This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Results Of Hijackthis Scan (log)

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Tom,

I joined your team, and downloaded Hijackthis. Can u go over the results of the scan and advise me on how to fix the discrepancies of the items listed. Look forward to your response. Thank u very much.

James





Logfile of HijackThis v1.99.1
Scan saved at 8:11:06 AM, on 8/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\SpywareBot\SpywareBotSrv.srv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Ascentive\ActiveSpeed\AS.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe
C:\WINDOWS\surfmonkey\smproxy.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe
C:\Program Files\mail.com\mcalert.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\James Santos\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie…ton/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://start.earthlink.net/AL/Search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.earthlink.net/partner/more/msie…ton/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.earthlink.net/AL/Search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R3 - URLSearchHook: SrchHook Class - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - C:\Program Files\EarthLink TotalAccess\ElnIE.dll
R3 - URLSearchHook: (no name) - ~EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - ~c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1} - (no file)
R3 - URLSearchHook: (no name) - ~00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: ElnkBhoGuard Class - {00000000-0000-0000-0000-000000000002} - C:\Program Files\EarthLink\Toolbar\EScamBlk.dll
O2 - BHO: IE7pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7pro\IE7pro.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BAHelper Class - {074E3AA7-7718-4404-B3F8-FF8FB5414E0E} - C:\Program Files\BrowserAccelerator\BrowserAccelerator.dll
O2 - BHO: (no name) - {465E08E7-F005-4389-980F-1D8764B3486C} - (no file)
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: ElnkPubBHO Class - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:\Program Files\EarthLink\Toolbar\ElnkPuB.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: ElnkProtectionBHO Class - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:\Program Files\EarthLink\Toolbar\ProtctIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: New_York_Yankees toolbar - {c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1} - C:\Program Files\New_York_Yankees\tbNew_.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink\Toolbar\uninsttb.dll
O3 - Toolbar: EarthLink Toolbar - {C7768536-96F8-4001-B1A2-90EE21279187} - C:\Program Files\EarthLink\Toolbar\Toolbar.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: New_York_Yankees toolbar - {c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1} - C:\Program Files\New_York_Yankees\tbNew_.dll
O3 - Toolbar: BrowserAccelerator - {2D6A91CF-37C6-4EB2-A8D8-F65F1DB14ECE} - C:\Program Files\BrowserAccelerator\BrowserAccelerator.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ActiveSpeed] C:\Program Files\Ascentive\ActiveSpeed\AS.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ELNKProxy] C:\WINDOWS\surfmonkey\smproxy.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe"
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" -l
O4 - HKCU\..\Run: [Mail.com] C:\Program Files\mail.com\mcalert.exe -auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - Startup: Secunia Personal Software Inspector (BETA).lnk = C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: AccountLogon - C:\WINDOWS\al-popup-james santos.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra button: iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: AccountLogon - {1CB13C88-96B6-11d6-9AF5-D12D26EE1F36} - C:\WINDOWS\al-popup-james santos.html (HKCU)
O9 - Extra 'Tools' menuitem: AccountLogon - {1CB13C88-96B6-11d6-9AF5-D12D26EE1F36} - C:\WINDOWS\al-popup-james santos.html (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} (iWon Progressive Counter) - http://cc.iwon.com/ct/pm3/iWonPMSetup_12_1,0,2,5.exe
O16 - DPF: {97BB6657-DC7F-4489-9067-51FAB9D8857D} - http://earthlink.cf1live.com/earthlink/sta…e.WebLaunch.cab
O16 - DPF: {9E515FE4-2A60-4D08-8E96-CF9A967BE49B} - http://check.earthlinksecurity.com/SSMEarthLink.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SpywareBot Scanning Engine (SpywareBotSrv) - Unknown owner - C:\Program Files\SpywareBot\SpywareBotSrv.srv.exe
Hi! Welcome to the Tom Coyote forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.

Hi! Welcome to the Tom Coyote forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient and I'd be grateful if you would note the following:

  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.

Hi Scotty, Just responding to your thread concerning my Hijackthis log, which I read. Here is the information you requested. Bear with my timing on responding, I'm just learning how to use this forum. Thanks! James ActiveSpeed Adobe Flash Player ActiveX Adobe Reader 8.1.0 Adobe Shockwave Player Adobe® Photoshop® Album Starter Edition 3.2 AI RoboForm (All Users) AOL Uninstaller (Choose which Products to Remove) Apple Software Update BearShare Bitzi's Bitcollider 0.6.0 Bug Eliminator 1.3 Comcast High-Speed Internet Install Wizard Comcast Toolbar Conexant HSF V92 56K Data Fax PCI Modem Desktop Doctor EarthLink FastLane EarthLink LiteScanner EarthLink Software EarthLink Toolbar Enigma Browser (remove only) GiPo@MoveOnBoot 1.9.5 Google Toolbar for Internet Explorer HijackThis 1.99.1 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows XP (KB896344) Hotfix for Windows XP (KB906569) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) HP Photo Imaging Software HP Photo Printing Software HP Share-to-Web IE7pro iWon Prize Machine Java™ 6 Update 2 Java™ SE Runtime Environment 6 Update 1 K-Lite Codec Pack 2.69 Full Lernout & Hauspie TruVoice for Microsoft Agent Mail.com Alert Maxthon Browser (remove only) McAfee SecurityCenter Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Microsoft .NET Framework 3.0 Microsoft .NET Framework 3.0 Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Encarta Encyclopedia Standard 2002 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Windows XP Video Decoder Checkup Utility Microsoft Word 2002 Microsoft Works 2002 Setup Launcher Microsoft Works 6.0 Microsoft Works Suite Add-in for Microsoft Word Mozilla Firefox (2.0.0.4) Mozilla Firefox (2.0.0.5) MSN MSN Music Assistant MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 6.0 Parser (KB933579) My Kazaa Gold MySpaceIM Nero 7 Demo Netscape Navigator (9.0b2) New_York_Yankees Toolbar NVIDIA Windows 2000/XP Display Drivers Performance Center Radio365 1.2 RealArcade RegistryFix v5.5 Search Assistant - My Search Secunia Personal Software Inspector (BETA) Security Update for Microsoft .NET Framework 2.0 (KB928365) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB938829) Shareaza version 2.2.5.0 Soft Data Fax Modem with SmartCP SpywareBot System Requirements Lab Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB912945) Update for Windows XP (KB916595) Update for Windows XP (KB920342) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB923845) Update for Windows XP (KB925720) Update for Windows XP (KB925876) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Viewpoint Media Player WebCyberCoach 3.2 Dell Windows Communication Foundation Windows Defender Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Live OneCare safety scanner Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Format 11 SDK Windows Media Player 11 Windows Media Player 11 Windows Media Player Hotfix [See Q828026 for more information] Windows Presentation Foundation Windows Workflow Foundation Windows XP Hotfix - KB873339 Windows XP Hotfix - KB884020 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888240 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Service Pack 2 Wintuneup Pro
Hi

Download and Run SmitfraudFix
Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
Hey Scotty, Here are the results of the test you had me run. Apparently this dug up infected files, No? Well will be waiting on your further instructions. Thanks SmitFraudFix v2.216 Scan done at 22:42:14.48, Thu 08/23/2007 Run from C:\Documents and Settings\James Santos\Desktop\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\Program Files\SpywareBot\SpywareBotSrv.srv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\WINDOWS\System32\cisvc.exe C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe C:\PROGRA~1\McAfee\MSC\mcpromgr.exe c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\system32\devldr32.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\Program Files\Support.com\bin\tgcmd.exe C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Ascentive\ActiveSpeed\AS.exe C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe C:\WINDOWS\surfmonkey\smproxy.exe C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe C:\Program Files\mail.com\mcalert.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Enigma Browser\Enigma.exe c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\James Santos »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\James Santos\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\JAMESS~1\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="http://www.brucelee.org.uk/lee.gif" "SubscribedURL"="http://www.brucelee.org.uk/lee.gif" "FriendlyName"="" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1] "Source"="http://www.allposters.com/IMAGES/PF/PF_971818.JPG" "SubscribedURL"="http://www.allposters.com/IMAGES/PF/PF_971818.JPG" "FriendlyName"="" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\2] "Source"="http://ppc.warhawkenterprises.com/brucelee/bigbossleefist0.jpg" "SubscribedURL"="http://ppc.warhawkenterprises.com/brucelee/bigbossleefist0.jpg" "FriendlyName"="" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: CNet PRO200WL PCI Fast Ethernet Adapter - Packet Scheduler Miniport DNS Server Search Order: 68.87.71.226 DNS Server Search Order: 68.87.73.242 HKLM\SYSTEM\CCS\Services\Tcpip\..\{2FE8B440-AF52-4F75-94F2-071A5AA6C681}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{2FE8B440-AF52-4F75-94F2-071A5AA6C681}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\..\{2FE8B440-AF52-4F75-94F2-071A5AA6C681}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Hi

That didnt go as planned. Delete the Smitfraudfix folder from your Desktop.

Download and Run ComboFix
  • Download this file from below:

    Here
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
Scotty,


Ran the combofix.exe and then hjt, both logs are below. Sorry, couldn't get this to you sooner.

James


ComboFix 07-08-17.2 - "James Santos" 2007-08-24 17:55:41.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.32 [GMT -4:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\cursorcafe.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\cursorcafeA.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\FindIt.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\FindItHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\findithotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\finditxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\games.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\gamesA.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\Highlight.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\HighlightHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\highlighthotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\highlightxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\logo.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\logoxp.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\moviesA.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\Reference.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\ReferenceHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\referencehotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\referencexp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\screensaver.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\screensaverA.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\Weather.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\weatherhotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\weatherxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\contexts\error.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\contexts\related.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\contexts\travel.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\images\walertXP.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\SimpleUpdate\ProductMessagingConfig.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\SimpleUpdate\ProductMessagingConfig.xml.backup
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\SimpleUpdate\SimpleUpdateConfig.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\SimpleUpdate\SimpleUpdateConfig.xml.backup
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\SimpleUpdate\TimerManagerConfig.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\SimpleUpdate\TimerManagerConfig.xml.backup
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\cursorcafe.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\cursorcafeA.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\FindIt.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\FindItHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\findithotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\finditxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\games.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\gamesA.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\Highlight.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\HighlightHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\highlighthotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\highlightxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\logo.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\logoxp.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\moviesA.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\Reference.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\ReferenceHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\referencehotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\referencexp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\screensaver.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\screensaverA.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\Weather.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\weatherhotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\weatherxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\contexts\error.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\contexts\related.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\contexts\travel.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\images\walertXP.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\SimpleUpdate\ProductMessagingConfig.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\SimpleUpdate\ProductMessagingConfig.xml.backup
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\SimpleUpdate\SimpleUpdateConfig.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\SimpleUpdate\SimpleUpdateConfig.xml.backup
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\SimpleUpdate\TimerManagerConfig.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\SimpleUpdate\TimerManagerConfig.xml.backup
C:\DOCUME~1\JAMESS~1\APPLIC~1\FunWebProducts
C:\Program Files\Common Files\companion wizard
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\ScreenSaver\Images1A9123C.urr
C:\Program Files\FunWebProducts\ScreenSaver\Images2EFE8F3.urr
C:\Program Files\FunWebProducts\ScreenSaver\Images2F0B4BF.dat
C:\Program Files\FunWebProducts\ScreenSaver\Images\wrkparam.lst
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\WINDOWS\system32\lsp.dll
C:\WINDOWS\system32\stera.job


((((((((((((((((((((((((( Files Created from 2007-07-24 to 2007-08-24 )))))))))))))))))))))))))))))))


2007-08-24 17:52 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-23 22:42 3,732 –a—— C:\WINDOWS\system32\tmp.reg
2007-08-23 22:41 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-08-23 22:41 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-08-23 22:41 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-08-23 17:20 d——– C:\WINDOWS\LastGood.Tmp
2007-08-16 15:08 18,672 –a—— C:\WINDOWS\system32\drivers\antispyfilter.sys
2007-08-16 15:08 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-08-16 15:07 d——– C:\Program Files\SpywareBot
2007-08-15 12:07 d——– C:\Program Files\MSXML 4.0
2007-08-13 18:17 d——– C:\Program Files\Netscape
2007-08-13 18:17 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Netscape
2007-08-02 18:27 d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\Xdrive
2007-08-01 21:48 71,496 –a—— C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-08-01 21:48 37,480 –a—— C:\WINDOWS\system32\drivers\mfesmfk.sys
2007-08-01 21:48 34,184 –a—— C:\WINDOWS\system32\drivers\mfebopk.sys
2007-08-01 21:48 32,008 –a—— C:\WINDOWS\system32\drivers\mferkdk.sys
2007-08-01 21:48 170,408 –a—— C:\WINDOWS\system32\drivers\mfehidk.sys
2007-08-01 21:47 109,608 –a—— C:\WINDOWS\system32\drivers\Mpfp.sys
2007-08-01 21:44 d——– C:\Program Files\McAfee.com
2007-08-01 21:41 d——– C:\Program Files\Common Files\McAfee
2007-08-01 21:40 d——– C:\Program Files\McAfee
2007-08-01 15:24 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Visual Networks
2007-08-01 14:44 d——– C:\WINDOWS\speech
2007-08-01 14:43 d——– C:\WINDOWS\surfmonkey
2007-08-01 14:43 d——– C:\Program Files\Microsoft Agent
2007-08-01 14:42 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
2007-08-01 13:53 40,960 –a—— C:\AluriaCacheFile.dat
2007-08-01 13:41 d——– C:\Program Files\EarthLink TotalAccess
2007-07-31 12:41 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
2007-07-31 02:07 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\ComcastToolbar
2007-07-31 01:00 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-07-31 00:39 10,920 –a—— C:\aolconnfix.exe
2007-07-30 21:30 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-07-30 17:06 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\AOL
2007-07-30 17:03 d——– C:\Program Files\Common Files\Nullsoft
2007-07-30 17:01 d——– C:\Program Files\Viewpoint
2007-07-30 17:01 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
2007-07-30 16:57 33,588 -ra—— C:\WINDOWS\system32\drivers\wanatw4.sys
2007-07-30 16:53 d——– C:\Program Files\Common Files\aolshare
2007-07-30 16:53 d——– C:\Program Files\AOL 9.0
2007-07-30 16:46 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
2007-07-30 16:27 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Xdrive
2007-07-30 14:32 4,992 –a—— C:\WINDOWS\system32\drivers\loop.sys
2007-07-30 14:31 d——– C:\Program Files\Common Files\AOL
2007-07-30 14:31 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
2007-07-30 14:29 55,808 –a—— C:\WINDOWS\system32\zlib1.dll
2007-07-27 15:48 d——– C:\DOCUME~1\JAMESS~1\.SunDownloadManager
2007-07-26 14:16 d——– C:\Program Files\Secunia
2007-07-24 14:02 d——– C:\Program Files\Bitcollider


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-24 17:52 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Enigma Browser
2007-08-24 14:58 ——— d——– C:\Program Files\BrowserAccelerator
2007-08-16 01:16 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-12 22:35 ——— d——– C:\Program Files\Enigma Browser
2007-08-02 08:00 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\SlimBrowser
2007-08-01 14:55 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\EarthLink
2007-08-01 14:42 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-01 13:28 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\McAfee
2007-07-31 18:40 ——— d——– C:\Program Files\Free Offers from Freeze.com
2007-07-31 02:08 ——— d——– C:\Program Files\ComcastToolbar
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 –a—— C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-27 12:11 ——— d——– C:\Program Files\Google
2007-07-19 11:04 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Leadertech
2007-07-19 10:58 ——— d——– C:\Program Files\Maxthon
2007-07-18 12:11 38567 –a—— C:\WINDOWS\system32\pcpbios.exe
2007-07-14 21:00 7808 –a—— C:\WINDOWS\system32\drivers\psi_mf.sys
2007-07-09 22:03 ——— d——– C:\Program Files\Wintuneup Pro
2007-07-09 09:53 ——— d——– C:\Program Files\mail.com
2007-06-27 20:05 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\WinTuneup Data
2007-06-27 15:58 ——— d——– C:\Program Files\VideoProfessor
2007-06-27 14:52 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Shareaza
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-25 17:28 ——— d——– C:\Program Files\EarthLink
2007-06-25 15:46 ——— d——– C:\Program Files\LexmarkX83
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe
2007-05-24 09:20 8192 –a—— C:\WINDOWS\system32\bitsprx2.dll
2007-05-24 09:20 7168 –a—— C:\WINDOWS\system32\bitsprx3.dll
2007-05-24 09:20 7168 ——— C:\WINDOWS\system32\bitsprx4.dll
2007-05-24 09:20 408064 –a—— C:\WINDOWS\system32\qmgr.dll
2007-05-24 09:20 18944 –a—— C:\WINDOWS\system32\qmgrprxy.dll
2006-05-15 18:33 774144 –a—— C:\Program Files\RngInterstitial.dll
2001-08-18 12:00:00 94,784 –sh–w C:\WINDOWS\twain.dll
2004-08-04 07:56:46 50,688 –sh–w C:\WINDOWS\twain_32.dll
2004-08-04 07:56:42 1,028,096 –sh–w C:\WINDOWS\system32\mfc42.dll
2004-08-04 07:56:43 54,784 –sh–w C:\WINDOWS\system32\msvcirt.dll
2004-08-04 07:56:43 413,696 –sh–w C:\WINDOWS\system32\msvcp60.dll
2007-05-17 11:28:05 549,376 –sh–w C:\WINDOWS\system32\oleaut32.dll
2004-08-04 07:56:44 83,456 –sh–w C:\WINDOWS\system32\olepro32.dll
2004-08-04 07:56:55 11,776 –sh–w C:\WINDOWS\system32\regsvr32.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{074E3AA7-7718-4404-B3F8-FF8FB5414E0E}]
2006-07-12 09:19 255600 –a—— C:\Program Files\BrowserAccelerator\BrowserAccelerator.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1}]
2007-06-03 11:42 1354776 –a—— C:\Program Files\New_York_Yankees\tbNew_.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C7E292F8-1F8D-40A6-8FA6-E6E83D51E7E1}"= C:\Program Files\New_York_Yankees\tbNew_.dll [2007-06-03 11:42 1354776]
"{2D6A91CF-37C6-4EB2-A8D8-F65F1DB14ECE}"= C:\Program Files\BrowserAccelerator\BrowserAccelerator.dll [2006-07-12 09:19 255600]

[HKEY_CLASSES_ROOT\CLSID\{C7E292F8-1F8D-40A6-8FA6-E6E83D51E7E1}]

[HKEY_CLASSES_ROOT\CLSID\{2D6A91CF-37C6-4EB2-A8D8-F65F1DB14ECE}]
[HKEY_CLASSES_ROOT\BrowserAccelerator.ToolBandObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{B0CF4C07-0941-4CE3-865A-D0E8F492A648}]
[HKEY_CLASSES_ROOT\BrowserAccelerator.ToolBandObj]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 00:41]
"tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [2007-03-07 10:58]
"Lexmark X83 Button Monitor"="C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe" [2001-10-18 11:25]
"Lexmark X83 Button Manager"="C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe" [2001-06-14 13:42]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2002-06-27 04:47]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"ActiveSpeed"="C:\Program Files\Ascentive\ActiveSpeed\AS.exe" [2007-01-30 19:00]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 15:19]
"nwiz"="nwiz.exe" [2003-07-28 15:19 C:\WINDOWS\system32\nwiz.exe]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"HostManager"="C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe" [2007-04-12 17:23]
"ELNKProxy"="C:\WINDOWS\surfmonkey\smproxy.exe" [2004-06-18 22:15]
"IPInSightMonitor 01"="C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe" [2005-08-10 21:10]
"IPInSightLAN 01"="C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" [2005-08-10 21:10]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mail.com"="C:\Program Files\mail.com\mcalert.exe" [2007-06-25 04:14]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"SpywareBot"="C:\Program Files\SpywareBot\SpywareBot.exe" []
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
"XdriveTray"="C:\Program Files\Xdrive\Xdrive Desktop\xdrive.exe" /trayicon

C:\Documents and Settings\James Santos\Start Menu\Programs\Startup\
Secunia Personal Software Inspector (BETA).lnk - C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe [2007-07-23 15:26:34]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

R1 AntiSpyFilter;AntiSpyFilter;C:\WINDOWS\system32\DRIVERS\antispyfilter.sys
R2 EarthLinkMonitor;EarthLink Monitor Service;"C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe"
R2 SpywareBotSrv;SpywareBot Scanning Engine;"C:\Program Files\SpywareBot\SpywareBotSrv.srv.exe"
R3 PSI;PSI;C:\WINDOWS\system32\DRIVERS\psi_mf.sys
S3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\system32\Drivers\BW2NDIS5.sys
S3 msloop;Microsoft Loopback Adapter Driver;C:\WINDOWS\system32\DRIVERS\loop.sys


Contents of the 'Scheduled Tasks' folder
2007-08-24 22:18:32 C:\WINDOWS\Tasks\MP Scheduled Scan.job

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-24 18:15:39
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-24 18:26:37 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-24 18:26

— E O F —


Logfile of HijackThis v1.99.1
Scan saved at 1:05:38 AM, on 8/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\SpywareBot\SpywareBotSrv.srv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Ascentive\ActiveSpeed\AS.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe
C:\WINDOWS\surfmonkey\smproxy.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe
C:\Program Files\mail.com\mcalert.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Documents and Settings\James Santos\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie…ton/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: SrchHook Class - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - C:\Program Files\EarthLink TotalAccess\ElnIE.dll
R3 - URLSearchHook: (no name) - ~EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - ~c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1} - (no file)
R3 - URLSearchHook: (no name) - ~00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: ElnkBhoGuard Class - {00000000-0000-0000-0000-000000000002} - C:\Program Files\EarthLink\Toolbar\EScamBlk.dll
O2 - BHO: IE7pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7pro\IE7pro.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BAHelper Class - {074E3AA7-7718-4404-B3F8-FF8FB5414E0E} - C:\Program Files\BrowserAccelerator\BrowserAccelerator.dll
O2 - BHO: (no name) - {465E08E7-F005-4389-980F-1D8764B3486C} - (no file)
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: ElnkPubBHO Class - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:\Program Files\EarthLink\Toolbar\ElnkPuB.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: ElnkProtectionBHO Class - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:\Program Files\EarthLink\Toolbar\ProtctIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: New_York_Yankees toolbar - {c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1} - C:\Program Files\New_York_Yankees\tbNew_.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink\Toolbar\uninsttb.dll
O3 - Toolbar: EarthLink Toolbar - {C7768536-96F8-4001-B1A2-90EE21279187} - C:\Program Files\EarthLink\Toolbar\Toolbar.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: New_York_Yankees toolbar - {c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1} - C:\Program Files\New_York_Yankees\tbNew_.dll
O3 - Toolbar: BrowserAccelerator - {2D6A91CF-37C6-4EB2-A8D8-F65F1DB14ECE} - C:\Program Files\BrowserAccelerator\BrowserAccelerator.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ActiveSpeed] C:\Program Files\Ascentive\ActiveSpeed\AS.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ELNKProxy] C:\WINDOWS\surfmonkey\smproxy.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe"
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" -l
O4 - HKCU\..\Run: [Mail.com] C:\Program Files\mail.com\mcalert.exe -auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Secunia Personal Software Inspector (BETA).lnk = C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: AccountLogon - C:\WINDOWS\al-popup-james santos.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra button: iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: AccountLogon - {1CB13C88-96B6-11d6-9AF5-D12D26EE1F36} - C:\WINDOWS\al-popup-james santos.html (HKCU)
O9 - Extra 'Tools' menuitem: AccountLogon - {1CB13C88-96B6-11d6-9AF5-D12D26EE1F36} - C:\WINDOWS\al-popup-james santos.html (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} (iWon Progressive Counter) - http://cc.iwon.com/ct/pm3/iWonPMSetup_12_1,0,2,5.exe
O16 - DPF: {97BB6657-DC7F-4489-9067-51FAB9D8857D} - http://earthlink.cf1live.com/earthlink/sta…e.WebLaunch.cab
O16 - DPF: {9E515FE4-2A60-4D08-8E96-CF9A967BE49B} - http://check.earthlinksecurity.com/SSMEarthLink.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SpywareBot Scanning Engine (SpywareBotSrv) - Unknown owner - C:\Program Files\SpywareBot\SpywareBotSrv.srv.exe
Hi

I see that Viewpoint Media Player is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto‑updating for the Viewpoint Manager ‑‑ the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.


Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware.
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight >>Viewpoint component<< , click Remove.
  • Do the same for each Viewpoint component.
Remove programs from Add/Remove Programs List
Please go to:
  • Start
  • Control Panel
  • Add/Remove Programs
Find and remove these programs (if they are present)
  • SpywareBot
  • BrowserAccelerator



Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):
R3 - URLSearchHook: (no name) - ~EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - ~c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1} - (no file)
R3 - URLSearchHook: (no name) - ~00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: BAHelper Class - {074E3AA7-7718-4404-B3F8-FF8FB5414E0E} - C:\Program Files\BrowserAccelerator\BrowserAccelerator.dll
O2 - BHO: (no name) - {465E08E7-F005-4389-980F-1D8764B3486C} - (no file)
O3 - Toolbar: BrowserAccelerator - {2D6A91CF-37C6-4EB2-A8D8-F65F1DB14ECE} - C:\Program Files\BrowserAccelerator\BrowserAccelerator.dll
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O23 - Service: SpywareBot Scanning Engine (SpywareBotSrv) - Unknown owner - C:\Program Files\SpywareBot\SpywareBotSrv.srv.exe



WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked exit HijackThis and reboot.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
Scotty,

Below is the outcome of your instructions with new combofix log and hijackthis log

James


ComboFix 07-08-17.2 - "James Santos" 2007-08-25 20:24:59.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.52 [GMT -4:00]


((((((((((((((((((((((((( Files Created from 2007-07-26 to 2007-08-26 )))))))))))))))))))))))))))))))


2007-08-24 17:52 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-23 22:42 3,732 –a—— C:\WINDOWS\system32\tmp.reg
2007-08-23 22:41 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-08-23 22:41 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-08-23 22:41 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-08-16 15:08 18,672 –a—— C:\WINDOWS\system32\drivers\antispyfilter.sys
2007-08-16 15:08 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-08-16 15:07 d——– C:\Program Files\SpywareBot
2007-08-15 12:07 d——– C:\Program Files\MSXML 4.0
2007-08-13 18:17 d——– C:\Program Files\Netscape
2007-08-13 18:17 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Netscape
2007-08-02 18:27 d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\Xdrive
2007-08-01 21:48 71,496 –a—— C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-08-01 21:48 37,480 –a—— C:\WINDOWS\system32\drivers\mfesmfk.sys
2007-08-01 21:48 34,184 –a—— C:\WINDOWS\system32\drivers\mfebopk.sys
2007-08-01 21:48 32,008 –a—— C:\WINDOWS\system32\drivers\mferkdk.sys
2007-08-01 21:48 170,408 –a—— C:\WINDOWS\system32\drivers\mfehidk.sys
2007-08-01 21:47 109,608 –a—— C:\WINDOWS\system32\drivers\Mpfp.sys
2007-08-01 21:44 d——– C:\Program Files\McAfee.com
2007-08-01 21:41 d——– C:\Program Files\Common Files\McAfee
2007-08-01 21:40 d——– C:\Program Files\McAfee
2007-08-01 15:24 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Visual Networks
2007-08-01 14:44 d——– C:\WINDOWS\speech
2007-08-01 14:43 d——– C:\WINDOWS\surfmonkey
2007-08-01 14:43 d——– C:\Program Files\Microsoft Agent
2007-08-01 14:42 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
2007-08-01 13:53 40,960 –a—— C:\AluriaCacheFile.dat
2007-08-01 13:41 d——– C:\Program Files\EarthLink TotalAccess
2007-07-31 12:41 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
2007-07-31 02:07 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\ComcastToolbar
2007-07-31 01:00 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-07-31 00:39 10,920 –a—— C:\aolconnfix.exe
2007-07-30 21:30 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-07-30 17:06 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\AOL
2007-07-30 17:03 d——– C:\Program Files\Common Files\Nullsoft
2007-07-30 16:57 33,588 -ra—— C:\WINDOWS\system32\drivers\wanatw4.sys
2007-07-30 16:53 d——– C:\Program Files\Common Files\aolshare
2007-07-30 16:53 d——– C:\Program Files\AOL 9.0
2007-07-30 16:46 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
2007-07-30 16:27 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Xdrive
2007-07-30 14:32 4,992 –a—— C:\WINDOWS\system32\drivers\loop.sys
2007-07-30 14:31 d——– C:\Program Files\Common Files\AOL
2007-07-30 14:31 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
2007-07-30 14:29 55,808 –a—— C:\WINDOWS\system32\zlib1.dll
2007-07-27 15:48 d——– C:\DOCUME~1\JAMESS~1\.SunDownloadManager
2007-07-26 14:16 d——– C:\Program Files\Secunia


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-25 20:22 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Enigma Browser
2007-08-16 01:16 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-12 22:35 ——— d——– C:\Program Files\Enigma Browser
2007-08-02 08:00 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\SlimBrowser
2007-08-01 14:55 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\EarthLink
2007-08-01 14:42 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-01 13:28 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\McAfee
2007-07-31 18:40 ——— d——– C:\Program Files\Free Offers from Freeze.com
2007-07-31 02:08 ——— d——– C:\Program Files\ComcastToolbar
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 –a—— C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-27 12:11 ——— d——– C:\Program Files\Google
2007-07-24 14:03 ——— d——– C:\Program Files\Bitcollider
2007-07-19 11:04 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Leadertech
2007-07-19 10:58 ——— d——– C:\Program Files\Maxthon
2007-07-18 12:11 38567 –a—— C:\WINDOWS\system32\pcpbios.exe
2007-07-14 21:00 7808 –a—— C:\WINDOWS\system32\drivers\psi_mf.sys
2007-07-09 22:03 ——— d——– C:\Program Files\Wintuneup Pro
2007-07-09 09:53 ——— d——– C:\Program Files\mail.com
2007-06-27 20:05 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\WinTuneup Data
2007-06-27 15:58 ——— d——– C:\Program Files\VideoProfessor
2007-06-27 14:52 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Shareaza
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe
2006-05-15 18:33 774144 –a—— C:\Program Files\RngInterstitial.dll
2001-08-18 12:00:00 94,784 –sh–w C:\WINDOWS\twain.dll
2004-08-04 07:56:46 50,688 –sh–w C:\WINDOWS\twain_32.dll
2004-08-04 07:56:42 1,028,096 –sh–w C:\WINDOWS\system32\mfc42.dll
2004-08-04 07:56:43 54,784 –sh–w C:\WINDOWS\system32\msvcirt.dll
2004-08-04 07:56:43 413,696 –sh–w C:\WINDOWS\system32\msvcp60.dll
2007-05-17 11:28:05 549,376 –sh–w C:\WINDOWS\system32\oleaut32.dll
2004-08-04 07:56:44 83,456 –sh–w C:\WINDOWS\system32\olepro32.dll
2004-08-04 07:56:55 11,776 –sh–w C:\WINDOWS\system32\regsvr32.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1}]
2007-06-03 11:42 1354776 –a—— C:\Program Files\New_York_Yankees\tbNew_.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C7E292F8-1F8D-40A6-8FA6-E6E83D51E7E1}"= C:\Program Files\New_York_Yankees\tbNew_.dll [2007-06-03 11:42 1354776]

[HKEY_CLASSES_ROOT\CLSID\{C7E292F8-1F8D-40A6-8FA6-E6E83D51E7E1}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 00:41]
"tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [2007-03-07 10:58]
"Lexmark X83 Button Monitor"="C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe" [2001-10-18 11:25]
"Lexmark X83 Button Manager"="C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe" [2001-06-14 13:42]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2002-06-27 04:47]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"ActiveSpeed"="C:\Program Files\Ascentive\ActiveSpeed\AS.exe" [2007-01-30 19:00]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 15:19]
"nwiz"="nwiz.exe" [2003-07-28 15:19 C:\WINDOWS\system32\nwiz.exe]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"HostManager"="C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe" [2007-04-12 17:23]
"ELNKProxy"="C:\WINDOWS\surfmonkey\smproxy.exe" [2004-06-18 22:15]
"IPInSightMonitor 01"="C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe" [2005-08-10 21:10]
"IPInSightLAN 01"="C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" [2005-08-10 21:10]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mail.com"="C:\Program Files\mail.com\mcalert.exe" [2007-06-25 04:14]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
"XdriveTray"="C:\Program Files\Xdrive\Xdrive Desktop\xdrive.exe" /trayicon

C:\Documents and Settings\James Santos\Start Menu\Programs\Startup\
Secunia Personal Software Inspector (BETA).lnk - C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe [2007-07-23 15:26:34]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

R1 AntiSpyFilter;AntiSpyFilter;C:\WINDOWS\system32\DRIVERS\antispyfilter.sys
R2 EarthLinkMonitor;EarthLink Monitor Service;"C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe"
R2 SpywareBotSrv;SpywareBot Scanning Engine;"C:\Program Files\SpywareBot\SpywareBotSrv.srv.exe"
R3 PSI;PSI;C:\WINDOWS\system32\DRIVERS\psi_mf.sys
S3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\system32\Drivers\BW2NDIS5.sys
S3 msloop;Microsoft Loopback Adapter Driver;C:\WINDOWS\system32\DRIVERS\loop.sys


Contents of the 'Scheduled Tasks' folder
2007-08-25 23:05:03 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-25 20:31:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-25 20:35:27
C:\ComboFix-quarantined-files.txt … 2007-08-25 20:35
C:\ComboFix2.txt … 2007-08-24 18:26

— E O F —

Logfile of HijackThis v1.99.1
Scan saved at 8:48:03 PM, on 8/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\SpywareBot\SpywareBotSrv.srv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe
C:\WINDOWS\surfmonkey\smproxy.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe
C:\Program Files\mail.com\mcalert.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Enigma Browser\Enigma.exe
C:\Documents and Settings\James Santos\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie…ton/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: SrchHook Class - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - C:\Program Files\EarthLink TotalAccess\ElnIE.dll
O2 - BHO: ElnkBhoGuard Class - {00000000-0000-0000-0000-000000000002} - C:\Program Files\EarthLink\Toolbar\EScamBlk.dll
O2 - BHO: IE7pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7pro\IE7pro.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: ElnkPubBHO Class - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:\Program Files\EarthLink\Toolbar\ElnkPuB.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: ElnkProtectionBHO Class - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:\Program Files\EarthLink\Toolbar\ProtctIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: New_York_Yankees toolbar - {c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1} - C:\Program Files\New_York_Yankees\tbNew_.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink\Toolbar\uninsttb.dll
O3 - Toolbar: EarthLink Toolbar - {C7768536-96F8-4001-B1A2-90EE21279187} - C:\Program Files\EarthLink\Toolbar\Toolbar.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: New_York_Yankees toolbar - {c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1} - C:\Program Files\New_York_Yankees\tbNew_.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ActiveSpeed] C:\Program Files\Ascentive\ActiveSpeed\AS.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ELNKProxy] C:\WINDOWS\surfmonkey\smproxy.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe"
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" -l
O4 - HKCU\..\Run: [Mail.com] C:\Program Files\mail.com\mcalert.exe -auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Secunia Personal Software Inspector (BETA).lnk = C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: AccountLogon - C:\WINDOWS\al-popup-james santos.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra button: iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: AccountLogon - {1CB13C88-96B6-11d6-9AF5-D12D26EE1F36} - C:\WINDOWS\al-popup-james santos.html (HKCU)
O9 - Extra 'Tools' menuitem: AccountLogon - {1CB13C88-96B6-11d6-9AF5-D12D26EE1F36} - C:\WINDOWS\al-popup-james santos.html (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} (iWon Progressive Counter) - http://cc.iwon.com/ct/pm3/iWonPMSetup_12_1,0,2,5.exe
O16 - DPF: {97BB6657-DC7F-4489-9067-51FAB9D8857D} - http://earthlink.cf1live.com/earthlink/sta…e.WebLaunch.cab
O16 - DPF: {9E515FE4-2A60-4D08-8E96-CF9A967BE49B} - http://check.earthlinksecurity.com/SSMEarthLink.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SpywareBot Scanning Engine (SpywareBotSrv) - Unknown owner - C:\Program Files\SpywareBot\SpywareBotSrv.srv.exe
Hi

Delete bad services
Please copy (Ctrl+C) and paste (Ctrl+V) the following text in the quote to Notepad. Save it as "All Files" and name it FixServices.bat Please save it on your desktop.

@echo off
sc stop "SpywareBotSrv"
sc delete "SpywareBotSrv"
del Fixservices.bat
exit


Double click FixServices.bat. A window will open and close. This is normal.

Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\WINDOWS\system32\drivers\antispyfilter.sys

Folder::
C:\Program Files\SpywareBot

Registry::
[-HKEY_CLASSES_ROOT\CLSID\{C7E292F8-1F8D-40A6-8FA6-E6E83D51E7E1}]

Driver::
AntiSpyFilter
SpywareBotSrv

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.
  • Please go HERE to run PandaActiveScan…

  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)

  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to your desktop.
Post the Panda report with the new Combofix log and the new HijackThis log, please.
Scotty,


Below is the 3 scans you requested. Goodluck.

James

ComboFix 07-08-17.2 - "James Santos" 2007-08-26 17:04:28.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.39 [GMT -4:00]
Command switches used :: C:\Documents and Settings\James Santos\Desktop\CFScript
* Created a new restore point

FILE::
C:\WINDOWS\system32\drivers\antispyfilter.sys


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\SpywareBot
C:\Program Files\SpywareBot\Databases\Spy.ref
C:\Program Files\SpywareBot\Launcher.exe
C:\Program Files\SpywareBot\Microsoft.VC80.ATL\atl80.dll
C:\Program Files\SpywareBot\Microsoft.VC80.ATL\Microsoft.VC80.ATL.manifest
C:\Program Files\SpywareBot\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
C:\Program Files\SpywareBot\Microsoft.VC80.CRT\msvcp80.dll
C:\Program Files\SpywareBot\Microsoft.VC80.CRT\msvcr80.dll
C:\Program Files\SpywareBot\SpyCleaner.plg.dll
C:\Program Files\SpywareBot\SpywareBotSrv.srv.exe
C:\Program Files\SpywareBot\vistaCPtasks.xml
C:\WINDOWS\system32\drivers\antispyfilter.sys


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_ANTISPYFILTER
——-\AntiSpyFilter


((((((((((((((((((((((((( Files Created from 2007-07-26 to 2007-08-26 )))))))))))))))))))))))))))))))


2007-08-25 23:41 d——– C:\DOCUME~1\CODYSA~1\APPLIC~1\COMCASTTOOLBAR
2007-08-24 17:52 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-23 22:42 3,732 –a—— C:\WINDOWS\system32\tmp.reg
2007-08-23 22:41 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-08-23 22:41 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-08-23 22:41 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-08-16 15:08 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-08-15 12:07 d——– C:\Program Files\MSXML 4.0
2007-08-13 18:17 d——– C:\Program Files\Netscape
2007-08-13 18:17 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Netscape
2007-08-02 18:27 d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\Xdrive
2007-08-01 21:48 71,496 –a—— C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-08-01 21:48 37,480 –a—— C:\WINDOWS\system32\drivers\mfesmfk.sys
2007-08-01 21:48 34,184 –a—— C:\WINDOWS\system32\drivers\mfebopk.sys
2007-08-01 21:48 32,008 –a—— C:\WINDOWS\system32\drivers\mferkdk.sys
2007-08-01 21:48 170,408 –a—— C:\WINDOWS\system32\drivers\mfehidk.sys
2007-08-01 21:47 109,608 –a—— C:\WINDOWS\system32\drivers\Mpfp.sys
2007-08-01 21:44 d——– C:\Program Files\McAfee.com
2007-08-01 21:41 d——– C:\Program Files\Common Files\McAfee
2007-08-01 21:40 d——– C:\Program Files\McAfee
2007-08-01 15:24 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Visual Networks
2007-08-01 14:44 d——– C:\WINDOWS\speech
2007-08-01 14:43 d——– C:\WINDOWS\surfmonkey
2007-08-01 14:43 d——– C:\Program Files\Microsoft Agent
2007-08-01 14:42 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
2007-08-01 13:53 40,960 –a—— C:\AluriaCacheFile.dat
2007-08-01 13:41 d——– C:\Program Files\EarthLink TotalAccess
2007-07-31 12:41 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
2007-07-31 02:07 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\ComcastToolbar
2007-07-31 01:00 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-07-31 00:39 10,920 –a—— C:\aolconnfix.exe
2007-07-30 21:30 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-07-30 17:06 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\AOL
2007-07-30 17:03 d——– C:\Program Files\Common Files\Nullsoft
2007-07-30 16:57 33,588 -ra—— C:\WINDOWS\system32\drivers\wanatw4.sys
2007-07-30 16:53 d——– C:\Program Files\Common Files\aolshare
2007-07-30 16:53 d——– C:\Program Files\AOL 9.0
2007-07-30 16:46 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
2007-07-30 16:27 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Xdrive
2007-07-30 14:32 4,992 –a—— C:\WINDOWS\system32\drivers\loop.sys
2007-07-30 14:31 d——– C:\Program Files\Common Files\AOL
2007-07-30 14:31 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
2007-07-30 14:29 55,808 –a—— C:\WINDOWS\system32\zlib1.dll
2007-07-27 15:48 d——– C:\DOCUME~1\JAMESS~1\.SunDownloadManager
2007-07-26 14:16 d——– C:\Program Files\Secunia


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-26 17:03 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Enigma Browser
2007-08-16 01:16 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-12 22:35 ——— d——– C:\Program Files\Enigma Browser
2007-08-02 08:00 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\SlimBrowser
2007-08-01 14:55 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\EarthLink
2007-08-01 14:42 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-01 13:28 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\McAfee
2007-07-31 18:40 ——— d——– C:\Program Files\Free Offers from Freeze.com
2007-07-31 02:08 ——— d——– C:\Program Files\ComcastToolbar
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 –a—— C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-27 12:11 ——— d——– C:\Program Files\Google
2007-07-24 14:03 ——— d——– C:\Program Files\Bitcollider
2007-07-19 11:04 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Leadertech
2007-07-19 10:58 ——— d——– C:\Program Files\Maxthon
2007-07-18 12:11 38567 –a—— C:\WINDOWS\system32\pcpbios.exe
2007-07-14 21:00 7808 –a—— C:\WINDOWS\system32\drivers\psi_mf.sys
2007-07-09 22:03 ——— d——– C:\Program Files\Wintuneup Pro
2007-07-09 09:53 ——— d——– C:\Program Files\mail.com
2007-06-27 20:05 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\WinTuneup Data
2007-06-27 15:58 ——— d——– C:\Program Files\VideoProfessor
2007-06-27 14:52 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Shareaza
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe
2006-05-15 18:33 774144 –a—— C:\Program Files\RngInterstitial.dll
2001-08-18 12:00:00 94,784 –sh–w C:\WINDOWS\twain.dll
2004-08-04 07:56:46 50,688 –sh–w C:\WINDOWS\twain_32.dll
2004-08-04 07:56:42 1,028,096 –sh–w C:\WINDOWS\system32\mfc42.dll
2004-08-04 07:56:43 54,784 –sh–w C:\WINDOWS\system32\msvcirt.dll
2004-08-04 07:56:43 413,696 –sh–w C:\WINDOWS\system32\msvcp60.dll
2007-05-17 11:28:05 549,376 –sh–w C:\WINDOWS\system32\oleaut32.dll
2004-08-04 07:56:44 83,456 –sh–w C:\WINDOWS\system32\olepro32.dll
2004-08-04 07:56:55 11,776 –sh–w C:\WINDOWS\system32\regsvr32.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 00:41]
"tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [2007-03-07 10:58]
"Lexmark X83 Button Monitor"="C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe" [2001-10-18 11:25]
"Lexmark X83 Button Manager"="C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe" [2001-06-14 13:42]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2002-06-27 04:47]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"ActiveSpeed"="C:\Program Files\Ascentive\ActiveSpeed\AS.exe" [2007-01-30 19:00]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 15:19]
"nwiz"="nwiz.exe" [2003-07-28 15:19 C:\WINDOWS\system32\nwiz.exe]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"HostManager"="C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe" [2007-04-12 17:23]
"ELNKProxy"="C:\WINDOWS\surfmonkey\smproxy.exe" [2004-06-18 22:15]
"IPInSightMonitor 01"="C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe" [2005-08-10 21:10]
"IPInSightLAN 01"="C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" [2005-08-10 21:10]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mail.com"="C:\Program Files\mail.com\mcalert.exe" [2007-06-25 04:14]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
"XdriveTray"="C:\Program Files\Xdrive\Xdrive Desktop\xdrive.exe" /trayicon

C:\Documents and Settings\James Santos\Start Menu\Programs\Startup\
Secunia Personal Software Inspector (BETA).lnk - C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe [2007-07-23 15:26:34]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

R2 EarthLinkMonitor;EarthLink Monitor Service;"C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe"
R3 PSI;PSI;C:\WINDOWS\system32\DRIVERS\psi_mf.sys
S3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\system32\Drivers\BW2NDIS5.sys
S3 msloop;Microsoft Loopback Adapter Driver;C:\WINDOWS\system32\DRIVERS\loop.sys


Contents of the 'Scheduled Tasks' folder
2007-08-26 21:33:41 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-26 17:31:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-26 17:39:42 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-26 17:39
C:\ComboFix2.txt … 2007-08-25 20:35
C:\ComboFix3.txt … 2007-08-24 18:26

— E O F —

Logfile of HijackThis v1.99.1
Scan saved at 5:51:00 PM, on 8/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Ascentive\ActiveSpeed\AS.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe
C:\WINDOWS\surfmonkey\smproxy.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe
C:\Program Files\mail.com\mcalert.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Enigma Browser\Enigma.exe
C:\Documents and Settings\James Santos\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie…ton/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: SrchHook Class - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - C:\Program Files\EarthLink TotalAccess\ElnIE.dll
O2 - BHO: ElnkBhoGuard Class - {00000000-0000-0000-0000-000000000002} - C:\Program Files\EarthLink\Toolbar\EScamBlk.dll
O2 - BHO: IE7pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7pro\IE7pro.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: ElnkPubBHO Class - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:\Program Files\EarthLink\Toolbar\ElnkPuB.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: ElnkProtectionBHO Class - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:\Program Files\EarthLink\Toolbar\ProtctIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1} - (no file)
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink\Toolbar\uninsttb.dll
O3 - Toolbar: EarthLink Toolbar - {C7768536-96F8-4001-B1A2-90EE21279187} - C:\Program Files\EarthLink\Toolbar\Toolbar.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: (no name) - {c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ActiveSpeed] C:\Program Files\Ascentive\ActiveSpeed\AS.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ELNKProxy] C:\WINDOWS\surfmonkey\smproxy.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe"
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" -l
O4 - HKCU\..\Run: [Mail.com] C:\Program Files\mail.com\mcalert.exe -auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Secunia Personal Software Inspector (BETA).lnk = C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: AccountLogon - C:\WINDOWS\al-popup-james santos.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra button: iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: AccountLogon - {1CB13C88-96B6-11d6-9AF5-D12D26EE1F36} - C:\WINDOWS\al-popup-james santos.html (HKCU)
O9 - Extra 'Tools' menuitem: AccountLogon - {1CB13C88-96B6-11d6-9AF5-D12D26EE1F36} - C:\WINDOWS\al-popup-james santos.html (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} (iWon Progressive Counter) - http://cc.iwon.com/ct/pm3/iWonPMSetup_12_1,0,2,5.exe
O16 - DPF: {97BB6657-DC7F-4489-9067-51FAB9D8857D} - http://earthlink.cf1live.com/earthlink/sta…e.WebLaunch.cab
O16 - DPF: {9E515FE4-2A60-4D08-8E96-CF9A967BE49B} - http://check.earthlinksecurity.com/SSMEarthLink.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe



Incident Status Location

Potentially unwanted tool:application/funweb Not disinfected c:\windows\downloaded program files\f3initialsetup1.0.0.15-3.inf
Adware:adware/cydoor Not disinfected c:\windows\cdmxtras
Spyware:spyware/browseraccelerator Not disinfected Windows Registry
Potentially unwanted tool:application/mywebsearch Not disinfected hkey_current_user\software\MyWebSearch
Potentially unwanted tool:application/iwon Not disinfected hkey_local_machine\software\iWon
Potentially unwanted tool:application/myway Not disinfected hkey_classes_root\clsid\{04079851-5845-4dea-848C-3ECD647AA554}
Adware:adware/ist.istbar Not disinfected Windows Registry
Adware:adware/savenow Not disinfected Windows Registry
Adware:adware/exact.bargainbuddy Not disinfected Windows Registry
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.azjmp.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.webpower.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[landing.domainsponsor.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Cody Santos\Cookies\[removed]-sys[2].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@ccbill[2].txt
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@clickbank[1].txt
Spyware:Cookie/Powerscan Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@gammae[2].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@overture[2].txt
Spyware:Cookie/WegCash Not disinfected C:\Documents and Settings\Cody Santos\Cookies\[removed][2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@serving-sys[2].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@statcounter[2].txt
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@webpower[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Cody Santos\Cookies\[removed][1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@yadro[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.com.com/]
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.clickbank.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.2o7.net/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.zedo.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.com.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@247realmedia[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@2o7[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@adrevolver[2].txt
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][2].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][1].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@advertising[2].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@apmebf[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@atwola[1].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@azjmp[2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed]-sys[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@casalemedia[2].txt
Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@centrport[1].txt
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@clickbank[2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@com[2].txt
Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@doubleclick[1].txt
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@enhance[2].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@errorsafe[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@fastclick[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@go[2].txt
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][2].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@maxserving[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@mediaplex[2].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@overture[2].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@questionmarket[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@realmedia[1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][5].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@serving-sys[2].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@statcounter[1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][1].txt
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][2].txt
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@tradedoubler[2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@trafficmp[2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@tribalfusion[1].txt
Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@weborama[2].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@winantivirus[2].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@zedo[2].txt
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\James Santos\Desktop\ComboFix.exe[nircmd.exe]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[.atdmt.com/]
Virus:Generic Malware Disinfected C:\Program Files\Bitcollider\bitcoll.dll
Potentially unwanted tool:Application/iWon Not disinfected C:\Program Files\iWon\iWonSlot\bin\cpltSetp.exe
Potentially unwanted tool:Application/iWon Not disinfected C:\WINDOWS\Downloaded Program Files\iwonslot1,0,2,5.inf
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\nircmd.exe
Potentially unwanted tool:Application/RealSpy Not disinfected C:\WINDOWS\system32\actskn45.ocx
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
Hi

Download AVG Anti-Spyware.
  • Install AVG Anti-Spyware.
  • Launch AVG by double-clicking on the icon.
  • The program will now open to the main screen.
  • You will need to update AVG to the latest definition files.
  • At the top of the main screen click Update.
  • Then in the Manual Update section, click on Start Update.
[*]The update will start and a progress bar will show the updates being installed.

[*]When updates are completed, close AVG.

If you are having problems with the updater, you can use this link to manually update AVG.
AVG manual updates

Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it.

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.

*Note* If you do not have Firefox or Opera, those options will be greyed out.

Open Notepad and Copy/Paste the text in the codebox below into it:

File::
c:\windows\downloaded program files\f3initialsetup1.0.0.15-3.inf

Folder::
C:\Program Files\Free Offers from Freeze.com
c:\windows\cdmxtras

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1}]

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.

Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} (iWon Progressive Counter) - http://cc.iwon.com/ct/pm3/iWonPMSetup_12_1,0,2,5.exe
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab


WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit HijackThis.

Run a scan with AVG.
  • Click on Scanner
    • Click on the Settings tab, and set the following settings.
      • How to act
      • Click on Recommended actions, and set to Quarantine.
    • How to scan
      • Check all options.
    • Possibly unwanted software.
      • Check all options.
    • Reports
      • Check Do not automatically generate reports after every scan.
    • What to scan
      • Check Scan every file.
  • Click on the Scan tab.
    • Click on Complete System Scan and the scan will begin.
    • When the scan has finished
    • Make sure that Set all elements to: shows Quarantine, if not click on the link and choose Quarantine from the popup menu.
    • At the bottom of the window click on the Apply all Actions button.
Note: Don't save the report before you hit the Apply action button.

Close AVG Anti-Spyware.

AVG will save a report in the following location C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports


Post back with the Combofix log, AVG report and a new HijackThis log please.
Scotty,


I think I screwed up, the log for combofix which I ran and had I tried to paste it to reply, but being that it took me a while to do all the steps my login time on the forum expired, it was already in there, but when I went to add reply It was lost, can u tell me how to retrieve the one that you need? Sorry.

James

Logfile of HijackThis v1.99.1
Scan saved at 3:33:47 PM, on 8/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Ascentive\ActiveSpeed\AS.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe
C:\WINDOWS\surfmonkey\smproxy.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe
C:\Program Files\mail.com\mcalert.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe
C:\Program Files\Enigma Browser\Enigma.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\James Santos\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie…ton/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: SrchHook Class - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - C:\Program Files\EarthLink TotalAccess\ElnIE.dll
O2 - BHO: ElnkBhoGuard Class - {00000000-0000-0000-0000-000000000002} - C:\Program Files\EarthLink\Toolbar\EScamBlk.dll
O2 - BHO: IE7pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7pro\IE7pro.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: ElnkPubBHO Class - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:\Program Files\EarthLink\Toolbar\ElnkPuB.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: ElnkProtectionBHO Class - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:\Program Files\EarthLink\Toolbar\ProtctIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink\Toolbar\uninsttb.dll
O3 - Toolbar: EarthLink Toolbar - {C7768536-96F8-4001-B1A2-90EE21279187} - C:\Program Files\EarthLink\Toolbar\Toolbar.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: (no name) - {c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ActiveSpeed] C:\Program Files\Ascentive\ActiveSpeed\AS.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ELNKProxy] C:\WINDOWS\surfmonkey\smproxy.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe"
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" -l
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Mail.com] C:\Program Files\mail.com\mcalert.exe -auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Secunia Personal Software Inspector (BETA).lnk = C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: AccountLogon - C:\WINDOWS\al-popup-james santos.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra button: iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: AccountLogon - {1CB13C88-96B6-11d6-9AF5-D12D26EE1F36} - C:\WINDOWS\al-popup-james santos.html (HKCU)
O9 - Extra 'Tools' menuitem: AccountLogon - {1CB13C88-96B6-11d6-9AF5-D12D26EE1F36} - C:\WINDOWS\al-popup-james santos.html (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {97BB6657-DC7F-4489-9067-51FAB9D8857D} - http://earthlink.cf1live.com/earthlink/sta…e.WebLaunch.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9E515FE4-2A60-4D08-8E96-CF9A967BE49B} - http://check.earthlinksecurity.com/SSMEarthLink.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


Incident Status Location

Potentially unwanted tool:application/funweb Not disinfected c:\windows\downloaded program files\f3initialsetup1.0.0.15-3.inf
Adware:adware/cydoor Not disinfected c:\windows\cdmxtras
Spyware:spyware/browseraccelerator Not disinfected Windows Registry
Potentially unwanted tool:application/mywebsearch Not disinfected hkey_current_user\software\MyWebSearch
Potentially unwanted tool:application/iwon Not disinfected hkey_local_machine\software\iWon
Potentially unwanted tool:application/myway Not disinfected hkey_classes_root\clsid\{04079851-5845-4dea-848C-3ECD647AA554}
Adware:adware/ist.istbar Not disinfected Windows Registry
Adware:adware/savenow Not disinfected Windows Registry
Adware:adware/exact.bargainbuddy Not disinfected Windows Registry
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.azjmp.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.webpower.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[landing.domainsponsor.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Cody Santos\Application Data\Mozilla\Firefox\Profiles\e7hd1k77.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Cody Santos\Cookies\[removed]-sys[2].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@ccbill[2].txt
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@clickbank[1].txt
Spyware:Cookie/Powerscan Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@gammae[2].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@overture[2].txt
Spyware:Cookie/WegCash Not disinfected C:\Documents and Settings\Cody Santos\Cookies\[removed][2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@serving-sys[2].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@statcounter[2].txt
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@webpower[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Cody Santos\Cookies\[removed][1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Cody Santos\Cookies\cody_santos@yadro[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.com.com/]
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\James Santos\Application Data\Mozilla\Firefox\Profiles\ylum1h2y.default\cookies.txt[.clickbank.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.2o7.net/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.zedo.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.com.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\James Santos\Application Data\Netscape\Navigator\Profiles\c6lmg8vj.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@247realmedia[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@2o7[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@adrevolver[2].txt
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][2].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][1].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@advertising[2].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@apmebf[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@atwola[1].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@azjmp[2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed]-sys[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@casalemedia[2].txt
Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@centrport[1].txt
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@clickbank[2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@com[2].txt
Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@doubleclick[1].txt
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@enhance[2].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@errorsafe[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@fastclick[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@go[2].txt
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][2].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@maxserving[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@mediaplex[2].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@overture[2].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@questionmarket[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@realmedia[1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][5].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@serving-sys[2].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@statcounter[1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][1].txt
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][2].txt
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@tradedoubler[2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@trafficmp[2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@tribalfusion[1].txt
Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@weborama[2].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@winantivirus[2].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\James Santos\Cookies\[removed][1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\James Santos\Cookies\james_santos@zedo[2].txt
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\James Santos\Desktop\ComboFix.exe[nircmd.exe]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Linda Santos\Application Data\Mozilla\Firefox\Profiles\nporsd73.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Suspect\Application Data\Mozilla\Firefox\Profiles\qak6hcht.default\cookies.txt[.atdmt.com/]
Virus:Generic Malware Disinfected C:\Program Files\Bitcollider\bitcoll.dll
Potentially unwanted tool:Application/iWon Not disinfected C:\Program Files\iWon\iWonSlot\bin\cpltSetp.exe
Potentially unwanted tool:Application/iWon Not disinfected C:\WINDOWS\Downloaded Program Files\iwonslot1,0,2,5.inf
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\nircmd.exe
Potentially unwanted tool:Application/RealSpy Not disinfected C:\WINDOWS\system32\actskn45.ocx
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
ComboFix 07-08-17.2 - "James Santos" 2007-08-27 13:42:09.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.34 [GMT -4:00]
Command switches used :: C:\Documents and Settings\James Santos\Desktop\CFScript
* Created a new restore point

FILE::
c:\windows\downloaded program files\f3initialsetup1.0.0.15-3.inf


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Free Offers from Freeze.com
C:\Program Files\Free Offers from Freeze.com61016_icon_frosty_games.ico
C:\Program Files\Free Offers from Freeze.com\101_Free_Songs.ico
C:\Program Files\Free Offers from Freeze.com\3737.url
C:\Program Files\Free Offers from Freeze.com\3763.url
C:\Program Files\Free Offers from Freeze.com\3764.url
C:\Program Files\Free Offers from Freeze.com\3767.url
C:\Program Files\Free Offers from Freeze.com\3778.url
C:\Program Files\Free Offers from Freeze.com\control.txt
C:\Program Files\Free Offers from Freeze.com\propel.ico
C:\Program Files\Free Offers from Freeze.com\Ringtones.ico
c:\windows\cdmxtras
c:\windows\downloaded program files\f3initialsetup1.0.0.15-3.inf


((((((((((((((((((((((((( Files Created from 2007-07-27 to 2007-08-27 )))))))))))))))))))))))))))))))


2007-08-27 13:20 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-26 17:56 d——– C:\WINDOWS\system32\ActiveScan
2007-08-25 23:41 d——– C:\DOCUME~1\CODYSA~1\APPLIC~1\COMCASTTOOLBAR
2007-08-24 17:52 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-23 22:42 3,732 –a—— C:\WINDOWS\system32\tmp.reg
2007-08-23 22:41 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-08-23 22:41 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-08-23 22:41 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-08-16 15:08 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-08-15 12:07 d——– C:\Program Files\MSXML 4.0
2007-08-13 18:17 d——– C:\Program Files\Netscape
2007-08-13 18:17 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Netscape
2007-08-02 18:27 d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\Xdrive
2007-08-01 21:48 71,496 –a—— C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-08-01 21:48 37,480 –a—— C:\WINDOWS\system32\drivers\mfesmfk.sys
2007-08-01 21:48 34,184 –a—— C:\WINDOWS\system32\drivers\mfebopk.sys
2007-08-01 21:48 32,008 –a—— C:\WINDOWS\system32\drivers\mferkdk.sys
2007-08-01 21:48 170,408 –a—— C:\WINDOWS\system32\drivers\mfehidk.sys
2007-08-01 21:47 109,608 –a—— C:\WINDOWS\system32\drivers\Mpfp.sys
2007-08-01 21:44 d——– C:\Program Files\McAfee.com
2007-08-01 21:41 d——– C:\Program Files\Common Files\McAfee
2007-08-01 21:40 d——– C:\Program Files\McAfee
2007-08-01 15:24 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Visual Networks
2007-08-01 14:44 d——– C:\WINDOWS\speech
2007-08-01 14:43 d——– C:\WINDOWS\surfmonkey
2007-08-01 14:43 d——– C:\Program Files\Microsoft Agent
2007-08-01 14:42 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
2007-08-01 13:53 40,960 –a—— C:\AluriaCacheFile.dat
2007-08-01 13:41 d——– C:\Program Files\EarthLink TotalAccess
2007-07-31 12:41 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
2007-07-31 02:07 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\ComcastToolbar
2007-07-31 01:00 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-07-31 00:39 10,920 –a—— C:\aolconnfix.exe
2007-07-30 21:30 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-07-30 17:06 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\AOL
2007-07-30 17:03 d——– C:\Program Files\Common Files\Nullsoft
2007-07-30 16:57 33,588 -ra—— C:\WINDOWS\system32\drivers\wanatw4.sys
2007-07-30 16:53 d——– C:\Program Files\Common Files\aolshare
2007-07-30 16:53 d——– C:\Program Files\AOL 9.0
2007-07-30 16:46 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
2007-07-30 16:27 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Xdrive
2007-07-30 14:32 4,992 –a—— C:\WINDOWS\system32\drivers\loop.sys
2007-07-30 14:31 d——– C:\Program Files\Common Files\AOL
2007-07-30 14:31 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
2007-07-30 14:29 55,808 –a—— C:\WINDOWS\system32\zlib1.dll
2007-07-27 15:48 d——– C:\DOCUME~1\JAMESS~1\.SunDownloadManager


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-27 02:31 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Enigma Browser
2007-08-26 22:57 ——— d——– C:\Program Files\Windows Defender
2007-08-26 22:21 ——— d——– C:\Program Files\mail.com
2007-08-26 22:21 ——— d——– C:\Program Files\LexmarkX83
2007-08-26 22:08 ——— d——– C:\Program Files\Enigma Browser
2007-08-26 21:59 ——— d——– C:\Program Files\Bitcollider
2007-08-16 01:16 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-02 08:00 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\SlimBrowser
2007-08-01 14:55 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\EarthLink
2007-08-01 14:42 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-01 13:28 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\McAfee
2007-07-31 02:08 ——— d——– C:\Program Files\ComcastToolbar
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 –a—— C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-27 12:11 ——— d——– C:\Program Files\Google
2007-07-26 14:16 ——— d——– C:\Program Files\Secunia
2007-07-19 11:04 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Leadertech
2007-07-19 10:58 ——— d——– C:\Program Files\Maxthon
2007-07-18 12:11 38567 –a—— C:\WINDOWS\system32\pcpbios.exe
2007-07-14 21:00 7808 –a—— C:\WINDOWS\system32\drivers\psi_mf.sys
2007-07-09 22:03 ——— d——– C:\Program Files\Wintuneup Pro
2007-06-27 20:05 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\WinTuneup Data
2007-06-27 15:58 ——— d——– C:\Program Files\VideoProfessor
2007-06-27 14:52 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Shareaza
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe
2006-05-15 18:33 774144 –a—— C:\Program Files\RngInterstitial.dll
2001-08-18 12:00:00 94,784 –sh–w C:\WINDOWS\twain.dll
2004-08-04 07:56:46 50,688 –sh–w C:\WINDOWS\twain_32.dll
2004-08-04 07:56:42 1,028,096 –sh–w C:\WINDOWS\system32\mfc42.dll
2004-08-04 07:56:43 54,784 –sh–w C:\WINDOWS\system32\msvcirt.dll
2004-08-04 07:56:43 413,696 –sh–w C:\WINDOWS\system32\msvcp60.dll
2007-05-17 11:28:05 549,376 –sh–w C:\WINDOWS\system32\oleaut32.dll
2004-08-04 07:56:44 83,456 –sh–w C:\WINDOWS\system32\olepro32.dll
2004-08-04 07:56:55 11,776 –sh–w C:\WINDOWS\system32\regsvr32.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 00:41]
"tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [2007-03-07 10:58]
"Lexmark X83 Button Monitor"="C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe" [2001-10-18 11:25]
"Lexmark X83 Button Manager"="C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe" [2001-06-14 13:42]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2002-06-27 04:47]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"ActiveSpeed"="C:\Program Files\Ascentive\ActiveSpeed\AS.exe" [2007-01-30 19:00]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 15:19]
"nwiz"="nwiz.exe" [2003-07-28 15:19 C:\WINDOWS\system32\nwiz.exe]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"HostManager"="C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe" [2007-04-12 17:23]
"ELNKProxy"="C:\WINDOWS\surfmonkey\smproxy.exe" [2004-06-18 22:15]
"IPInSightMonitor 01"="C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe" [2005-08-10 21:10]
"IPInSightLAN 01"="C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" [2005-08-10 21:10]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mail.com"="C:\Program Files\mail.com\mcalert.exe" [2007-06-25 04:14]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
"XdriveTray"="C:\Program Files\Xdrive\Xdrive Desktop\xdrive.exe" /trayicon

C:\Documents and Settings\James Santos\Start Menu\Programs\Startup\
Secunia Personal Software Inspector (BETA).lnk - C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe [2007-07-23 15:26:34]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

R2 EarthLinkMonitor;EarthLink Monitor Service;"C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe"
R3 PSI;PSI;C:\WINDOWS\system32\DRIVERS\psi_mf.sys
S3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\system32\Drivers\BW2NDIS5.sys
S3 msloop;Microsoft Loopback Adapter Driver;C:\WINDOWS\system32\DRIVERS\loop.sys

*Newly Created Service* - AVG_ANTI-SPYWARE_DRIVER
*Newly Created Service* - AVG_ANTI-SPYWARE_GUARD

Contents of the 'Scheduled Tasks' folder
2007-08-27 16:22:43 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-27 13:51:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-27 13:55:56
C:\ComboFix-quarantined-files.txt … 2007-08-27 13:55
C:\ComboFix2.txt … 2007-08-26 17:39
C:\ComboFix3.txt … 2007-08-25 20:35

— E O F —

ComboFix 07-08-17.2 - "James Santos" 2007-08-27 13:42:09.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.34 [GMT -4:00]
Command switches used :: C:\Documents and Settings\James Santos\Desktop\CFScript
* Created a new restore point

FILE::
c:\windows\downloaded program files\f3initialsetup1.0.0.15-3.inf


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Free Offers from Freeze.com
C:\Program Files\Free Offers from Freeze.com61016_icon_frosty_games.ico
C:\Program Files\Free Offers from Freeze.com\101_Free_Songs.ico
C:\Program Files\Free Offers from Freeze.com\3737.url
C:\Program Files\Free Offers from Freeze.com\3763.url
C:\Program Files\Free Offers from Freeze.com\3764.url
C:\Program Files\Free Offers from Freeze.com\3767.url
C:\Program Files\Free Offers from Freeze.com\3778.url
C:\Program Files\Free Offers from Freeze.com\control.txt
C:\Program Files\Free Offers from Freeze.com\propel.ico
C:\Program Files\Free Offers from Freeze.com\Ringtones.ico
c:\windows\cdmxtras
c:\windows\downloaded program files\f3initialsetup1.0.0.15-3.inf


((((((((((((((((((((((((( Files Created from 2007-07-27 to 2007-08-27 )))))))))))))))))))))))))))))))


2007-08-27 13:20 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-26 17:56 d——– C:\WINDOWS\system32\ActiveScan
2007-08-25 23:41 d——– C:\DOCUME~1\CODYSA~1\APPLIC~1\COMCASTTOOLBAR
2007-08-24 17:52 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-23 22:42 3,732 –a—— C:\WINDOWS\system32\tmp.reg
2007-08-23 22:41 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-08-23 22:41 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-08-23 22:41 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-08-16 15:08 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-08-15 12:07 d——– C:\Program Files\MSXML 4.0
2007-08-13 18:17 d——– C:\Program Files\Netscape
2007-08-13 18:17 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Netscape
2007-08-02 18:27 d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\Xdrive
2007-08-01 21:48 71,496 –a—— C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-08-01 21:48 37,480 –a—— C:\WINDOWS\system32\drivers\mfesmfk.sys
2007-08-01 21:48 34,184 –a—— C:\WINDOWS\system32\drivers\mfebopk.sys
2007-08-01 21:48 32,008 –a—— C:\WINDOWS\system32\drivers\mferkdk.sys
2007-08-01 21:48 170,408 –a—— C:\WINDOWS\system32\drivers\mfehidk.sys
2007-08-01 21:47 109,608 –a—— C:\WINDOWS\system32\drivers\Mpfp.sys
2007-08-01 21:44 d——– C:\Program Files\McAfee.com
2007-08-01 21:41 d——– C:\Program Files\Common Files\McAfee
2007-08-01 21:40 d——– C:\Program Files\McAfee
2007-08-01 15:24 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Visual Networks
2007-08-01 14:44 d——– C:\WINDOWS\speech
2007-08-01 14:43 d——– C:\WINDOWS\surfmonkey
2007-08-01 14:43 d——– C:\Program Files\Microsoft Agent
2007-08-01 14:42 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
2007-08-01 13:53 40,960 –a—— C:\AluriaCacheFile.dat
2007-08-01 13:41 d——– C:\Program Files\EarthLink TotalAccess
2007-07-31 12:41 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
2007-07-31 02:07 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\ComcastToolbar
2007-07-31 01:00 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-07-31 00:39 10,920 –a—— C:\aolconnfix.exe
2007-07-30 21:30 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-07-30 17:06 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\AOL
2007-07-30 17:03 d——– C:\Program Files\Common Files\Nullsoft
2007-07-30 16:57 33,588 -ra—— C:\WINDOWS\system32\drivers\wanatw4.sys
2007-07-30 16:53 d——– C:\Program Files\Common Files\aolshare
2007-07-30 16:53 d——– C:\Program Files\AOL 9.0
2007-07-30 16:46 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
2007-07-30 16:27 d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Xdrive
2007-07-30 14:32 4,992 –a—— C:\WINDOWS\system32\drivers\loop.sys
2007-07-30 14:31 d——– C:\Program Files\Common Files\AOL
2007-07-30 14:31 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
2007-07-30 14:29 55,808 –a—— C:\WINDOWS\system32\zlib1.dll
2007-07-27 15:48 d——– C:\DOCUME~1\JAMESS~1\.SunDownloadManager


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-27 02:31 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Enigma Browser
2007-08-26 22:57 ——— d——– C:\Program Files\Windows Defender
2007-08-26 22:21 ——— d——– C:\Program Files\mail.com
2007-08-26 22:21 ——— d——– C:\Program Files\LexmarkX83
2007-08-26 22:08 ——— d——– C:\Program Files\Enigma Browser
2007-08-26 21:59 ——— d——– C:\Program Files\Bitcollider
2007-08-16 01:16 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-02 08:00 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\SlimBrowser
2007-08-01 14:55 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\EarthLink
2007-08-01 14:42 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-01 13:28 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\McAfee
2007-07-31 02:08 ——— d——– C:\Program Files\ComcastToolbar
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 –a—— C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-27 12:11 ——— d——– C:\Program Files\Google
2007-07-26 14:16 ——— d——– C:\Program Files\Secunia
2007-07-19 11:04 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Leadertech
2007-07-19 10:58 ——— d——– C:\Program Files\Maxthon
2007-07-18 12:11 38567 –a—— C:\WINDOWS\system32\pcpbios.exe
2007-07-14 21:00 7808 –a—— C:\WINDOWS\system32\drivers\psi_mf.sys
2007-07-09 22:03 ——— d——– C:\Program Files\Wintuneup Pro
2007-06-27 20:05 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\WinTuneup Data
2007-06-27 15:58 ——— d——– C:\Program Files\VideoProfessor
2007-06-27 14:52 ——— d——– C:\DOCUME~1\JAMESS~1\APPLIC~1\Shareaza
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe
2006-05-15 18:33 774144 –a—— C:\Program Files\RngInterstitial.dll
2001-08-18 12:00:00 94,784 –sh–w C:\WINDOWS\twain.dll
2004-08-04 07:56:46 50,688 –sh–w C:\WINDOWS\twain_32.dll
2004-08-04 07:56:42 1,028,096 –sh–w C:\WINDOWS\system32\mfc42.dll
2004-08-04 07:56:43 54,784 –sh–w C:\WINDOWS\system32\msvcirt.dll
2004-08-04 07:56:43 413,696 –sh–w C:\WINDOWS\system32\msvcp60.dll
2007-05-17 11:28:05 549,376 –sh–w C:\WINDOWS\system32\oleaut32.dll
2004-08-04 07:56:44 83,456 –sh–w C:\WINDOWS\system32\olepro32.dll
2004-08-04 07:56:55 11,776 –sh–w C:\WINDOWS\system32\regsvr32.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 00:41]
"tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [2007-03-07 10:58]
"Lexmark X83 Button Monitor"="C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe" [2001-10-18 11:25]
"Lexmark X83 Button Manager"="C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe" [2001-06-14 13:42]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2002-06-27 04:47]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"ActiveSpeed"="C:\Program Files\Ascentive\ActiveSpeed\AS.exe" [2007-01-30 19:00]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 15:19]
"nwiz"="nwiz.exe" [2003-07-28 15:19 C:\WINDOWS\system32\nwiz.exe]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"HostManager"="C:\Program Files\Common Files\AOL\1185820277\ee\AOLSoftware.exe" [2007-04-12 17:23]
"ELNKProxy"="C:\WINDOWS\surfmonkey\smproxy.exe" [2004-06-18 22:15]
"IPInSightMonitor 01"="C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe" [2005-08-10 21:10]
"IPInSightLAN 01"="C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" [2005-08-10 21:10]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mail.com"="C:\Program Files\mail.com\mcalert.exe" [2007-06-25 04:14]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
"XdriveTray"="C:\Program Files\Xdrive\Xdrive Desktop\xdrive.exe" /trayicon

C:\Documents and Settings\James Santos\Start Menu\Programs\Startup\
Secunia Personal Software Inspector (BETA).lnk - C:\Program Files\Secunia\Personal Software Inspector (BETA)\PSI.exe [2007-07-23 15:26:34]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

R2 EarthLinkMonitor;EarthLink Monitor Service;"C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe"
R3 PSI;PSI;C:\WINDOWS\system32\DRIVERS\psi_mf.sys
S3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\system32\Drivers\BW2NDIS5.sys
S3 msloop;Microsoft Loopback Adapter Driver;C:\WINDOWS\system32\DRIVERS\loop.sys

*Newly Created Service* - AVG_ANTI-SPYWARE_DRIVER
*Newly Created Service* - AVG_ANTI-SPYWARE_GUARD

Contents of the 'Scheduled Tasks' folder
2007-08-27 16:22:43 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-27 13:51:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-27 13:55:56
C:\ComboFix-quarantined-files.txt … 2007-08-27 13:55
C:\ComboFix2.txt … 2007-08-26 17:39
C:\ComboFix3.txt … 2007-08-25 20:35

— E O F —
Um, the Combo log is there (twice), so do you mean the AVG Report? You posted the Panda report again.

The AVG report will be found here.

C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI