This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware Won't Delete

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'VE BEEN AT IT FOR A FEW DAYS NOW AND IT SEEMS LIKE THE MALWARE WILL NOT REPAIR. AS SOON AS MY ANTIVIRUS FINDS IT, IT CRASHES AND RESETS THE COMPUTER. SO IVE FOLLOWED THE INSTRUCTIONS FROM A PREVIOUS TOPIC OF THE SORT AND HOPEFULLY SOMEONE COULD HELP ME. IVE ALREADY TAKEN OUT "VIEWPOINT" HERE'S WHAT'S LEFT.

MY HIJACK:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:55:49 AM, on 9/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\windows\regedit.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.sony.com/vaiopeople
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [qiqbapm] c:\windows\system32\qiqbapm.exe qiqbapm
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Malware Sweeper] C:\Program Files\MalwareSweeper.com\MalwareSweeper\MalSwep.exe
O4 - HKUS\S-1-5-18\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebpr…etup1.0.0.8.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab30149.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/popc…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DA4555A7-7D86-4FF5-8C7F-E061A2801E06}: NameServer = 137.49.1.100,137.49.1.150
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\umkawwem.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe

–
End of file - 5676 bytes




MY ACTIVE SCAN:

Incident Status Location

Spyware:Spyware/Virtumonde Not disinfected C:\windows\system32\ljjgecb.dll
Spyware:Spyware/Virtumonde Not disinfected C:\windows\system32\awtqqnm.dll
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\jkkji.dll
Virus:bck/haxdoor.gen Disinfected Operating system
Potentially unwanted tool:application/funweb Not disinfected c:\windows\downloaded program files\f3initialsetup1.0.0.8-2.inf
Dialer:dialer.b Not disinfected c:\windows\tmlpcert2005
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\BESAVWEN.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\REAGUDFS.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\QDPCLAEL.DLL
Virus:Trj/Downloader.PCQ Disinfected C:\WINDOWS\SYSTEM32\WYQNVSBU.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\DAWSGTWY.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\ICXBQKOX.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\BIHCMTGV.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\WXAVWUMO.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\CQCXCTIB.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\XFCVMRYI.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\OGPAPMFU.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\DMSQLTDT.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\IPCIEOBQ.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\BVQXVGNO.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\AQJOUMLC.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\BQCIMWAN.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\NDGMASHU.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\OLPMKNQD.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\QRFHCMFL.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\UNNEHBND.DLL
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\VCILPXNV.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\TVATMWKH.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\DHIAVIYO.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\VRFOKSJN.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\WDLAKMJD.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\GJXJAOGA.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\QJPDXUNB.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\VUSQANVN.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\ECXIVFPV.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\PIGJOOIL.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\EHCJHCXQ.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\VUSRVYHT.DLL
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\IOUNESSO.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\VVQRHOHV.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\QHFWOTOH.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\AGGTVXKY.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\IDWUASUH.DLL
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\AQBILUGM.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\VJJCYKTB.DLL
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\NRSUGBKM.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\GFDAEVJL.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\BWLWUDHJ.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\QYKUSXWK.DLL
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\AXVJBDHW.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\FFBKUBJR.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\PQQORFHM.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\EFJECUML.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\UFILBIKN.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\ATTUKMWJ.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\RBXXQLDN.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\CSGARYVF.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\GXOCNSCB.DLL
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\IDHECEKQ.EXE
Virus:Trj/GetPasswords.G Disinfected C:\WINDOWS\SYSTEM32\SERVICE\EXPLORER.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\ENJEASIE.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\LURVJEWJ.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\LGUAHTEC.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\PWIFUTYD.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\JNBOQCEE.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\HYASUHCC.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\FKASKQRO.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\XQIQMBKN.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\RVPXYHQB.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\UMOKXGAM.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\JSCTFNJA.DLL
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\KJIXYTQH.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\BRDXJGMY.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\KSKXLSUE.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\YVPCNLBU.DLL
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\DRAUAWJS.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\LNDCBTHS.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\BUMWYULV.DLL
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\UHUVOVBL.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\IWLXDQRH.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\BWTUSIRP.DLL
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\RFXCJPBW.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\NEREDFON.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\OLCNMCAH.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\UOCWHJWQ.DLL
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\PKXRVUMH.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\TOUDTBPF.DLL
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\XJTLFPSF.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\FEPVELGT.DLL
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\WSKGWMPB.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\NKJQEBTK.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\UIQYYULX.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\JOIHLWYQ.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\GVCACYAW.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\IBQDBJTB.DLL
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\XWRBYCYW.EXE
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\YCKBVGYE.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\BGXKRYEE.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\RQRSSPP.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\BVSTNHWT.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\UPFRRFMR.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\JKLOEMRV.DLL
Adware:Adware/eZula Not disinfected C:\WINDOWS\SYSTEM32\SGEFGGCR.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\VBYJBAPW.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\FIGNMGXK.DLL
Virus:W32/ZLFake.A.drp Disinfected C:\WINDOWS\Temp\SVCIPA.EXE
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\NirCmd.exe
Adware:Adware/CWS.GoogleError Not disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\temp.fr35D2
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\Cookies\mr[4].txt
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\Cookies\mr[8].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\Cookies\mr[35].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\Cookies\mr. miller@winantivirus[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\Cookies\mr[18].txt
Spyware:Cookie/Lop Not disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\Cookies\mr. miller@mp3search[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\Cookies\mr. miller@go[2].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\Cookies\mr. miller@target[2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\Cookies\mr. [removed][1].txt
Virus:Bck/Haxdoor.NH Disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\temp.frA2B7
Virus:Trj/Downloader.OWJ Disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\SVCHST.EXE
Virus:Trj/Downloader.MDW Disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\XRUN.EXE
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\jar_cache10814.tmp[NewSecurityClassLoader.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\jar_cache10814.tmp[NewURLClassLoader.class]
Potentially unwanted tool:Application/WinFixer2006 Not disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\WINFIX.CHM[/SystemDoctor2006FreeInstall.cab][USDR6_0001_D08M0404NetInstaller.exe]
Adware:Adware/Yazzle Not disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\YazzleBundle-1281.exe
Virus:Trj/Downloader.OBC Disinfected C:\Documents and Settings\Mr. Miller\Local Settings\Temp\wr-1-2000219.exe
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Mr. Miller\Application Data\Sun\Java\Deployment\CACHE\6.0\1\347841c1-4dc97492[NewSecurityClassLoader.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Mr. Miller\Application Data\Sun\Java\Deployment\CACHE\6.0\1\347841c1-4dc97492[NewURLClassLoader.class]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@2o7[1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@atwola[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Administrator\Cookies\[removed][1].txt
Adware:Adware/NavHelper Not disinfected C:\Program Files\WAV to MP3 Encoder\NH20040517.4a.EE.exe
Adware:Adware/ClockSync Not disinfected C:\Program Files\WAV to MP3 Encoder\VVSNInst.exe
Hacktool:Exploit/WinampPLS Not disinfected C:\FOUND.011\FILE0000.CHK
Hacktool:Exploit/WinampPLS Not disinfected C:\FOUND.026\FILE0000.CHK
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\ComboFix\NIRCMD.EXE
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\ComboFix\NirCmd.cfexe

ANY HELP WOULD BE APPRECIATED. THANKS
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


You need to run the following in Normal Mode.

Download and Run ComboFix
  • Download this file from below:

    Here
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
ComboFix 07-09-18.4 - "Mr. Miller" 2007-09-19 10:30:13.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.233 [GMT -4:00]
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\windows\cookies.ini
C:\WINDOWS\DOWNLO~1.\nethv32.inf
C:\windows\system32\aggtvxky.dll
C:\windows\system32\aqbilugm.exe
C:\windows\system32\aqjoumlc.dll
C:\windows\system32\attukmwj.dll
C:\windows\system32\awtqqnm.dll
C:\WINDOWS\system32\bcsncoxg.ini
C:\windows\system32\besavwen.exe
C:\windows\system32\bgxkryee.dll
C:\windows\system32\bihcmtgv.dll
C:\windows\system32\bqcimwan.dll
C:\windows\system32\brdxjgmy.exe
C:\WINDOWS\system32\btkycjjv.ini
C:\windows\system32\bumwyulv.dll
C:\windows\system32\bvqxvgno.dll
C:\windows\system32\bvstnhwt.dll
C:\windows\system32\bwlwudhj.dll
C:\windows\system32\bwtusirp.dll
C:\windows\system32\cqcxctib.dll
C:\windows\system32\csgaryvf.dll
C:\windows\system32\dawsgtwy.exe
C:\windows\system32\dhiaviyo.dll
C:\windows\system32\dmsqltdt.dll
C:\windows\system32\drauawjs.exe
C:\windows\system32\ecxivfpv.dll
C:\windows\system32\efjecuml.dll
C:\windows\system32\ehcjhcxq.dll
C:\windows\system32\enjeasie.exe
C:\windows\system32\fepvelgt.dll
C:\windows\system32\ffbkubjr.exe
C:\windows\system32\fignmgxk.dll
C:\windows\system32\fkaskqro.dll
C:\windows\system32\gfdaevjl.exe
C:\windows\system32\gjxjaoga.dll
C:\windows\system32\gvcacyaw.dll
C:\windows\system32\gxocnscb.dll
C:\WINDOWS\system32\hotowfhq.ini
C:\windows\system32\hyasuhcc.dll
C:\windows\system32\ibqdbjtb.dll
C:\windows\system32\icxbqkox.dll
C:\windows\system32\idhecekq.exe
C:\windows\system32\idwuasuh.dll
C:\WINDOWS\system32\ijkkj.bak1
C:\WINDOWS\system32\ijkkj.bak2
C:\WINDOWS\system32\ijkkj.ini
C:\WINDOWS\system32\ijkkj.ini2
C:\WINDOWS\system32\ijkkj.tmp
C:\windows\system32\iounesso.exe
C:\windows\system32\ipcieobq.dll
C:\windows\system32\iwlxdqrh.dll
C:\windows\system32\jkkji.dll
C:\windows\system32\jkloemrv.dll
C:\windows\system32\jnboqcee.dll
C:\windows\system32\joihlwyq.exe
C:\windows\system32\jsctfnja.dll
C:\windows\system32\kjixytqh.exe
C:\windows\system32\kskxlsue.dll
C:\WINDOWS\system32\kxgmngif.ini
C:\WINDOWS\system32\lealcpdq.ini
C:\windows\system32\lguahtec.exe
C:\windows\system32\lndcbths.exe
C:\windows\system32\lurvjewj.exe
C:\windows\system32\ndgmashu.dll
C:\WINDOWS\system32\ndlqxxbr.ini
C:\windows\system32\neredfon.exe
C:\WINDOWS\system32\njskofrv.ini
C:\windows\system32\nkjqebtk.exe
C:\windows\system32\nrsugbkm.exe
C:\windows\system32\ogpapmfu.dll
C:\windows\system32\olcnmcah.dll
C:\windows\system32\olpmknqd.dll
C:\windows\system32\pigjooil.dll
C:\windows\system32\pkxrvumh.exe
C:\windows\system32\pqqorfhm.exe
C:\windows\system32\pwifutyd.dll
C:\windows\system32\qdpclael.dll
C:\windows\system32\qhfwotoh.dll
C:\windows\system32\qiqbapm.dat
C:\windows\system32\qiqbapm.exe
C:\windows\system32\qiqbapm_nav.dat
C:\windows\system32\qiqbapm_navps.dat
C:\windows\system32\qjpdxunb.dll
C:\windows\system32\qrfhcmfl.dll
C:\windows\system32\qykusxwk.dll
C:\windows\system32\rbxxqldn.dll
C:\windows\system32\reagudfs.dll
C:\windows\system32\rfxcjpbw.exe
C:\windows\system32\sgefggcr.exe
C:\windows\system32\toudtbpf.dll
C:\windows\system32\tvatmwkh.dll
C:\WINDOWS\system32\ublncpvy.ini
C:\windows\system32\ufilbikn.dll
C:\windows\system32\uhuvovbl.exe
C:\windows\system32\uiqyyulx.exe
C:\windows\system32\umokxgam.exe
C:\windows\system32\unnehbnd.dll
C:\windows\system32\uocwhjwq.dll
C:\windows\system32\vbyjbapw.dll
C:\windows\system32\vcilpxnv.exe
C:\windows\system32\vjjcyktb.dll
C:\windows\system32\vrfoksjn.dll
C:\windows\system32\vusqanvn.dll
C:\windows\system32\vusrvyht.dll
C:\windows\system32\vvqrhohv.exe
C:\WINDOWS\system32\waycacvg.ini
C:\windows\system32\wdlakmjd.dll
C:\windows\system32\wskgwmpb.exe
C:\windows\system32\wxavwumo.dll
C:\windows\system32\xfcvmryi.dll
C:\windows\system32\xjtlfpsf.exe
C:\windows\system32\xqiqmbkn.dll
C:\windows\system32\xwrbycyw.exe
C:\windows\system32\yckbvgye.exe
C:\windows\system32\yvpcnlbu.dll
C:\windows\tmlpcert2005
C:\xcrashdump.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_DOMAINSERVICE
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-08-19 to 2007-09-19 )))))))))))))))))))))))))))))))
.

2007-09-18 11:02 384 –a—— C:\WINDOWS\system32\DVCStateBkp-{00000002-00000000-00000009-00001102-00000004-40011102}.dat
2007-09-18 11:02 384 –a—— C:\WINDOWS\system32\DVCState-{00000002-00000000-00000009-00001102-00000004-40011102}.dat
2007-09-18 10:26 217,088 –a—— C:\WINDOWS\Rewire.dll
2007-09-18 10:21 914,320 –a—— C:\WINDOWS\system32\drivers\ha10kx2k.sys
2007-09-18 10:21 298,971 –a—— C:\WINDOWS\system32\ctstatic.dat
2007-09-18 10:21 20,480 –a—— C:\WINDOWS\INRES.DLL
2007-09-18 10:21 148,368 –a—— C:\WINDOWS\system32\drivers\haP16v2k.sys
2007-09-18 10:21 147,088 –a—— C:\WINDOWS\system32\drivers\emupia2k.sys
2007-09-18 10:21 130,384 –a—— C:\WINDOWS\system32\drivers\ctsfm2k.sys
2007-09-18 08:06 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-18 07:03 d——– C:\WINDOWS\system32\ActiveScan
2007-09-18 01:47 512,688 –a—— C:\WINDOWS\system32\XceedCry.dll
2007-09-18 01:47 423,784 –a—— C:\WINDOWS\system32\XceedBkp.dll
2007-09-18 01:47 101,888 –a—— C:\WINDOWS\system32\VB6STKIT.DLL
2007-09-18 01:47 10,752 –a—— C:\WINDOWS\system32\md5.dll
2007-09-18 01:47 d——– C:\Program Files\MalwareSweeper.com
2007-09-18 01:40 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-17 23:54 d–hs—- C:\FOUND.059
2007-09-14 22:35 d–hs—- C:\FOUND.058
2007-09-14 22:06 d——– C:\WINDOWS\pss
2007-09-14 10:56 d–hs—- C:\FOUND.057
2007-09-14 09:47 d–hs—- C:\FOUND.056
2007-09-11 11:36 d——– C:\Program Files\AAS
2007-09-09 23:35 d——– C:\WINDOWS\ASTULogTemp
2007-09-08 17:45 d——– C:\Program Files\Cakewalk
2007-09-08 17:45 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cakewalk
2007-09-08 16:01 17,408 ——— C:\WINDOWS\system32\minimp3.exe
2007-09-08 15:56 d——– C:\Program Files\Common Files\Native Instruments
2007-09-08 14:47 d–hs—- C:\FOUND.055
2007-09-06 16:03 d–hs—- C:\FOUND.054
2007-08-31 12:01 d——– C:\Program Files\Common Files\Intellisync
2007-08-30 01:07 d–hs—- C:\FOUND.053
2007-08-23 14:41 d–hs—- C:\FOUND.052

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-08-16 11:01 287766 –a—— C:\windows\system32\rqrsspp.dll
2007-08-16 11:01 287766 –a—— C:\windows\system32\ljjgecb.dll
2007-08-16 11:00 304161 ——— C:\windows\system32\upfrrfmr.exe
2007-08-16 11:00 304161 ——— C:\windows\system32\rvpxyhqb.exe
2007-08-13 17:21 49936 –a—— C:\windows\system32\compress.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
2007-08-16 11:01 287766 –a—— C:\windows\system32\ljjgecb.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83B91FB3-9CA4-4B6B-873D-9691578353E3}]
C:\WINDOWS\system32\hskeevjr.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" []
"H2O"="C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe" [2005-11-01 00:00]
"ZTgServerSwitch"="c:\program files\support.com\client\lserver\server.vbs" [2001-09-10 19:36]
"WebTrapNT.exe"="C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe" [2001-09-06 09:20]
"Pop3trap.exe"="C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe" [2001-09-06 09:25]
"CTHelper"="CTHELPER.EXE" [2004-02-02 22:30 C:\WINDOWS\system32\CTHELPER.EXE]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 22:36]
"SetDefaultMIDI"="MIDIDef.exe" [2003-06-20 06:13 C:\WINDOWS\MIDIDEF.EXE]
"Malware Sweeper"="C:\Program Files\MalwareSweeper.com\MalwareSweeper\MalSwep.exe" [2006-12-26 09:41]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Yahoo! Pager"=C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
"AIM"=C:\Program Files\AIM95\aim.exe -cnetwait.odl

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"= C:\windows\system32\ljjgecb.dll [2007-08-16 11:01 287766]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjgecb]
ljjgecb.dll 2007-08-16 11:01 287766 C:\WINDOWS\system32\ljjgecb.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xcttgs]
xcttgs.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c009343E]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\xcttgm.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\xcttgs.sys]
@="Driver"

R1 SonyFanC;FAN Control Device Service;C:\windows\system32\Drivers\SonyFanC.sys
R1 xcttgm;STK Bi 001;\??\C:\WINDOWS\system32\xcttgm.sys
R2 V7;V7;C:\windows\system32\drivers\V7.sys
R3 CLEDX;Team H2O CLEDX service;C:\windows\system32\DRIVERS\cledx.sys
R3 USBKT1X1;M-Audio USB Keystation;C:\windows\system32\drivers\usbkt1x1.sys
S2 xcttgs;STK Bi 002;\??\C:\WINDOWS\system32\xcttgm.sys
S3 BCM42XX;Broadcom iLine10™ Network Adapter Driver;C:\windows\system32\DRIVERS\bcm42xx5.sys
S3 BCMModem;BCM V.90 56K Modem;C:\windows\system32\DRIVERS\BCMDM.sys
S3 sonypvs1;Sony Digital Imaging Video2;C:\windows\system32\DRIVERS\sonypvs1.sys
S3 tbhsd;Tunebite High-Speed Dubbing;C:\windows\system32\drivers\tbhsd.sys
S3 UKS11LDR;M-Audio USB Keystation Loader;C:\windows\system32\drivers\uks11ldr.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-09-19 05:00:00 C:\windows\Tasks\At2.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 06:00:00 C:\windows\Tasks\At3.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 07:00:02 C:\windows\Tasks\At4.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 08:00:00 C:\windows\Tasks\At5.job"
"2007-09-19 09:00:00 C:\windows\Tasks\At6.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 10:00:00 C:\windows\Tasks\At7.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 11:00:00 C:\windows\Tasks\At8.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 12:00:00 C:\windows\Tasks\At9.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 13:00:02 C:\windows\Tasks\At10.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 14:00:02 C:\windows\Tasks\At11.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-18 15:00:02 C:\windows\Tasks\At12.job"
"2007-09-18 16:00:02 C:\windows\Tasks\At13.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-18 17:00:02 C:\windows\Tasks\At14.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-18 18:00:02 C:\windows\Tasks\At15.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-18 19:00:02 C:\windows\Tasks\At16.job"
"2007-09-18 20:00:02 C:\windows\Tasks\At17.job"
"2007-09-18 21:00:02 C:\windows\Tasks\At18.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-18 22:00:02 C:\windows\Tasks\At19.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-18 23:00:02 C:\windows\Tasks\At20.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 00:00:02 C:\windows\Tasks\At21.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 01:00:02 C:\windows\Tasks\At22.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 02:00:02 C:\windows\Tasks\At23.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 03:00:02 C:\windows\Tasks\At24.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 04:00:02 C:\windows\Tasks\At25.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 05:00:02 C:\windows\Tasks\At26.job"
"2007-09-19 06:00:02 C:\windows\Tasks\At27.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 07:00:02 C:\windows\Tasks\At28.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 08:00:02 C:\windows\Tasks\At29.job"
"2007-09-19 09:00:02 C:\windows\Tasks\At30.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 10:00:02 C:\windows\Tasks\At31.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 11:00:02 C:\windows\Tasks\At32.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 12:00:02 C:\windows\Tasks\At33.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 13:00:02 C:\windows\Tasks\At34.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 14:00:02 C:\windows\Tasks\At35.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-18 15:00:02 C:\windows\Tasks\At36.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-18 16:00:02 C:\windows\Tasks\At37.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-18 17:00:02 C:\windows\Tasks\At38.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-18 18:00:02 C:\windows\Tasks\At39.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-18 19:00:02 C:\windows\Tasks\At40.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-18 20:00:02 C:\windows\Tasks\At41.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-18 21:00:02 C:\windows\Tasks\At42.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-18 22:00:02 C:\windows\Tasks\At43.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-18 23:00:02 C:\windows\Tasks\At44.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 00:00:02 C:\windows\Tasks\At45.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 01:00:02 C:\windows\Tasks\At46.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 02:00:02 C:\windows\Tasks\At47.job"
"2007-09-19 03:00:02 C:\windows\Tasks\At48.job"
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-19 10:40:26
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-19 10:43:54 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-19 10:43
.
— E O F —


HIJACK LOG:

StartupList report, 9/19/2007, 10:55:40 AM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\windows\System32\nvsvc32.exe
C:\windows\Explorer.EXE
C:\windows\System32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\windows\system32\wscntfy.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe
C:\windows\system32\CTHELPER.EXE
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\windows\system32\notepad.exe
C:\windows\system32\rundll32.exe
C:\Program Files\Avant Browser\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\windows\system32\NOTEPAD.EXE
C:\windows\system32\NOTEPAD.EXE

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\windows\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

NvCplDaemon = RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
H2O = C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
ZTgServerSwitch = c:\program files\support.com\client\lserver\server.vbs
WebTrapNT.exe = "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
Pop3trap.exe = "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
CTHelper = CTHELPER.EXE

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

H/PC Connection Agent = "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
SetDefaultMIDI = MIDIDef.exe
Malware Sweeper = C:\Program Files\MalwareSweeper.com\MalwareSweeper\MalSwep.exe /STARTUP
HijackThis startup scan = C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan

————————————————–

Shell & screensaver key from C:\windows\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Task Scheduler jobs:

At2.job
At3.job
At4.job
At5.job
At6.job
At7.job
At8.job
At9.job
At10.job
At11.job
At12.job
At13.job
At14.job
At15.job
At16.job
At17.job
At18.job
At19.job
At20.job
At21.job
At22.job
At23.job
At24.job
At25.job
At26.job
At27.job
At28.job
At29.job
At30.job
At31.job
At32.job
At33.job
At34.job
At35.job
At36.job
At37.job
At38.job
At39.job
At40.job
At41.job
At42.job
At43.job
At44.job
At45.job
At46.job
At47.job
At48.job

————————————————–

Enumerating Download Program Files:

[Checkers Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\msgrchkr.dll
CODEBASE = http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab

[QuickTime Object]
InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

[{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}]
CODEBASE = http://imgfarm.com/images/nocache/funwebpr…etup1.0.0.8.cab

[Facebook Photo Uploader Control]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\FacebookPhotoUploader.ocx
CODEBASE = http://upload.facebook.com/controls/Facebo…otoUploader.cab

[HouseCall Control]
CODEBASE = http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab

[Yahoo! Webcam Upload Wrapper]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\yuplapp.dll
CODEBASE = http://chat.yahoo.com/cab/yuplapp.cab

[MessengerStatsClient Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll
CODEBASE = http://messenger.zone.msn.com/binary/Messe…nt.cab30149.cab

[WordMojo Control]
CODEBASE = http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab

[ActiveScan Installer Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\asinst.dll
CODEBASE = http://acs.pandasoftware.com/activescan/as5free/asinst.cab

[{9F1C11AA-197B-4942-BA54-47A8489BB47F}]
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/…8215.4196527778

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa…ash/swflash.cab

[{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}]
CODEBASE = http://download.games.yahoo.com/games/popc…aploader_v6.cab

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\windows\system32\SHELL32.dll
CDBurn: C:\windows\system32\SHELL32.dll
WebCheck: C:\windows\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

1 = C:\windows\system32\service\explorer.exe

————————————————–

End of report, 6,739 bytes
Report generated in 0.047 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Hi

That's not the HijackThis log I was looking for. It's the one you get when you click on "Scan and save a logfile" like your first one.

Follow these instructions in the order I give, and pay close attention to the second part of the AVG instructions, to ensure a report is generated.


You have no anti-virus on your computer. It is important you install one now before we continue with your fix. Check this out for a list of free AV scanners, AVG is highly recommended

Download AVG Anti-Spyware.
  • Install AVG Anti-Spyware.
  • Launch AVG by double-clicking on the icon.
  • The program will now open to the main screen.
  • You will need to update AVG to the latest definition files.
  • At the top of the main screen click Update.
  • Then in the Manual Update section, click on Start Update.
[*]The update will start and a progress bar will show the updates being installed.

[*]When updates are completed, close AVG.

If you are having problems with the updater, you can use this link to manually update AVG.
AVG manual updates

Run a scan with AVG.
  • Click on Scanner
    • Click on the Settings tab, and set the following settings.
      • How to act
      • Click on Recommended actions, and set to Quarantine.
    • How to scan
      • Check all options.
    • Possibly unwanted software.
      • Check all options.
    • Reports
      • Check Do not automatically generate reports after every scan.
    • What to scan
      • Check Scan every file.
  • Click on the Scan tab.
    • Click on Complete System Scan and the scan will begin.
    • When the scan has finished
    • Make sure that Set all elements to: shows Quarantine, if not click on the link and choose Quarantine from the popup menu.
    • At the bottom of the window click on the Apply all Actions button.
Note: Don't save the report before you hit the Apply action button.

Close AVG Anti-Spyware.

AVG will save a report in the following location C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.

Post back with
  • AVG report
  • new Combofix log
  • new HijackThis log.
AVG LOG:

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 7:06:55 PM 9/19/2007

+ Scan result:



C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0379008.SRG -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378846.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378847.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378863.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0376589.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378628.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1294\A0379344.DLL -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\qoobox\Quarantine\C\WINDOWS\system32\awtqqnm.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0379027.DLL -> Backdoor.Haxdoor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0379028.SYS -> Backdoor.Haxdoor.dw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0379010.EXE -> Backdoor.Haxdoor.ky : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378793.exe -> Backdoor.VB.kb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378776.exe -> Downloader.Adload.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378843.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0379029.EXE -> Downloader.Tiny.id : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378864.exe -> Hijacker.Small.mw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378865.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@pandasoftware.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Mr. Miller\Cookies\mr. miller@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Mr. Miller\Cookies\mr. miller@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Mr. Miller\Cookies\mr. miller@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Mr. Miller\Cookies\mr. miller@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Mr. Miller\Cookies\mr. [removed][1].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Mr. Miller\Cookies\mr. [removed][2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Mr. Miller\Cookies\mr. miller@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Mr. Miller\Cookies\mr. miller@revsci[2].txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\Mr. Miller\Cookies\mr. [removed][1].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\Mr. Miller\Cookies\mr. [removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Mr. Miller\Cookies\mr. miller@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378805.exe -> Trojan.Agent.anr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378806.exe -> Trojan.Agent.anr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378807.exe -> Trojan.Agent.anr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378808.exe -> Trojan.Agent.anr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378809.exe -> Trojan.Agent.anr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378810.exe -> Trojan.Agent.anr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378811.exe -> Trojan.Agent.anr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378881.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378882.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378883.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378884.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378885.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378886.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378887.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378888.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378889.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378890.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378891.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378892.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378893.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378894.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378895.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378896.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378897.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378898.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378899.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378900.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378901.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378902.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378903.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378904.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378905.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378906.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP1292\A0378907.exe -> Trojan.Agent.aoy : Cleaned with backup (quarantined).


::Report end



COMBOFIX LOG:

ComboFix 07-09-19.8 - "Mr. Miller" 2007-09-19 19:13:05.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.284 [GMT -4:00]
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\windows\system32\jkkll.dll
C:\WINDOWS\system32\llkkj.bak1
C:\WINDOWS\system32\llkkj.ini
C:\WINDOWS\system32\llkkj.tmp

.
((((((((((((((((((((((((( Files Created from 2007-08-19 to 2007-09-19 )))))))))))))))))))))))))))))))
.

2007-09-19 16:00 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-09-18 11:02 384 –a—— C:\WINDOWS\system32\DVCStateBkp-{00000002-00000000-00000009-00001102-00000004-40011102}.dat
2007-09-18 11:02 384 –a—— C:\WINDOWS\system32\DVCState-{00000002-00000000-00000009-00001102-00000004-40011102}.dat
2007-09-18 10:26 217,088 –a—— C:\WINDOWS\Rewire.dll
2007-09-18 10:21 914,320 –a—— C:\WINDOWS\system32\drivers\ha10kx2k.sys
2007-09-18 10:21 298,971 –a—— C:\WINDOWS\system32\ctstatic.dat
2007-09-18 10:21 20,480 –a—— C:\WINDOWS\INRES.DLL
2007-09-18 10:21 148,368 –a—— C:\WINDOWS\system32\drivers\haP16v2k.sys
2007-09-18 10:21 147,088 –a—— C:\WINDOWS\system32\drivers\emupia2k.sys
2007-09-18 10:21 130,384 –a—— C:\WINDOWS\system32\drivers\ctsfm2k.sys
2007-09-18 08:06 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-18 07:03 d——– C:\WINDOWS\system32\ActiveScan
2007-09-18 01:47 512,688 –a—— C:\WINDOWS\system32\XceedCry.dll
2007-09-18 01:47 423,784 –a—— C:\WINDOWS\system32\XceedBkp.dll
2007-09-18 01:47 101,888 –a—— C:\WINDOWS\system32\VB6STKIT.DLL
2007-09-18 01:47 10,752 –a—— C:\WINDOWS\system32\md5.dll
2007-09-18 01:47 d——– C:\Program Files\MalwareSweeper.com
2007-09-18 01:40 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-17 23:54 d–hs—- C:\FOUND.059
2007-09-14 22:35 d–hs—- C:\FOUND.058
2007-09-14 22:06 d——– C:\WINDOWS\pss
2007-09-14 10:56 d–hs—- C:\FOUND.057
2007-09-14 09:47 d–hs—- C:\FOUND.056
2007-09-11 11:36 d——– C:\Program Files\AAS
2007-09-09 23:35 d——– C:\WINDOWS\ASTULogTemp
2007-09-08 17:45 d——– C:\Program Files\Cakewalk
2007-09-08 17:45 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cakewalk
2007-09-08 16:01 17,408 ——— C:\WINDOWS\system32\minimp3.exe
2007-09-08 15:56 d——– C:\Program Files\Common Files\Native Instruments
2007-09-08 14:47 d–hs—- C:\FOUND.055
2007-09-06 16:03 d–hs—- C:\FOUND.054
2007-08-31 12:01 d——– C:\Program Files\Common Files\Intellisync
2007-08-30 01:07 d–hs—- C:\FOUND.053
2007-08-23 14:41 d–hs—- C:\FOUND.052

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-08-16 11:01 287766 –a—— C:\windows\system32\rqrsspp.dll
2007-08-16 11:01 287766 –a—— C:\windows\system32\ljjgecb.dll
2007-08-16 11:00 304161 ——— C:\windows\system32\upfrrfmr.exe
2007-08-16 11:00 304161 ——— C:\windows\system32\rvpxyhqb.exe
2007-08-13 17:21 49936 –a—— C:\windows\system32\compress.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
2007-08-16 11:01 287766 –a—— C:\windows\system32\ljjgecb.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83B91FB3-9CA4-4B6B-873D-9691578353E3}]
C:\WINDOWS\system32\hskeevjr.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" []
"H2O"="C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe" [2005-11-01 00:00]
"ZTgServerSwitch"="c:\program files\support.com\client\lserver\server.vbs" [2001-09-10 19:36]
"WebTrapNT.exe"="C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe" [2001-09-06 09:20]
"Pop3trap.exe"="C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe" [2001-09-06 09:25]
"CTHelper"="CTHELPER.EXE" [2004-02-02 22:30 C:\WINDOWS\system32\CTHELPER.EXE]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 22:36]
"SetDefaultMIDI"="MIDIDef.exe" [2003-06-20 06:13 C:\WINDOWS\MIDIDEF.EXE]
"Malware Sweeper"="C:\Program Files\MalwareSweeper.com\MalwareSweeper\MalSwep.exe" [2006-12-26 09:41]
"HijackThis startup scan"="C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" [2007-09-18 06:55]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Yahoo! Pager"=C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
"AIM"=C:\Program Files\AIM95\aim.exe -cnetwait.odl

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"= C:\windows\system32\ljjgecb.dll [2007-08-16 11:01 287766]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjgecb]
ljjgecb.dll 2007-08-16 11:01 287766 C:\WINDOWS\system32\ljjgecb.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xcttgs]
xcttgs.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c009343E]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\xcttgm.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\xcttgs.sys]
@="Driver"

R1 SonyFanC;FAN Control Device Service;C:\windows\system32\Drivers\SonyFanC.sys
R1 xcttgm;STK Bi 001;\??\C:\WINDOWS\system32\xcttgm.sys
R2 V7;V7;C:\windows\system32\drivers\V7.sys
R3 CLEDX;Team H2O CLEDX service;C:\windows\system32\DRIVERS\cledx.sys
R3 USBKT1X1;M-Audio USB Keystation;C:\windows\system32\drivers\usbkt1x1.sys
S2 xcttgs;STK Bi 002;\??\C:\WINDOWS\system32\xcttgm.sys
S3 BCM42XX;Broadcom iLine10™ Network Adapter Driver;C:\windows\system32\DRIVERS\bcm42xx5.sys
S3 BCMModem;BCM V.90 56K Modem;C:\windows\system32\DRIVERS\BCMDM.sys
S3 sonypvs1;Sony Digital Imaging Video2;C:\windows\system32\DRIVERS\sonypvs1.sys
S3 tbhsd;Tunebite High-Speed Dubbing;C:\windows\system32\drivers\tbhsd.sys
S3 UKS11LDR;M-Audio USB Keystation Loader;C:\windows\system32\drivers\uks11ldr.sys

*Newly Created Service* - AVGASCLN
.
Contents of the 'Scheduled Tasks' folder
"2007-09-19 05:00:00 C:\windows\Tasks\At2.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 06:00:00 C:\windows\Tasks\At3.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 07:00:02 C:\windows\Tasks\At4.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 08:00:00 C:\windows\Tasks\At5.job"
"2007-09-19 09:00:00 C:\windows\Tasks\At6.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 10:00:00 C:\windows\Tasks\At7.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 11:00:00 C:\windows\Tasks\At8.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 12:00:00 C:\windows\Tasks\At9.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 13:00:02 C:\windows\Tasks\At10.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 14:00:02 C:\windows\Tasks\At11.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 15:00:02 C:\windows\Tasks\At12.job"
"2007-09-19 16:00:00 C:\windows\Tasks\At13.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 17:00:00 C:\windows\Tasks\At14.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 18:00:02 C:\windows\Tasks\At15.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 19:00:02 C:\windows\Tasks\At16.job"
"2007-09-19 20:00:02 C:\windows\Tasks\At17.job"
"2007-09-19 21:00:04 C:\windows\Tasks\At18.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 22:00:02 C:\windows\Tasks\At19.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 23:00:02 C:\windows\Tasks\At20.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 00:00:02 C:\windows\Tasks\At21.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 01:00:02 C:\windows\Tasks\At22.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 02:00:02 C:\windows\Tasks\At23.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 03:00:02 C:\windows\Tasks\At24.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
"2007-09-19 04:00:02 C:\windows\Tasks\At25.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 05:00:02 C:\windows\Tasks\At26.job"
"2007-09-19 06:00:02 C:\windows\Tasks\At27.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 07:00:02 C:\windows\Tasks\At28.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 08:00:02 C:\windows\Tasks\At29.job"
"2007-09-19 09:00:02 C:\windows\Tasks\At30.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 10:00:02 C:\windows\Tasks\At31.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 11:00:02 C:\windows\Tasks\At32.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 12:00:02 C:\windows\Tasks\At33.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 13:00:02 C:\windows\Tasks\At34.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 14:00:02 C:\windows\Tasks\At35.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 15:00:02 C:\windows\Tasks\At36.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 16:00:02 C:\windows\Tasks\At37.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 17:00:02 C:\windows\Tasks\At38.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 18:00:02 C:\windows\Tasks\At39.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 19:00:02 C:\windows\Tasks\At40.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 20:00:02 C:\windows\Tasks\At41.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 21:00:04 C:\windows\Tasks\At42.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 22:00:02 C:\windows\Tasks\At43.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 23:00:02 C:\windows\Tasks\At44.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 00:00:02 C:\windows\Tasks\At45.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 01:00:02 C:\windows\Tasks\At46.job"
- C:\WINDOWS\system32\p4oxoIQr.exe
"2007-09-19 02:00:02 C:\windows\Tasks\At47.job"
"2007-09-19 03:00:02 C:\windows\Tasks\At48.job"
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-19 19:22:43
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-19 19:28:03 - machine was rebooted
C:\ComboFix2.txt … 2007-09-19 10:43
C:\ComboFix-quarantined-files.txt … 2007-09-19 19:28
.
— E O F —

HIJACKTHIS LOG:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:32:35 PM, on 9/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\windows\System32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\windows\Explorer.EXE
C:\windows\system32\wscntfy.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe
C:\windows\system32\CTHELPER.EXE
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\windows\system32\notepad.exe
C:\windows\system32\rundll32.exe
C:\Program Files\Avant Browser\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Malware Sweeper] C:\Program Files\MalwareSweeper.com\MalwareSweeper\MalSwep.exe /STARTUP
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan
O4 - HKCU\..\Policies\Explorer\Run: [1] C:\windows\system32\service\explorer.exe
O4 - HKUS\S-1-5-18\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet (User 'Default user')
O8 - Extra context menu item: Add to AD Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Block All Images from the Same Server - C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open All Links in This Page… - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebpr…etup1.0.0.8.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab30149.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/popc…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DA4555A7-7D86-4FF5-8C7F-E061A2801E06}: NameServer = 137.49.1.100,137.49.1.150
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe

–
End of file - 7638 bytes
Hi

Download HaxFix.
Save it to your desktop.
Close down all applications and every browser window.
Double-Click onto the haxfix.exe, to start the installation.
Put a checkmark next to "Create a desktop icon".
Click "Next" and follow the prompts on the screen.
When the installation is finished, make sure that "Launch HaxFix" is enabled.
Click "Finish".
Now a Red DOS Window opens with the following options to chose:
1. Make logfile
2. Run auto fix
3. Run manual fix
E. Exit Haxfix

Choose the Option 1: Create a log by pressing 1
This will need a moment of your time. When the HaxFix is finished, a textfile opens (haxlog.txt)
You need to use this option first. And paste the logfile here.

Start the HaxFix on your desktop again by clicking onto the HaxFix icon.
(You can also open the folder program files\haxfix and have a double click onto the fix.bat)
Close down all applications and browser windows. Your system will restart while using the HaxFix.
Choose 2 and press ENTER to start the Option 2 "Run Auto Fix.
Follow the instructions on the screen.
Your system will restart.
As soon as the HaxFix is done, a textfile will open (c:\haxfix.txt). Paste this here.

Open Notepad and Copy/Paste the text in the codebox below into it:


File::
C:\windows\system32\rqrsspp.dll
C:\windows\system32\ljjgecb.dll
C:\windows\system32\upfrrfmr.exe
C:\windows\system32\rvpxyhqb.exe
C:\WINDOWS\system32\hskeevjr.dll
C:\windows\Tasks\At2.job
C:\windows\Tasks\At3.job
C:\windows\Tasks\At4.job
C:\windows\Tasks\At5.job
C:\windows\Tasks\At6.job
C:\windows\Tasks\At7.job
C:\windows\Tasks\At8.job
C:\windows\Tasks\At9.job
C:\windows\Tasks\At10.job
C:\windows\Tasks\At11.job
C:\windows\Tasks\At12.job
C:\windows\Tasks\At13.job
C:\windows\Tasks\At14.job
C:\windows\Tasks\At16.job
C:\windows\Tasks\At17.job
C:\windows\Tasks\At18.job
C:\windows\Tasks\At19.job
C:\windows\Tasks\At20.job
C:\windows\Tasks\At21.job
C:\windows\Tasks\At22.job
C:\windows\Tasks\At23.job
C:\windows\Tasks\At24.job
C:\windows\Tasks\At25.job
C:\windows\Tasks\At26.job
C:\windows\Tasks\At27.job
C:\windows\Tasks\At28.job
C:\windows\Tasks\At29.job
C:\windows\Tasks\At30.job
C:\windows\Tasks\At31.job
C:\windows\Tasks\At32.job
C:\windows\Tasks\At33.job
C:\windows\Tasks\At34.job
C:\windows\Tasks\At35.job
C:\windows\Tasks\At36.job
C:\windows\Tasks\At37.job
C:\windows\Tasks\At38.job
C:\windows\Tasks\At39.job
C:\windows\Tasks\At40.job
C:\windows\Tasks\At41.job
C:\windows\Tasks\At42.job
C:\windows\Tasks\At43.job
C:\windows\Tasks\At44.job
C:\windows\Tasks\At45.job
C:\windows\Tasks\At46.job
C:\windows\Tasks\At47.job
C:\windows\Tasks\At48.job

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83B91FB3-9CA4-4B6B-873D-9691578353E3}] 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjgecb]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c009343E]

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log and the haxfix log.
COMBOFIX LOG:

ComboFix 07-09-19.8 - "Mr. Miller" 2007-09-20 12:47:04.4 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.275 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Mr. Miller\Desktop\SpyWare Tools\CFScript.txt
* Created a new restore point

FILE::
C:\windows\system32\rqrsspp.dll
C:\windows\system32\ljjgecb.dll
C:\windows\system32\upfrrfmr.exe
C:\windows\system32\rvpxyhqb.exe
C:\WINDOWS\system32\hskeevjr.dll
C:\windows\Tasks\At2.job
C:\windows\Tasks\At3.job
C:\windows\Tasks\At4.job
C:\windows\Tasks\At5.job
C:\windows\Tasks\At6.job
C:\windows\Tasks\At7.job
C:\windows\Tasks\At8.job
C:\windows\Tasks\At9.job
C:\windows\Tasks\At10.job
C:\windows\Tasks\At11.job
C:\windows\Tasks\At12.job
C:\windows\Tasks\At13.job
C:\windows\Tasks\At14.job
C:\windows\Tasks\At16.job
C:\windows\Tasks\At17.job
C:\windows\Tasks\At18.job
C:\windows\Tasks\At19.job
C:\windows\Tasks\At20.job
C:\windows\Tasks\At21.job
C:\windows\Tasks\At22.job
C:\windows\Tasks\At23.job
C:\windows\Tasks\At24.job
C:\windows\Tasks\At25.job
C:\windows\Tasks\At26.job
C:\windows\Tasks\At27.job
C:\windows\Tasks\At28.job
C:\windows\Tasks\At29.job
C:\windows\Tasks\At30.job
C:\windows\Tasks\At31.job
C:\windows\Tasks\At32.job
C:\windows\Tasks\At33.job
C:\windows\Tasks\At34.job
C:\windows\Tasks\At35.job
C:\windows\Tasks\At36.job
C:\windows\Tasks\At37.job
C:\windows\Tasks\At38.job
C:\windows\Tasks\At39.job
C:\windows\Tasks\At40.job
C:\windows\Tasks\At41.job
C:\windows\Tasks\At42.job
C:\windows\Tasks\At43.job
C:\windows\Tasks\At44.job
C:\windows\Tasks\At45.job
C:\windows\Tasks\At46.job
C:\windows\Tasks\At47.job
C:\windows\Tasks\At48.job
.

((((((((((((((((((((((((( Files Created from 2007-08-20 to 2007-09-20 )))))))))))))))))))))))))))))))
.

2007-09-20 12:08 90,112 –a—— C:\WINDOWS\system32\RegDACL.exe
2007-09-20 12:08 9,006 –a—— C:\clean.bat
2007-09-20 12:08 53,248 –a—— C:\WINDOWS\system32\process.exe
2007-09-20 12:08 4,096 –a—— C:\WINDOWS\system32\reboot.exe
2007-09-19 16:00 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-09-18 11:02 384 –a—— C:\WINDOWS\system32\DVCStateBkp-{00000002-00000000-00000009-00001102-00000004-40011102}.dat
2007-09-18 11:02 384 –a—— C:\WINDOWS\system32\DVCState-{00000002-00000000-00000009-00001102-00000004-40011102}.dat
2007-09-18 10:26 217,088 –a—— C:\WINDOWS\Rewire.dll
2007-09-18 10:21 914,320 –a—— C:\WINDOWS\system32\drivers\ha10kx2k.sys
2007-09-18 10:21 298,971 –a—— C:\WINDOWS\system32\ctstatic.dat
2007-09-18 10:21 20,480 –a—— C:\WINDOWS\INRES.DLL
2007-09-18 10:21 148,368 –a—— C:\WINDOWS\system32\drivers\haP16v2k.sys
2007-09-18 10:21 147,088 –a—— C:\WINDOWS\system32\drivers\emupia2k.sys
2007-09-18 10:21 130,384 –a—— C:\WINDOWS\system32\drivers\ctsfm2k.sys
2007-09-18 08:06 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-18 07:03 d——– C:\WINDOWS\system32\ActiveScan
2007-09-18 01:47 512,688 –a—— C:\WINDOWS\system32\XceedCry.dll
2007-09-18 01:47 423,784 –a—— C:\WINDOWS\system32\XceedBkp.dll
2007-09-18 01:47 101,888 –a—— C:\WINDOWS\system32\VB6STKIT.DLL
2007-09-18 01:47 10,752 –a—— C:\WINDOWS\system32\md5.dll
2007-09-18 01:47 d——– C:\Program Files\MalwareSweeper.com
2007-09-18 01:40 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-17 23:54 d–hs—- C:\FOUND.059
2007-09-14 22:35 d–hs—- C:\FOUND.058
2007-09-14 22:06 d——– C:\WINDOWS\pss
2007-09-14 10:56 d–hs—- C:\FOUND.057
2007-09-14 09:47 d–hs—- C:\FOUND.056
2007-09-11 11:36 d——– C:\Program Files\AAS
2007-09-09 23:35 d——– C:\WINDOWS\ASTULogTemp
2007-09-08 17:45 d——– C:\Program Files\Cakewalk
2007-09-08 17:45 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cakewalk
2007-09-08 16:01 17,408 ——— C:\WINDOWS\system32\minimp3.exe
2007-09-08 15:56 d——– C:\Program Files\Common Files\Native Instruments
2007-09-08 14:47 d–hs—- C:\FOUND.055
2007-09-06 16:03 d–hs—- C:\FOUND.054
2007-08-31 12:01 d——– C:\Program Files\Common Files\Intellisync
2007-08-30 01:07 d–hs—- C:\FOUND.053
2007-08-23 14:41 d–hs—- C:\FOUND.052

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-08-13 17:21 49936 –a—— C:\windows\system32\compress.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E2005AA1-991F-4F20-A516-26BE7632A674}]
C:\windows\system32\pmkhi.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" []
"H2O"="C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe" [2005-11-01 00:00]
"ZTgServerSwitch"="c:\program files\support.com\client\lserver\server.vbs" [2001-09-10 19:36]
"WebTrapNT.exe"="C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe" [2001-09-06 09:20]
"Pop3trap.exe"="C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe" [2001-09-06 09:25]
"CTHelper"="CTHELPER.EXE" [2004-02-02 22:30 C:\WINDOWS\system32\CTHELPER.EXE]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 22:36]
"SetDefaultMIDI"="MIDIDef.exe" [2003-06-20 06:13 C:\WINDOWS\MIDIDEF.EXE]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Yahoo! Pager"=C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
"AIM"=C:\Program Files\AIM95\aim.exe -cnetwait.odl

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkhi]
C:\windows\system32\pmkhi.dll

R1 SonyFanC;FAN Control Device Service;C:\windows\system32\Drivers\SonyFanC.sys
R2 V7;V7;C:\windows\system32\drivers\V7.sys
R3 CLEDX;Team H2O CLEDX service;C:\windows\system32\DRIVERS\cledx.sys
R3 USBKT1X1;M-Audio USB Keystation;C:\windows\system32\drivers\usbkt1x1.sys
S3 BCM42XX;Broadcom iLine10™ Network Adapter Driver;C:\windows\system32\DRIVERS\bcm42xx5.sys
S3 BCMModem;BCM V.90 56K Modem;C:\windows\system32\DRIVERS\BCMDM.sys
S3 sonypvs1;Sony Digital Imaging Video2;C:\windows\system32\DRIVERS\sonypvs1.sys
S3 tbhsd;Tunebite High-Speed Dubbing;C:\windows\system32\drivers\tbhsd.sys
S3 UKS11LDR;M-Audio USB Keystation Loader;C:\windows\system32\drivers\uks11ldr.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-09-19 18:00:02 C:\windows\Tasks\At15.job"
- C:\WINDOWS\system32\k2j8vTL6.exe
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-20 12:50:31
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-20 12:52:19
C:\ComboFix3.txt … 2007-09-19 10:43
C:\ComboFix-quarantined-files.txt … 2007-09-20 12:52
C:\ComboFix2.txt … 2007-09-19 19:28
.
— E O F —



HIJACK THIS LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:53:25 PM, on 9/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\windows\System32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\windows\system32\wscntfy.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe
C:\windows\system32\CTHELPER.EXE
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\windows\system32\taskmgr.exe
C:\windows\explorer.exe
C:\windows\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {E2005AA1-991F-4F20-A516-26BE7632A674} - C:\windows\system32\pmkhi.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Policies\Explorer\Run: [1] C:\windows\system32\service\explorer.exe
O4 - HKUS\S-1-5-18\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebpr…etup1.0.0.8.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab30149.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/popc…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DA4555A7-7D86-4FF5-8C7F-E061A2801E06}: NameServer = 137.49.1.100,137.49.1.150
O20 - Winlogon Notify: pmkhi - C:\windows\system32\pmkhi.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe

–
End of file - 7592 bytes




HAXFIX LOG:

HAXFIX logfile - by Marckie

version 4.54
Thu 09/20/2007 12:12:34.14

— Auto Haxdoorfix —


searching for files:


searching for services….
service xcttgs found
[SWSC] DeleteService SUCCESS
service xcttgm found
[SWSC] DeleteService SUCCESS


— Goldunfix —


searching for files:


checking iexplore.exe
iexplore.exe is not infected

searching for SSODLkeys:
no SSODLkeys found

searching for notifykeys:
no notifykeys found

searching for services:
no services found


…..rebooting the computer…..


searching for ssodlkeys

not needed


searching for notifykeys

notifykey xcttgs not found


searching for services

service xcttgs not found
service xcttgm not found


searching for safeboot services

safeboot service xcttgs.sys not found
safeboot service xcttgm.sys not found


searching for files

xcttgs.dll exists
deleting xcttgs.dll
xcttgs.dll has been deleted

xcttgs.sys exists
deleting xcttgs.sys
xcttgs.sys has been deleted

xcttgm.sys exists
deleting xcttgm.sys
xcttgm.sys has been deleted


checking for other files

83ghh.ini exists
deleting 83ghh.ini
83ghh.ini has been deleted

aaaxcfdwq.dat exists
deleting aaaxcfdwq.dat
aaaxcfdwq.dat has been deleted


checking for a3d files

no a3d files found


— Catchme logfile - thank you Gmer —

catchme 0.3.1160 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-20 12:28:07
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0



Finished
Hi

Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\windows\system32\pmkhi.dll
C:\windows\Tasks\At15.job
C:\WINDOWS\system32\k2j8vTL6.exe

Folder::
c:\program files\support.com
C:\FOUND.059
C:\FOUND.058
C:\FOUND.057
C:\FOUND.056
C:\FOUND.055
C:\FOUND.054
C:\FOUND.053
C:\FOUND.052
 
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E2005AA1-991F-4F20-A516-26BE7632A674}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkhi]

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.
COMBOFIX:

ComboFix 07-09-19.8 - "Mr. Miller" 2007-09-21 10:44:32.6 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.264 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Mr. Miller\Desktop\SpyWare Tools\CFScript.txt
* Created a new restore point

FILE::
C:\windows\system32\pmkhi.dll
C:\windows\Tasks\At15.job
C:\WINDOWS\system32\k2j8vTL6.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\FOUND.052
C:\FOUND.052\FILE0000.CHK
C:\FOUND.052\FILE0001.CHK
C:\FOUND.052\FILE0002.CHK
C:\FOUND.052\FILE0003.CHK
C:\FOUND.052\FILE0004.CHK
C:\FOUND.052\FILE0005.CHK
C:\FOUND.052\FILE0006.CHK
C:\FOUND.052\FILE0007.CHK
C:\FOUND.052\FILE0008.CHK
C:\FOUND.052\FILE0009.CHK
C:\FOUND.052\FILE0010.CHK
c:\program files\support.com

.
((((((((((((((((((((((((( Files Created from 2007-08-21 to 2007-09-21 )))))))))))))))))))))))))))))))
.

2007-09-20 12:08 90,112 –a—— C:\WINDOWS\system32\RegDACL.exe
2007-09-20 12:08 9,006 –a—— C:\clean.bat
2007-09-20 12:08 53,248 –a—— C:\WINDOWS\system32\process.exe
2007-09-20 12:08 4,096 –a—— C:\WINDOWS\system32\reboot.exe
2007-09-19 16:00 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-09-18 11:02 384 –a—— C:\WINDOWS\system32\DVCStateBkp-{00000002-00000000-00000009-00001102-00000004-40011102}.dat
2007-09-18 11:02 384 –a—— C:\WINDOWS\system32\DVCState-{00000002-00000000-00000009-00001102-00000004-40011102}.dat
2007-09-18 10:26 217,088 –a—— C:\WINDOWS\Rewire.dll
2007-09-18 10:21 914,320 –a—— C:\WINDOWS\system32\drivers\ha10kx2k.sys
2007-09-18 10:21 298,971 –a—— C:\WINDOWS\system32\ctstatic.dat
2007-09-18 10:21 20,480 –a—— C:\WINDOWS\INRES.DLL
2007-09-18 10:21 148,368 –a—— C:\WINDOWS\system32\drivers\haP16v2k.sys
2007-09-18 10:21 147,088 –a—— C:\WINDOWS\system32\drivers\emupia2k.sys
2007-09-18 10:21 130,384 –a—— C:\WINDOWS\system32\drivers\ctsfm2k.sys
2007-09-18 08:06 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-18 07:03 d——– C:\WINDOWS\system32\ActiveScan
2007-09-18 01:47 512,688 –a—— C:\WINDOWS\system32\XceedCry.dll
2007-09-18 01:47 423,784 –a—— C:\WINDOWS\system32\XceedBkp.dll
2007-09-18 01:47 101,888 –a—— C:\WINDOWS\system32\VB6STKIT.DLL
2007-09-18 01:47 10,752 –a—— C:\WINDOWS\system32\md5.dll
2007-09-18 01:47 d——– C:\Program Files\MalwareSweeper.com
2007-09-18 01:40 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-14 22:06 d——– C:\WINDOWS\pss
2007-09-11 11:36 d——– C:\Program Files\AAS
2007-09-09 23:35 d——– C:\WINDOWS\ASTULogTemp
2007-09-08 17:45 d——– C:\Program Files\Cakewalk
2007-09-08 17:45 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cakewalk
2007-09-08 16:01 17,408 ——— C:\WINDOWS\system32\minimp3.exe
2007-09-08 15:56 d——– C:\Program Files\Common Files\Native Instruments
2007-08-31 12:01 d——– C:\Program Files\Common Files\Intellisync

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-08-13 17:21 49936 –a—— C:\windows\system32\compress.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" []
"H2O"="C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe" [2005-11-01 00:00]
"ZTgServerSwitch"="c:\program files\support.com\client\lserver\server.vbs" []
"WebTrapNT.exe"="C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe" [2001-09-06 09:20]
"Pop3trap.exe"="C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe" [2001-09-06 09:25]
"CTHelper"="CTHELPER.EXE" [2004-02-02 22:30 C:\WINDOWS\system32\CTHELPER.EXE]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 22:36]
"SetDefaultMIDI"="MIDIDef.exe" [2003-06-20 06:13 C:\WINDOWS\MIDIDEF.EXE]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Yahoo! Pager"=C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
"AIM"=C:\Program Files\AIM95\aim.exe -cnetwait.odl

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"=0 (0x0)

R1 SonyFanC;FAN Control Device Service;C:\windows\system32\Drivers\SonyFanC.sys
R2 V7;V7;C:\windows\system32\drivers\V7.sys
R3 CLEDX;Team H2O CLEDX service;C:\windows\system32\DRIVERS\cledx.sys
R3 USBKT1X1;M-Audio USB Keystation;C:\windows\system32\drivers\usbkt1x1.sys
S3 BCM42XX;Broadcom iLine10™ Network Adapter Driver;C:\windows\system32\DRIVERS\bcm42xx5.sys
S3 BCMModem;BCM V.90 56K Modem;C:\windows\system32\DRIVERS\BCMDM.sys
S3 sonypvs1;Sony Digital Imaging Video2;C:\windows\system32\DRIVERS\sonypvs1.sys
S3 tbhsd;Tunebite High-Speed Dubbing;C:\windows\system32\drivers\tbhsd.sys
S3 UKS11LDR;M-Audio USB Keystation Loader;C:\windows\system32\drivers\uks11ldr.sys

.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-21 10:47:48
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-21 10:49:22
C:\ComboFix-quarantined-files.txt … 2007-09-21 10:49
C:\ComboFix3.txt … 2007-09-19 19:28
C:\ComboFix2.txt … 2007-09-20 12:52
.
— E O F —


HIJACKTHIS:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:53:35 AM, on 9/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\windows\System32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\windows\system32\wscntfy.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe
C:\windows\system32\CTHELPER.EXE
C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\windows\explorer.exe
C:\windows\system32\notepad.exe
C:\Program Files\Avant Browser\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Policies\Explorer\Run: [1] C:\windows\system32\service\explorer.exe
O4 - HKUS\S-1-5-18\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet (User 'Default user')
O8 - Extra context menu item: Add to AD Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Block All Images from the Same Server - C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open All Links in This Page… - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebpr…etup1.0.0.8.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab30149.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/popc…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DA4555A7-7D86-4FF5-8C7F-E061A2801E06}: NameServer = 137.49.1.100,137.49.1.150
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe

–
End of file - 7886 bytes
Hi

Download HaxFix.
Save it to your desktop.
Close down all applications and every browser window.
Double-Click onto the haxfix.exe, to start the installation.
Put a checkmark next to "Create a desktop icon".
Click "Next" and follow the prompts on the screen.
When the installation is finished, make sure that "Launch HaxFix" is enabled.
Click "Finish".
Now a Red DOS Window opens with the following options to chose:
1. Make logfile
2. Run auto fix
3. Run manual fix
E. Exit Haxfix

Choose the Option 1: Create a log by pressing 1
This will need a moment of your time. When the HaxFix is finished, a textfile opens (haxlog.txt)
You need to use this option first. And paste the logfile here.
HAXFIX logfile - by Marckie

version 4.54
Fri 09/21/2007 19:22:07.88

— Checking for Haxdoor —

checking for a3d files
a3d files not found

checking for matching notify keys
no matching notify keys found

checking for matching services
matching services found
tmcomm

checking for matching safeboot services
no matching safeboot services found

checking for other Haxdoor-files
no other Haxdoor-files found


— Checking for Goldun —

checking for SSODL keys
no ssodl keys found

checking for notify keys
no notify keys found

checking for services
no services found

checking for other Goldun-files
no other Goldun-files found

checking iexplore.exe
iexplore.exe is not infected


— Catchme logfile - thank you Gmer —

catchme 0.3.1160 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-21 19:22:08
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


— Analysing Catchme logfile —

no matching regkeys found


Finished!
Hi
  • Download GMER by GMER from here
  • Unzip it to a folder on your desktop
  • Double click on gmer.exe to launch GMER
  • If asked, allow the gmer.sys driver load
  • If it warns you about rootkit activity and asks if you want to run scan, click OK
  • If you don't get a warning then
    • Click the rootkit tab
    • Click Scan
  • Once the scan has finished, click copy
  • Paste the log into notepad using Ctrl+V
  • Save it to your desktop as gmerrk.txt
  • Click on the >>> tab
  • This will open up the rest of the tabs for you
  • Click on the Autostart tab
  • Click on Scan
  • Once the scan has finished, click copy
  • Paste the log into notepad using Ctrl+V
  • Save it to your desktop as gmerautos.txt
  • Copy and paste the contents of gmerautos.txt and gmerrk.txt as a reply to this topic
GMERRK:

GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-09-22 12:46:16
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.13 —-

SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess

—- Devices - GMER 1.0.13 —-

AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F49812B8] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F49815F2] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [F497FBBA] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE [F49812B8] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_NAMED_PIPE [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLOSE [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_READ [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_WRITE [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_EA [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL [F49815F2] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP [F497FBBA] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_MAILSLOT [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_SECURITY [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_SECURITY [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_POWER [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SYSTEM_CONTROL [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CHANGE [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_QUOTA [F497F930] tmpreflt.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_QUOTA [F497F930] tmpreflt.sys

—- EOF - GMER 1.0.13 —-




GMERAUTOS:
GMER 1.0.13.12551 - http://www.gmer.net
Autostart scan 2007-09-22 12:48:12
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\windows\system32\userinit.exe,

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
AVG Anti-Spyware Guard /*AVG Anti-Spyware Guard*/@ = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
Creative Service for CDROM Access /*Creative Service for CDROM Access*/@ = C:\WINDOWS\system32\CTsvcCDA.exe
NVSvc /*NVIDIA Driver Helper Service*/@ = %SystemRoot%\System32\nvsvc32.exe
ScsiPort@ = %SystemRoot%\system32\drivers\scsiport.sys
Spooler /*Print Spooler*/@ = %SystemRoot%\system32\spoolsv.exe
Tmntsrv /*Trend NT Realtime Service*/@ = "C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe"
UMWdf /*Windows User Mode Driver Framework*/@ = C:\WINDOWS\system32\wdfmgr.exe
WMDM PMSP Service /*WMDM PMSP Service*/@ = C:\WINDOWS\system32\MsPMSPSv.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@NvCplDaemonRUNDLL32.EXE NvQTwk,NvCplDaemon initialize = RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
@H2OC:\Program Files\SyncroSoft\Pos\H2O\cledx.exe = C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
@ZTgServerSwitchc:\program files\support.com\client\lserver\server.vbs /*file not found*/ = c:\program files\support.com\client\lserver\server.vbs /*file not found*/
@WebTrapNT.exe"C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe" = "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
@Pop3trap.exe"C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe" = "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
@CTHelperCTHELPER.EXE = CTHELPER.EXE
@!AVG Anti-Spyware"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@H/PC Connection Agent"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
@SetDefaultMIDIMIDIDef.exe = MIDIDef.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run@1 = C:\windows\system32\service\explorer.exe /*file not found*/

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks@{57B86673-276A-48B2-BAE7-C6DBB3020EB8} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Display Panning CPL Extension*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{32683183-48a0-441b-a342-7c2a440a9478} /*Media Band*/(null) =
@{FED7043D-346A-414D-ACD7-550D052499A7} /*dBpowerAMP Music Converter 1*/C:\Program Files\Illustrate\dBpowerAMP\dBShell.dll /*file not found*/ = C:\Program Files\Illustrate\dBpowerAMP\dBShell.dll /*file not found*/
@{2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5} /*dBpowerAMP Music Converter*/C:\Program Files\Illustrate\dBpowerAMP\dMCShell.dll /*file not found*/ = C:\Program Files\Illustrate\dBpowerAMP\dMCShell.dll /*file not found*/
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Outlook Custom Icon Handler*/C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL = C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Program Files\Microsoft Office\Office10\msohev.dll = C:\Program Files\Microsoft Office\Office10\msohev.dll
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\System32\extmgr.dll = C:\WINDOWS\System32\extmgr.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Program Files\WinRAR\rarext.dll = C:\Program Files\WinRAR\rarext.dll
@{4AFB2C12-9D16-4478-AEF4-C3FC539961E4} /*Zen MicroPhoto Media Explorer*/C:\Program Files\Creative\Creative Zen MicroPhoto\SHCTMTP.dll = C:\Program Files\Creative\Creative Zen MicroPhoto\SHCTMTP.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/C:\Program Files\Real\RealPlayer\rpshell.dll = C:\Program Files\Real\RealPlayer\rpshell.dll
@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} /*Adobe.Acrobat.ContextMenu*/C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll = C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll
@{48F45200-91E6-11CE-8A4F-0080C81A28D4} /*TMD Shell Extension*/C:\Program Files\Trend Micro\PC-cillin 2000\Tmdshell.dll = C:\Program Files\Trend Micro\PC-cillin 2000\Tmdshell.dll
@{771A9DA0-731A-11CE-993C-00AA004ADB6C} /*VBPropSheet*/C:\Program Files\Trend Micro\PC-cillin 2000\VBProp.dll = C:\Program Files\Trend Micro\PC-cillin 2000\VBProp.dll
@{49BF5420-FA7F-11cf-8011-00A0C90A8F78} /*Mobile Device*/C:\PROGRA~1\MICROS~3\Wcesview.dll = C:\PROGRA~1\MICROS~3\Wcesview.dll
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll = C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
Adobe.Acrobat.ContextMenu@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} = C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
CTMTPMediaExplorer@{7895F317-A125-42CC-BD3E-5830765CE577} = C:\PROGRA~1\Creative\SHARED~1\CtCmeCtx.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers >>>
@{48F45200-91E6-11CE-8A4F-0080C81A28D4}C:\Program Files\Trend Micro\PC-cillin 2000\Tmdshell.dll = C:\Program Files\Trend Micro\PC-cillin 2000\Tmdshell.dll
@{58C83EE0-5261-11D3-81DC-D2AB3F16133C}C:\WINDOWS\system32\Incinerator.dll = C:\WINDOWS\system32\Incinerator.dll

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers@{48F45200-91E6-11CE-8A4F-0080C81A28D4} = C:\Program Files\Trend Micro\PC-cillin 2000\Tmdshell.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
CTMTPMediaExplorer@{7895F317-A125-42CC-BD3E-5830765CE577} = C:\PROGRA~1\Creative\SHARED~1\CtCmeCtx.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers@{58C83EE0-5261-11D3-81DC-D2AB3F16133C} = C:\WINDOWS\system32\Incinerator.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll = C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll = C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
@{AE7CD045-E861-484f-8273-0445EE161910}C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll = C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll

HKLM\Software\Microsoft\Internet Explorer\Plugins\Extension\.spop@Location = C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.sony.com/vaiopeople = http://www.sony.com/vaiopeople
@Start Pagehttp://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr6/*http://www.yahoo.com = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main@Start Page = http://www.yahoo.com/

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
cdo@CLSID = C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\System32\itss.dll
lid@CLSID = C:\WINDOWS\System32\msvidctl.dll
livecall@CLSID = C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
mhtml@CLSID = %SystemRoot%\System32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\System32\itss.dll
msnim@CLSID = C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
mso-offdap@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll

HKLM\Software\Classes\PROTOCOLS\Handler\wia@CLSID = C:\WINDOWS\System32\wiascr.dll

—- EOF - GMER 1.0.13 —-
Hi

I notice you are running a FAT32 filesystem. Is there a reason for this, such as you are networked or dual-booting with an older OS such as Windows 98? If not, I would suggest switching to NTFS for better security, amongst other benefits. Let me know in your next reply?

You can now delete Haxfix and the Combofix icon and the GMER folder from your Desktop. Then navigate to and delete the following folders, if they are present.

C:\Combofix
C:\Qoobox

AVG Anti Spyware, this is a good scanner to use with others I have listed below. This will auto update and provide resident protection for 30 days. Afterwards you will need to update manually before scanning. Scan weekly if you have high internet use. You can remove this through Add/Remove Programs in the Control Panel.

Delete the older versions of Java and download the newest.
Please follow these steps to remove older version Java components.
  • Close any programmes you may have running, ESPECIALLY your web browser
  • Click Start > Control Panel.
  • Click Add/Remove Programs.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove all versions of Java.
  • Reboot your computer once all Java components are removed.
Then download the latest version of Java Runtime Environment (JRE) (4th one down the list), which is JRE6u2, and click Yes at the page warning, then accept the Licence Agreement before downloading the Offline file.

This is my usual speech for when you are clean, which you appear to be.

Please follow these simple steps in order to keep your computer clean and secure:
Disable and Enable System Restore.

It's also a good idea to Flush your System Restore points after ridding yourself of malware:
  • Click Start | Help and Support | Undo changes to your computer with System Restore.
  • Click Create A Restore Point then click Next. Give it a name it and then click Create, then Close.
  • Close the Help and Support Center box.
  • Click Start | Run and type Cleanmgr
  • Select (C: ) then click OK.
  • Click the More Options tab.
  • Click Clean Up in the System Restore Section.
This will remove all previous restore points except the newly created one.

Re hide your system files To do so, please follow the steps below:
  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Put a check by "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Do not show hidden files and folders."
  • Check "Hide protected operating system files."
  • Click Apply, and then click OK.

Here are some free programs, I recommend.

Spybot Search and Destroy
Download it from here . Just choose a mirror and off you go.
Find here the tutorial on how to use Spybot properly here

Install Spyware Guard
Download it from here
Find here the tutorial on how to use Spyware Guard here

Install SpyWare Blaster
Download it from here
Find here the tutorial on how to use Spyware Blaster here

Install WinPatrol
Download it from here
Here you can find information about how WinPatrol works here


Make sure your Windows is ALWAYS up to date!

An unpatched Windows is vulnerable and even with the "best" Antivirus and Firewall installed, malware will find its way through.
So visit http://windowsupdate.microsoft.com/ to download and install the latest updates.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Please check out Tony Klein's article "How did I get infected in the first place?"


Follow this list and your potential for being infected again will reduce dramatically.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI