12:17 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Missing SharedAccess Service

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\DOCUME~1\MJM\LOCALS~1\Temp\abc123.pid - Deleted
C:\WINDOWS\system32\TFTP280 - Deleted
C:\WINDOWS\system32\TFTP3184 - Deleted



Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files:
—————

Backups Folder: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp
C:\Documents and Settings\MJM\Application Data\Microsoft\Templates\~WRL0042.tmp
C:\Documents and Settings\MJM\Application Data\Microsoft\Word\~WRL1536.tmp
C:\Documents and Settings\MJM\Application Data\Microsoft\Word\~WRL2279.tmp
C:\Documents and Settings\MJM\Application Data\Microsoft\Word\~WRL2671.tmp
C:\Documents and Settings\MJM\Application Data\Microsoft\Word\~WRL3577.tmp

Finished

The following is the OTMoveIt log:

C:\WINDOWS\SYSTEM32\yccdd.bak1 moved successfully.
C:\WINDOWS\system32\drivers\perfect_cleaner_header_small.gif moved successfully.
C:\WINDOWS\system32\drivers\system_stable_box.jpg moved successfully.
C:\WINDOWS\system32\drivers\system_stable_header.gif moved successfully.
C:\WINDOWS\system32\drivers\users_rating.gif moved successfully.
C:\WINDOWS\system32\drivers\v.gif moved successfully.
C:\WINDOWS\system32\drivers\x.gif moved successfully.
C:\WINDOWS\system32\drivers\spy_away_box_small.jpg moved successfully.
C:\WINDOWS\system32\drivers\spy_away_header_small.gif moved successfully.
File/Folder C:\WINDOWS\system32\drivers\4_stars.gif C:\WINDOWS\system32\drivers\5_stars.gif C:\WINDOWS\system32\drivers\logo.gif not found.
C:\WINDOWS\system32\drivers\perfect_cleaner_header.gif moved successfully.
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg moved successfully.
File/Folder C:\WINDOWS\System32\KB_963493.exe not found.
File/Folder C:\WINDOWS\System32\mpcsvc.exe not found.
DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\hxfhcmvv.dll
C:\WINDOWS\SYSTEM32\hxfhcmvv.dll NOT unregistered.
C:\WINDOWS\SYSTEM32\hxfhcmvv.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\jbrluvwq.dll
C:\WINDOWS\SYSTEM32\jbrluvwq.dll NOT unregistered.
C:\WINDOWS\SYSTEM32\jbrluvwq.dll moved successfully.
File/Folder c:\windows\system32\dwdsregt.exe not found.

Created on 08/05/2007 12:54:53

NOTE - OTMoveit did not require a reboot to move any files.

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Sunday, August 05, 2007 6:48:13 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 5/08/2007
Kaspersky Anti-Virus database records: 373258
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 118861
Number of viruses found: 21
Number of infected objects: 48
Number of suspicious objects: 0
Duration of the scan process: 02:06:51

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{7636BC05-0144-4BF5-8874-87D89FBAC703}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR2.tmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\MJM\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\MJM\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\MJM\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\MJM\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\MJM\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\MJM\Local Settings\History\History.IE5\MSHist012007080520070806\index.dat Object is locked skipped
C:\Documents and Settings\MJM\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\MJM\ntuser.dat Object is locked skipped
C:\Documents and Settings\MJM\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Downloads\FlipWordsSetup-dm[1].exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Downloads\ScrabbleBlast-dm[1].exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Downloads\ScrabbleBlast-dm[2].exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Downloads\ScrabbleBlastSetup-dm[1].exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Downloads\ScrabbleBlast_Setup-dm[1].exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\My Music\Music Downloads\Music A\-DivX 5 Codec.exe/Gain_Trickler.exe Infected: not-a-virus:AdWare.Win32.Gator.3102 skipped
C:\My Music\Music Downloads\Music A\-DivX 5 Codec.exe Vise: infected - 1 skipped
C:\Program Files\Hijackthis\backups\backup-20070802-190743-192.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kr skipped
C:\Program Files\iMeshV4.exe/WISE0017.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet.d skipped
C:\Program Files\iMeshV4.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.Gator.4104 skipped
C:\Program Files\iMeshV4.exe/WISE0019.BIN/data0008/lsp_.dll Infected: not-a-virus:AdWare.Win32.Sahat.av skipped
C:\Program Files\iMeshV4.exe/WISE0019.BIN/data0008/SAHAgent_.exe Infected: not-a-virus:AdWare.Win32.Sahat.bb skipped
C:\Program Files\iMeshV4.exe/WISE0019.BIN/data0008/SAHDownloader_.exe Infected: not-a-virus:AdWare.Win32.Sahat.e skipped
C:\Program Files\iMeshV4.exe/WISE0019.BIN/data0008 Infected: not-a-virus:AdWare.Win32.Sahat.e skipped
C:\Program Files\iMeshV4.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.Sahat.e skipped
C:\Program Files\iMeshV4.exe/WISE0023.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\Program Files\iMeshV4.exe/WISE0025.BIN/cd_clint.dll Infected: not-a-virus:AdWare.Win32.Cydoor skipped
C:\Program Files\iMeshV4.exe/WISE0025.BIN Infected: not-a-virus:AdWare.Win32.Cydoor skipped
C:\Program Files\iMeshV4.exe/WISE0026.BIN Infected: not-a-virus:AdWare.Win32.Gator.4104 skipped
C:\Program Files\iMeshV4.exe WiseSFX: infected - 11 skipped
C:\Program Files\Morpheus\morpheustoolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Program Files\Shareaza\Incomplete\btih_AAG2BBOLHCRIR32USQWKVWKYWOYJJZD5.partial/ashampoo_movieshrinkburn211_se.exe/stream/data0001/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.dg skipped
C:\Program Files\Shareaza\Incomplete\btih_AAG2BBOLHCRIR32USQWKVWKYWOYJJZD5.partial/ashampoo_movieshrinkburn211_se.exe/stream/data0001/stream Infected: not-a-virus:AdWare.Win32.Agent.dg skipped
C:\Program Files\Shareaza\Incomplete\btih_AAG2BBOLHCRIR32USQWKVWKYWOYJJZD5.partial/ashampoo_movieshrinkburn211_se.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.dg skipped
C:\Program Files\Shareaza\Incomplete\btih_AAG2BBOLHCRIR32USQWKVWKYWOYJJZD5.partial/ashampoo_movieshrinkburn211_se.exe/stream Infected: not-a-virus:AdWare.Win32.Agent.dg skipped
C:\Program Files\Shareaza\Incomplete\btih_AAG2BBOLHCRIR32USQWKVWKYWOYJJZD5.partial/ashampoo_movieshrinkburn211_se.exe Infected: not-a-virus:AdWare.Win32.Agent.dg skipped
C:\Program Files\Shareaza\Incomplete\btih_AAG2BBOLHCRIR32USQWKVWKYWOYJJZD5.partial RAR: infected - 5 skipped
C:\QooBox\Quarantine\C\temp\aZ001.exe.vir/data0002 Infected: Trojan-Dropper.Win32.Agent.mu skipped
C:\QooBox\Quarantine\C\temp\aZ001.exe.vir/data0003 Infected: Trojan.Win32.BHO.ab skipped
C:\QooBox\Quarantine\C\temp\aZ001.exe.vir/data0004 Infected: Trojan-Downloader.Win32.Agent.brf skipped
C:\QooBox\Quarantine\C\temp\aZ001.exe.vir/data0005 Infected: not-a-virus:AdWare.Win32.Agent.dh skipped
C:\QooBox\Quarantine\C\temp\aZ001.exe.vir NSIS: infected - 4 skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\cpywwdtt.exe.vir Infected: Trojan-Dropper.Win32.Agent.bmk skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\djmorcqk.exe.vir Infected: Trojan-Dropper.Win32.Agent.bmk skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\lxdntmko.exe.vir Infected: Trojan-Dropper.Win32.Agent.bmk skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\nehqkbmd.exe.vir Infected: Trojan-Dropper.Win32.Agent.bmk skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\okgvrupa.exe.vir Infected: Trojan-Dropper.Win32.Agent.bmk skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ttghdole.exe.vir Infected: Trojan-Dropper.Win32.Agent.bmk skipped
C:\RECYCLER\S-1-5-21-240772092-1974565712-2106517767-500\Dc2.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\RECYCLER\S-1-5-21-240772092-1974565712-2106517767-500\Dc3.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\RECYCLER\S-1-5-21-240772092-1974565712-2106517767-500\Dc4.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\RECYCLER\S-1-5-21-240772092-1974565712-2106517767-500\Dc5.dll Infected: Trojan.Win32.BHO.bd skipped
C:\VundoFix Backups\pmkhh.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.kr skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{791EB3E2-8594-4C51-B515-2DFD7106600C}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.dat Object is locked skipped
C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.idx Object is locked skipped
C:\WINDOWS\SYSTEM32\DRIVERS\fidbox2.dat Object is locked skipped
C:\WINDOWS\SYSTEM32\DRIVERS\fidbox2.idx Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\hhudpwso.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\WINDOWS\SYSTEM32\kwsepgux.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\WINDOWS\SYSTEM32\owvlhyta.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wopydssh.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped
C:\WINDOWS\Temp\mcafee_25AIIHby1QnTK9C Object is locked skipped
C:\WINDOWS\Temp\mcafee_cFJoDVfj3VWQ2LW Object is locked skipped
C:\WINDOWS\Temp\mcmsc_B73HqVg9aCkOizL Object is locked skipped
C:\WINDOWS\Temp\mcmsc_lYD5ejcSesiRX14 Object is locked skipped
C:\WINDOWS\Temp\mcmsc_pohqsEL7eeStRve Object is locked skipped
C:\WINDOWS\Temp\mcmsc_SolLAuUp2i6v63E Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\_OTMoveIt\MovedFiles\WINDOWS\SYSTEM32\hxfhcmvv.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped

Scan process completed.

Also note - I started to load the Kaspersky free trial version, but stopped the install thinking you said just use the online scan, so that is what was used (the online scan).

The Jotti submissions both came up with the following:
The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file

I believe both files are now gone.


Logfile of HijackThis v1.99.1
Scan saved at 7:15:53 PM, on 8/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\found.SH!
O4 - Startup: HotSync Manager.lnk.disabled
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O4 - Global Startup: Adobe Reader Synchronizer.lnk.disabled
O4 - Global Startup: Camio Viewer 2000.lnk.disabled
O4 - Global Startup: Google Updater.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk.disabled
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk.disabled
O4 - Global Startup: Photo Express Calendar Checker SE.lnk.disabled
O4 - Global Startup: PI Monitor.lnk.disabled
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: *.onerateld.com (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200112…meInstaller.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…034/mcfscan.cab
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked

O15 - Trusted Zone: *.onerateld.com (HKLM)
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):



    C:\Downloads\FlipWordsSetup-dm[1].exe
    C:\Downloads\ScrabbleBlast-dm[1].exe
    C:\Downloads\ScrabbleBlast-dm[2].exe
    C:\Downloads\ScrabbleBlastSetup-dm[1].exe
    C:\My Music\Music Downloads\Music A\-DivX 5 Codec.exe/
    C:\Program Files\iMeshV4.exe/WISE0017.BIN
    C:\Program Files\iMeshV4.exe/WISE0018.BIN
    C:\Program Files\iMeshV4.exe/WISE0019.BIN
    C:\Program Files\iMeshV4.exe/WISE0023.BIN
    C:\Program Files\iMeshV4.exe/WISE0025.BIN
    C:\Program Files\iMeshV4.exe/WISE0025.BIN
    C:\Program Files\iMeshV4.exe/WISE0026.BIN
    C:\Program Files\iMeshV4.exe WiseSFX
    C:\Program Files\Morpheus\morpheustoolbar.exe
    C:\Program FilesFiles\Shareaza\Incomplete\btih_AAG2BBOLHCRIR32USQWKVWKYWOYJJZD5.partial
    C:\WINDOWS\SYSTEM32\hhudpwso.dll
    C:\WINDOWS\SYSTEM32\kwsepgux.dll
    C:\WINDOWS\SYSTEM32\owvlhyta.dll
    C:\WINDOWS\SYSTEM32\wopydssh.dll
    C:\Program Files\WindowsUpdate\visoqokofs.html
    C:\WINDOWS\kzknepsn.exe


  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
*If a file or folder cannot be moved immediately, you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine, choose Yes.
  • Close OTMoveIt
**If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")



____________________________





Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.
  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Issues block to clean anything with this program. It is for experts only and it is risky).



    Kaspersky produced alot. We had better get another from Panda.


    Panda
    Run Panda's ActiveScan from here and perform a full system scan.
    - Once you are on the Panda site click the "Scan your PC" button
    - A new window will open…click the big "Check Now" button
    - Enter your Country
    - Enter your State/Province
    - Enter your Valid Email
    - Select either Home User or Company
    - Click the big Scan Now button
    - If it wants to install an ActiveX component allow it
    - It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
    - Click on "Local Disks" to start the scan
    - When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
    - Post Panda scan results in your next reply


    In your next reply I would like to see:
    • A new HJT log
    • The report from OTMOVEIT
    • The report from Panda
    • Let me know how the computer is behaving now.
Bob,
We seem to be making progress, and I have not noticed any abnormal activities in the last few days or seen any strange requests from the firewall.

You asked for:

In your next reply I would like to see:
    A new HJT log
    The report from OTMOVEIT
    The report from Panda
    Let me know how the computer is behaving now.

    The following HJT log was done after the OTMoveIt was completed and after the Panda run.

    Logfile of HijackThis v1.99.1
    Scan saved at 10:45:11 PM, on 8/6/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16473)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Nhksrv.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\WINDOWS\System32\CTsvcCDA.EXE
    C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\program files\common files\mcafee\mna\mcnasvc.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\PROGRA~1\McAfee\MPS\mps.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\Program Files\McAfee\MPS\mpsevh.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\Explorer.EXE
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
    O4 - HKCU\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\found.SH!
    O4 - Startup: HotSync Manager.lnk.disabled
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
    O4 - Global Startup: Adobe Reader Synchronizer.lnk.disabled
    O4 - Global Startup: Camio Viewer 2000.lnk.disabled
    O4 - Global Startup: Google Updater.lnk.disabled
    O4 - Global Startup: Microsoft Office.lnk.disabled
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk.disabled
    O4 - Global Startup: Photo Express Calendar Checker SE.lnk.disabled
    O4 - Global Startup: PI Monitor.lnk.disabled
    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200112…meInstaller.exe
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…034/mcfscan.cab
    O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
    O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
    O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
    O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
    O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    OTMoveIt Log:

    C:\Downloads\FlipWordsSetup-dm[1].exe moved successfully.
    C:\Downloads\ScrabbleBlast-dm[1].exe moved successfully.
    C:\Downloads\ScrabbleBlast-dm[2].exe moved successfully.
    C:\Downloads\ScrabbleBlastSetup-dm[1].exe moved successfully.
    File/Folder C:\My Music\Music Downloads\Music A\-DivX 5 Codec.exe/ not found.
    File/Folder C:\Program Files\iMeshV4.exe/WISE0017.BIN not found.
    File/Folder C:\Program Files\iMeshV4.exe/WISE0018.BIN not found.
    File/Folder C:\Program Files\iMeshV4.exe/WISE0019.BIN not found.
    File/Folder C:\Program Files\iMeshV4.exe/WISE0023.BIN not found.
    File/Folder C:\Program Files\iMeshV4.exe/WISE0025.BIN not found.
    File/Folder C:\Program Files\iMeshV4.exe/WISE0025.BIN not found.
    File/Folder C:\Program Files\iMeshV4.exe/WISE0026.BIN not found.
    File/Folder C:\Program Files\iMeshV4.exe WiseSFX not found.
    C:\Program Files\Morpheus\morpheustoolbar.exe moved successfully.
    File/Folder C:\Program FilesFiles\Shareaza\Incomplete\btih_AAG2BBOLHCRIR32USQWKVWKYWOYJJZD5.partial not found.
    DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\hhudpwso.dll
    C:\WINDOWS\SYSTEM32\hhudpwso.dll NOT unregistered.
    C:\WINDOWS\SYSTEM32\hhudpwso.dll moved successfully.
    DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\kwsepgux.dll
    C:\WINDOWS\SYSTEM32\kwsepgux.dll NOT unregistered.
    C:\WINDOWS\SYSTEM32\kwsepgux.dll moved successfully.
    DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\owvlhyta.dll
    C:\WINDOWS\SYSTEM32\owvlhyta.dll NOT unregistered.
    C:\WINDOWS\SYSTEM32\owvlhyta.dll moved successfully.
    DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\wopydssh.dll
    C:\WINDOWS\SYSTEM32\wopydssh.dll NOT unregistered.
    C:\WINDOWS\SYSTEM32\wopydssh.dll moved successfully.
    File/Folder C:\Program Files\WindowsUpdate\visoqokofs.html not found.
    File/Folder C:\WINDOWS\kzknepsn.exe not found.

    Created on 08/06/2007 20:02:16


    ActiveScan Log:

    Incident Status Location

    Adware:adware/toolbarpartner Not disinfected c:\$$$_.log
    Spyware:spyware/virtumonde Not disinfected c:\windows\dpusys.ini
    Adware:adware/downloadware Not disinfected c:\program files\MediaLoads
    Adware:adware/savenow Not disinfected Windows Registry
    Adware:adware/sbsoft Not disinfected Windows Registry
    Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\MJM\Desktop\SDFix.exe[SDFix\apps\Process.exe]
    Adware:Adware/Trymedia Not disinfected C:\Downloads\ScrabbleBlast_Setup-dm[1].exe
    Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Program Files\Hijackthis\ComboFix.exe[nircmd.exe]
    Virus:Generic Malware Disinfected C:\Program Files\iMeshV4.exe
    Adware:Adware/Zenosearch Not disinfected C:\QooBox\Quarantine\C\temp\aZ001.exe.vir[am52.exe]
    Adware:Adware/TTC Not disinfected C:\QooBox\Quarantine\C\temp\aZ001.exe.vir[am67.exe]
    Virus:W32/Tobecho.AB.worm Not disinfected C:\QooBox\Quarantine\C\temp\aZ001.exe.vir[wr2.exe]
    Virus:Trj/Downloader.OZB Disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\cpywwdtt.exe.vir
    Virus:Trj/Downloader.OZB Disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\djmorcqk.exe.vir
    Virus:Trj/Downloader.OZB Disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\lxdntmko.exe.vir
    Virus:Trj/Downloader.OZB Disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\nehqkbmd.exe.vir
    Virus:Trj/Downloader.OZB Disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\okgvrupa.exe.vir
    Virus:Trj/Downloader.OZB Disinfected C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ttghdole.exe.vir
    Spyware:Spyware/Virtumonde Not disinfected C:\RECYCLER\S-1-5-21-240772092-1974565712-2106517767-500\Dc2.dll
    Spyware:Spyware/Virtumonde Not disinfected C:\RECYCLER\S-1-5-21-240772092-1974565712-2106517767-500\Dc3.dll
    Spyware:Spyware/Virtumonde Not disinfected C:\RECYCLER\S-1-5-21-240772092-1974565712-2106517767-500\Dc4.dll
    Adware:Adware/WebSearch Not disinfected C:\RECYCLER\S-1-5-21-240772092-1974565712-2106517767-500\Dc5.dll
    Potentially unwanted tool:Application/Processor Not disinfected C:\SDFix\apps\Process.exe
    Potentially unwanted tool:Application/MyWay Not disinfected C:\WINDOWS\Downloaded Program Files\s4initialsetup1.0.0.5.inf
    Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\nircmd.exe
    Adware:Adware/Trymedia Not disinfected C:\_OTMoveIt\MovedFiles\Downloads\FlipWordsSetup-dm[1].exe
    Adware:Adware/Trymedia Not disinfected C:\_OTMoveIt\MovedFiles\Downloads\ScrabbleBlast-dm[1].exe
    Adware:Adware/Trymedia Not disinfected C:\_OTMoveIt\MovedFiles\Downloads\ScrabbleBlast-dm[2].exe
    Adware:Adware/Trymedia Not disinfected C:\_OTMoveIt\MovedFiles\Downloads\ScrabbleBlastSetup-dm[1].exe
    Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\_OTMoveIt\MovedFiles\Program Files\Morpheus\morpheustoolbar.exe
    Spyware:Spyware/Virtumonde Not disinfected C:\_OTMoveIt\MovedFiles\WINDOWS\SYSTEM32\jbrluvwq.dll
1 last thing
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\iMeshV4.exe



  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
*If a file or folder cannot be moved immediately, you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine, choose Yes.
  • Close OTMoveIt
**If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")



____________________________________

Just post the log from OTmoveit.
Bob,
Here you go.

OTMoveIt log:

File/Folder C:\Program Files\iMeshV4.exe not found.

Created on 08/07/2007 17:53:12

And one last HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 5:58:12 PM, on 8/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\MJM\Desktop\OTMoveIt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\found.SH!
O4 - Startup: HotSync Manager.lnk.disabled
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O4 - Global Startup: Adobe Reader Synchronizer.lnk.disabled
O4 - Global Startup: Camio Viewer 2000.lnk.disabled
O4 - Global Startup: Google Updater.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk.disabled
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk.disabled
O4 - Global Startup: Photo Express Calendar Checker SE.lnk.disabled
O4 - Global Startup: PI Monitor.lnk.disabled
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200112…meInstaller.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…034/mcfscan.cab
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Great news ! [external image: Posted Image]

Your log now appears to be clean.

Lets do a few things to tidy up.
Please do these in the order I suggest!


___________________________________
If we have set your computer to see all files and folders we must reprotect them.

UNDO SHOW ALL FILES
click on the My Computer icon.
Select the Tools menu and click Folder Options.
After the new window appears select the View tab.
Deselect in the checkbox labeled Display the contents of system folders.
Deselect the checkbox labeled Show hidden files and folders.
Select the checkmark from the checkbox labeled Hide file extensions for known file types.
Replace the checkmark from the checkbox labeled Hide protected operating system files.
Press the Apply button and then the OK .
Now many important files are safe.


___________________________________
Download and install CCleaner from here.
If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.


Now open the program and click on Run Cleaner
( Do not use the Issues block to clean anything with this program. It is for experts only and it is risky).

You may opt out of cleaning cookies. If you clean them alls you will have to do is retype names and passwords for places you visit on the net 1 time.
If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla
I clean all my cookies out from time to time. It's not that big a deal if you remember passwords.


___________________________________
Please create a 'clean' System Restore Point:
The reason for doing this is in case you need system restore you don't put back all we just took out.
Right click My Computer
Then Propeties then system restore
Place a check mark by turn off system restore
Click APPLY
Windows will give you a warning click yes
REBOOT

Now go right back to the same place and unchecksystem restore
Click APPLYand OK




A few things to help with possible threats

These are optional . But will help protect you further.
___________________________________

SpywareBlaster

Install SpywareBlaster

SpywareBlaster will add a large list of programs and sites to your Internet Explorer settings that will protect you from accidentally running or downloading known malicious programs.
After the installation, click Download Latest Protection Updates. When it finishes, click Enable All Protection.


______________________________
SiteHound

http://www.firetrust.com/firetrustsitehound.html

This tool bar will help protect you from.

Over 4,000 fake bank and credit sites.
Tens of thousands of pornographic
and adult sites.
The never ending fake phishing sites.
Malicious sites, which can infect you
with spyware and adware if you visit
them.
Sites to download software which
may infect your computer with
spyware, a virus or adware


___________________________________
Download and keep this updated and run weekly if you don't already have it.

spybot seach & destroy
Tutorial




___________________________________
Download and Install a HOSTS File
A Hosts file is a plain text file which prevents your computer from connecting to malware and spyware sites by redirecting the connection request to 127.0.0.1, which is your local address. If you use a proxy server, or if you are on AOL, be sure to read the special instructions.
You can download the MVPS Hosts File and see a HOSTS file tutorial here :
This website also contains useful tips, and links to other resources and utilities.


___________________________________
Make your Internet Explorer more secure
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click on the Security tab
3. Click the Internet icon so it becomes highlighted.
4. Click on Default Level and click Ok
5. Click on the Custom Level button.

Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.

6. Next press the Apply button and then the OK to exit the Internet Properties page.

  • Be certain windows stays updated here






Safe and Happy Surfing. :)
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a valid link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used.
If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI