This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] My Homepage Was Hijacked!

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

TeaTimer is an excellent tool for the prevention of spyware but it can sometimes prevent HijackThis from fixing certain things. Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click "Advanced mode" if not already selected.
  • Choose Yes at the Warning prompt.
  • Expand the Tools menu.
  • Click Resident.
  • Uncheck the Resident "TeaTimer" (Protection of overall system settings) active. box.
  • In the File menu click Exit to exit Spybot Search & Destroy.
Download http://www.techsupportforum.com/sectools/ResetTeaTimer.zip
Double click ResetTeaTimer.bat to remove all entries set by TeaTimer.


———–


* Disconnect from the Internet.

* With the pendrive still inserted, run Flash_Disinfector once. It shall only take a few moments

* When that's done, do a scan with Hijackthis & place a check next to these items and select "Fix checked":

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hentaisailormoon.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.hentaisailormoon.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Freak-X Browser
O4 - HKLM\..\Run: [Microsoft File Server Manager 2.36] C:\WINDOWS\system32\filesrv32.exe
O4 - HKLM\..\Run: [Heiku - Munist] C:\WINDOWS\system32\EraleuH.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1


Do not be alarmed if most of those entries aren't found.


———–


Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\filesrv32.exe
C:\WINDOWS\system32\EraleuH.exe
Registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoThemesTab"=-
"NoChangeKeyboardNavigationIndicators"=-
"NoChangeAnimation"=-
"NoDispBackgroundPage"=-
"NoPwdPage"=-
"NoSecCPL"=-
"NoProfilePage"=-
"NoVirtMemPage"=-
"NoFileSysPage"=-
"NoConfigPage"=-
"NoDevMgrPage"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"=-
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoExpandedNewMenu"=-
"NoFileUrl"=-
"Btn_Back"=-
"Btn_Forward"=-
"Btn_Stop"=-
"Btn_Refresh"=-
"Btn_Home"=-
"Btn_Search"=-
"Btn_History"=-
"Btn_Favorites"=-
"Btn_Folders"=-
"Btn_Fullscreen"=-
"Btn_Tools"=-
"Btn_MailNews"=-
"Btn_Size"=-
"Btn_Print"=-
"Btn_PrintPreview"=-
"Btn_Edit"=-
"Btn_Discussions"=-
"Btn_Cut"=-
"Btn_Copy"=-
"Btn_Paste"=-
"Btn_Encoding"=-
"Btn_Media"=-
"NoNavButtons"=-
"SmallIcons"=-
"SpecifyDefaultButtons"=-
"RestrictRun"=-
"NoAddPrinter"=-
"NoPrinterTabs"=-
"NoDeletePrinter"=-
"NoSetActiveDesktop"=-
"NoSecurityTab"=-
"NoHardwareTab"=-
"NoToolbarCustomize"=-
"NoFileMenu"=-
"NoShellSearchButton"=-
"NoPropertiesMyComputer"=-
"NoSMMyDocs"=-
"NoFavoritesMenu"=-
"NoRecentDocsMenu"=-
"NoSetFolders"=-
"NoTrayContextMenu"=-
"NoStartButton"=-
"NoBandCustomize"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]

Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you, C:\ComboFix.txt. Save that Log on your Desktop


———–


Reboot the machine. You may remove the pendrive after that.

Check if your homepage is still Hijacked. If so, please run COmboFix once more. Show me both ComboFix logs.
hi!!!

i followed all the steps you had given to me and the problem is already solved at last!!! :lol:

i rebooted my pc twice to check if my homepage is hijacked and it is not hijacked!!!! :)

i would like to say thanks for helping. :thumbup:

here is the latest combofix report. i just run combo fix once:

ComboFix 07-10-04.5 - user 2007-10-05 2:01:31.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1312 [GMT 8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\user\Desktop\CFScript3.txt
* Created a new restore point

FILE::
C:\WINDOWS\system32\EraleuH.exe
C:\WINDOWS\system32\filesrv32.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\EraleuH.exe
C:\WINDOWS\system32\filesrv32.exe

.
((((((((((((((((((((((((( Files Created from 2007-09-04 to 2007-10-04 )))))))))))))))))))))))))))))))
.

2007-10-05 01:54 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-10-05 01:51 82,258 –a—— C:\WINDOWS\system32\drivers\klin.dat
2007-10-05 01:51 82,258 –a—— C:\WINDOWS\system32\drivers\klick.dat
2007-10-05 01:50 510,752 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-10-05 01:50 5,152 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-10-05 01:50 d——– C:\Program Files\Kaspersky Lab
2007-10-05 01:38 d——– C:\kav
2007-10-05 01:37 24,773,064 –a—— C:\Program Files\kav7.0.0.125en.exe
2007-10-05 01:17 7,467,056 –a—— C:\Program Files\spybotsd15.exe
2007-10-04 22:29 drahs—- C:\autorun.inf
2007-10-04 16:18 d——– C:\Documents and Settings\user\Application Data\U3
2007-10-04 13:46 d——– C:\Documents and Settings\user 2\Shared
2007-10-04 13:46 d——– C:\Documents and Settings\user 2\Incomplete
2007-10-04 13:46 d——– C:\Documents and Settings\user 2\Application Data\LimeWire
2007-10-03 10:17 d——– C:\Documents and Settings\user 2\Application Data\U3
2007-09-30 16:15 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-09-29 13:57 d——– C:\Documents and Settings\user\hl2
2007-09-27 15:09 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-09-27 15:09 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-09-26 20:33 d——– C:\Documents and Settings\user\Application Data\Media Player Classic
2007-09-26 13:58 d——– C:\Documents and Settings\user 2\Application Data\Media Player Classic
2007-09-26 13:58 d——– C:\Documents and Settings\user 2\Application Data\DivX
2007-09-25 18:41 d——– C:\Documents and Settings\user 2\Local Settingsocal Settings
2007-09-25 18:41 d——– C:\Documents and Settings\user 1\Local Settingsocal Settings
2007-09-23 20:53 d——– C:\WINDOWS\system32\NtmsData
2007-09-20 09:47 d——– C:\Documents and Settings\user 2\it7
2007-09-20 09:45 d——– C:\Documents and Settings\user 2\english
2007-09-18 10:52 d——– C:\Documents and Settings\user\Shared
2007-09-18 08:14 d——– C:\Documents and Settings\user\Application Data\PCToolsFirewallPlus
2007-09-18 08:12 d——– C:\Program Files\PC Tools Firewall Plus
2007-09-18 08:11 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-09-18 08:11 d——– C:\Program Files\Spyware Doctor
2007-09-18 01:41 d——– C:\Documents and Settings\All Users\Application Data\Trend Micro
2007-09-18 00:53 d——– C:\Documents and Settings\user\.housecall6.6
2007-09-17 22:39 d——– C:\Program Files\SUPERAntiSpyware
2007-09-17 22:39 d——– C:\Documents and Settings\user\Application Data\SUPERAntiSpyware.com
2007-09-17 22:39 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-09-17 22:37 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-09-17 22:33 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-09-17 22:10 d——– C:\New Folder
2007-09-16 17:18 4,212 —h—– C:\WINDOWS\system32\zllictbl.dat
2007-09-16 17:18 d——– C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-09-16 17:17 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2007-09-16 17:17 d——– C:\WINDOWS\system32\ZoneLabs
2007-09-16 17:12 d——– C:\WINDOWS\Internet Logs
2007-09-16 12:35 d——– C:\Program Files\LimeWire
2007-09-15 16:45 d——– C:\Documents and Settings\user\SHAGGY
2007-09-15 14:30 d——– C:\Documents and Settings\user\Application Data\Apple Computer
2007-09-15 08:43 d——– C:\Program Files\Microsoft Expression
2007-09-15 08:19 d——– C:\Documents and Settings\Power User\Application Data\Yahoo!
2007-09-15 08:19 d——– C:\Documents and Settings\Power User\Application Data\Google
2007-09-14 22:56 d——– C:\Inetpub
2007-09-13 17:49 37,376 -ra—— C:\WINDOWS\system32\Aquarium 200.scr
2007-09-08 19:42 d——– C:\Documents and Settings\user 2\ChikkaDefault
2007-09-08 18:06 d——– C:\Documents and Settings\user\ChikkaDefault
2007-09-07 13:09 d——– C:\logs
2007-09-07 13:09 d——– C:\Documents and Settings\user 1\ChikkaDefault
2007-09-07 11:54 d——– C:\Documents and Settings\user 1\Application Data\AdobeUM
2007-09-07 11:54 d——– C:\Documents and Settings\user 1\Application Data\AdobeAUM
2007-09-07 07:05 d——– C:\Documents and Settings\user 2\Application Data\Yahoo!
2007-09-07 07:05 d——– C:\Documents and Settings\user 2\Application Data\Google
2007-09-07 07:05 d——– C:\Documents and Settings\user 1\Application Data\Corel
2007-09-07 07:04 d——– C:\Documents and Settings\user 2\Application Data\Corel
2007-09-05 16:46 d——– C:\Documents and Settings\user 1\Application Data\Yahoo!
2007-09-05 16:46 d——– C:\Documents and Settings\user 1\Application Data\Google
2007-09-05 10:07 d——– C:\Documents and Settings\user\Application Data\Google
2007-09-05 10:06 d——– C:\Documents and Settings\All Users\Application Data\Google
2007-09-05 10:05 d——– C:\Program Files\Google

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-05 01:52 1964 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2007-10-05 01:52 1244 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-10-04 23:22 ——— d——– C:\Documents and Settings\user\Application Data\LimeWire
2007-10-04 10:15 ——— d——– C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-09-18 09:58 ——— d——– C:\Program Files\Common Files\Ahead
2007-09-18 02:33 ——— d——– C:\Program Files\VDOTool
2007-09-18 02:29 ——— d——– C:\Program Files\NCT-2000-XP
2007-09-18 02:08 ——— d——– C:\Program Files\Common Files\NComputer
2007-09-18 02:07 ——— d——– C:\Program Files\Common Files\LightScribe
2007-09-18 02:02 ——— d——– C:\Program Files\Bonjour
2007-09-17 21:47 ——— d——– C:\Program Files\CakeMania_at
2007-09-16 17:58 ——— d——– C:\Program Files\mIRC
2007-09-05 12:05 ——— d–h—– C:\Documents and Settings\user\Application Data\yahoo!
2007-09-02 18:18 ——— d——– C:\Documents and Settings\All Users\Application Data\Sandlot Games
2007-09-01 08:25 ——— d——– C:\Documents and Settings\user\Application Data\Ahead
2007-08-31 23:51 ——— d——– C:\Documents and Settings\All Users\Application Data\NFS Underground
2007-08-31 23:49 ——— d——– C:\Program Files\Common Files\DirectX
2007-08-31 19:36 ——— dr-h—– C:\Documents and Settings\user\Application Data\SecuROM
2007-08-31 18:36 ——— d——– C:\Documents and Settings\user\Application Data\Command & Conquer 3 Tiberium Wars
2007-08-31 12:13 ——— d——– C:\Documents and Settings\user\Application Data\ScanSoft
2007-08-31 09:41 ——— d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-08-31 09:02 ——— d——– C:\Program Files\Yahoo!
2007-08-31 09:02 ——— d——– C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-08-31 08:40 ——— d——– C:\Program Files\Winamp
2007-08-30 18:29 ——— d——– C:\Documents and Settings\user\Application Data\Kyocera
2007-08-30 18:28 ——— d——– C:\Documents and Settings\user\Application Data\Help
2007-08-30 18:18 ——— d——– C:\Program Files\ScanSoft
2007-08-30 18:18 ——— d——– C:\Program Files\Common Files\ScanSoft Shared
2007-08-30 18:18 ——— d——– C:\Documents and Settings\All Users\Application Data\ScanSoft
2007-08-30 13:50 ——— d——– C:\Documents and Settings\user\Application Data\CyberLink
2007-08-30 09:08 ——— d——– C:\Program Files\Alwil Software
2007-08-30 07:50 ——— d——– C:\Documents and Settings\user\Application Data\DivX
2007-08-30 07:50 ——— d——– C:\Documents and Settings\All Users\Application Data\CyberLink
2007-08-30 00:59 ——— d——– C:\Documents and Settings\user\Application Data\Corel
2007-08-30 00:55 ——— d——– C:\Program Files\HandyCafe
2007-08-30 00:55 ——— d——– C:\Program Files\Borland
2007-08-30 00:37 ——— d——– C:\Program Files\EPSON
2007-08-30 00:26 ——— d——– C:\Program Files\HP
2007-08-30 00:26 ——— d——– C:\Program Files\Common Files\Hewlett-Packard
2007-08-30 00:23 43488 –a—— C:\WINDOWS\system32\drivers\AFS2K.SYS
2007-08-30 00:23 ——— d——– C:\Program Files\Common Files\HP
2007-08-30 00:04 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-30 00:04 ——— d——– C:\Program Files\Kyocera
2007-08-29 15:48 ——— d——– C:\Program Files\ASUS
2007-08-29 10:03 108144 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-08-29 10:03 ——— dr-h—– C:\Documents and Settings\Power User\Application Data\SecuROM
2007-08-28 22:03 ——— d——– C:\Program Files\TGTSoft
2007-08-28 05:15 ——— d——– C:\Program Files\THQ
2007-08-28 03:53 ——— d——– C:\Program Files\e-Games
2007-08-28 03:19 ——— d——– C:\Program Files\FreeStyle Philippines
2007-08-28 00:31 ——— d——– C:\Program Files\NtreevSoft
2007-08-28 00:09 ——— d——– C:\Documents and Settings\Power User\Application Data\Corel
2007-08-28 00:05 ——— d——– C:\Program Files\QuickTime
2007-08-28 00:05 ——— d——– C:\Program Files\Apple Software Update
2007-08-28 00:05 ——— d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-08-28 00:05 ——— d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-08-27 23:58 ——— d——– C:\Program Files\Sierra On-Line
2007-08-27 23:55 ——— d——– C:\Program Files\Corel
2007-08-27 23:55 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-27 23:55 ——— d——– C:\Program Files\Common Files\Corel
2007-08-27 23:50 ——— d——– C:\Program Files\Chikka Messenger
2007-08-27 23:40 ——— d——– C:\Program Files\K-Lite Codec Pack
2007-08-27 23:39 ——— d——– C:\Program Files\Windows Media Connect 2
2007-08-27 23:20 ——— d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-08-27 13:17 ——— d——– C:\Program Files\Common Files\Macrovision Shared
2007-08-27 12:57 ——— d——– C:\Program Files\MSBuild
2007-08-27 12:57 ——— d——– C:\Program Files\Microsoft Works
2007-08-27 12:56 ——— d——– C:\Program Files\Microsoft.NET
2007-08-27 12:55 ——— d——– C:\Program Files\Microsoft Visual Studio 8
2007-08-27 06:18 ——— d——– C:\Program Files\Microsoft Student
2007-08-27 06:16 ——— d——– C:\Program Files\Learning Essentials
2007-08-27 06:11 639224 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2007-08-27 05:32 ——— d——– C:\Program Files\CyberLink
2007-08-27 04:07 ——— d——– C:\Program Files\Futuremark
2007-08-27 03:04 ——— d——– C:\Documents and Settings\Power User\Application Data\Ahead
2007-08-27 03:03 ——— d——– C:\Program Files\Nero
2007-08-27 03:03 ——— d——– C:\Documents and Settings\All Users\Application Data\Nero
2007-08-27 02:45 197120 –a—— C:\WINDOWS\system32\barebone.scr
2007-08-27 02:27 ——— d——– C:\Program Files\Realtek
2007-08-27 02:23 ——— d——– C:\Program Files\Analog Devices
2007-08-27 02:20 ——— d——– C:\Program Files\Intel
2007-08-27 01:54 ——— d——– C:\Program Files\microsoft frontpage
2007-07-29 17:51 7680 –a—— C:\WINDOWS\system32\ff_vfw.dll
2007-07-25 15:24 1559040 –a—— C:\WINDOWS\system32\xvidcore.dll
2006-06-23 14:48 32768 -ra—— C:\WINDOWS\inf\UpdateUSB.exe
.

((((((((((((((((((((((((((((( snapshot_2007-09-25_184100.56 )))))))))))))))))))))))))))))))))))))))))
.
—-a-w 135,168 2007-09-28 01:06:08 C:\WINDOWS\catchme.exe
—-a-w 135,168 2007-09-24 14:30:28 C:\WINDOWS\system32\java.exe
—-a-w 135,168 2007-09-24 14:30:30 C:\WINDOWS\system32\javaw.exe
—-a-w 139,264 2007-09-24 15:31:42 C:\WINDOWS\system32\javaws.exe
—-a-w 206,088 2007-06-28 04:51:48 C:\WINDOWS\system32\klogon.dll
—-a-w 844,800 2007-07-22 10:39:27 C:\WINDOWS\system32\swreg.exe
—-a-w 110,360 2007-04-28 08:51:02 C:\WINDOWS\system32\drivers\kl1.sys
—-a-w 186,640 2007-06-27 09:31:58 C:\WINDOWS\system32\drivers\klif.sys
—-a-w 24,344 2007-04-04 06:58:26 C:\WINDOWS\system32\drivers\klim5.sys
—-a-w 22,457 2007-06-28 04:50:52 C:\WINDOWS\system32\drivers\klop.dat
—-a-w 213,048 2005-05-24 03:27:16 C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
—-a-w 94,208 2007-09-07 03:29:00 C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
—-a-w 946,176 2007-09-07 03:29:00 C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
—-a-w 109,056 2007-07-19 16:47:22 C:\WINDOWS\catchme.exe
—-a-w 135,168 2007-07-11 17:22:00 C:\WINDOWS\system32\java.exe
—-a-w 135,168 2007-07-11 17:22:04 C:\WINDOWS\system32\javaw.exe
—-a-w 139,264 2007-07-11 18:22:38 C:\WINDOWS\system32\javaws.exe
—-a-w 279,552 2007-07-22 10:39:27 C:\WINDOWS\system32\swreg.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-03 22:32]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 22:31]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-03 22:32]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-03 22:32]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 10:07]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-04-10 09:19]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidTool.exe" [2006-07-12 17:47]
"Gainward"="C:\Program Files\VDOTool\TBPanel.exe" [2007-06-26 14:58]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-05-11 06:03]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-05-11 06:03]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 15:10]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 22:55]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 17:28]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38]
"DXDllRegExe"="dxdllreg.exe" []
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2004-06-18 08:55]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2004-06-18 09:17]
"PPort9reminder"="C:\Program Files\ScanSoft\PaperPort\WebEreg\Ereg.exe" [2003-07-07 10:29]
"WinampAgent"="D:\Program Files\Winamp\winampa.exe" [2007-05-15 06:22]
"HpMessage"="C:\Program Files\NCT-2000-XP\KmMsg.exe" [2006-08-18 12:48]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 22:59]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-28 12:51]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-27 16:19]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 22:59]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-05 10:49]
"L08AXLRD_46486453"="C:\Program Files\Microsoft Student\Microsoft Student with Encarta Premium 2008 DVD\EDICT.exe" [2007-05-21 19:00]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 05:19:24]

C:\Documents and Settings\Power User\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-07-21 01:57:16]

C:\Documents and Settings\user\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2007-08-17 06:00:00]
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-07-21 01:57:16]

C:\Documents and Settings\user 2\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2007-08-17 06:00:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 05:19:24]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\KmWinLog]
Kmlogon.dll 2006-08-18 12:50 401408 C:\WINDOWS\system32\Kmlogon.dll

R0 HpPciVga;Multiuser PCI VGA Station Driver (MultiScreen);C:\WINDOWS\system32\drivers\KmWpsMs.sys
R0 HpStore;Multiuser Devices Control Service;C:\WINDOWS\system32\drivers\KmStore.sys
R0 HpUsbKeyboard;Multiuser USB Keyboard Class Driver;C:\WINDOWS\system32\drivers\KmKbdCls.sys
R0 HpUsbMouse;Multiuser USB Mouse Class Driver;C:\WINDOWS\system32\drivers\KmMouCls.sys
R0 JGOGO;JMicron Hot-Plug Driver;C:\WINDOWS\system32\DRIVERS\JGOGO.sys
R0 JRAID;JRAID;C:\WINDOWS\system32\DRIVERS\jraid.sys
R1 HpHelper;Multiuser User Mode Helper Driver;C:\WINDOWS\system32\drivers\KmHlprk.sys
R1 HpVcard;UTMA Video-Accelerator;C:\WINDOWS\system32\drivers\hpvcard.sys
R1 Hstd;Multiuser hstd driver;C:\WINDOWS\system32\drivers\hstd.sys
R2 HpBootSrv;Multiuser Boot Server for Miniterm;C:\Program Files\Common Files\NComputer\bootsrv.exe
R2 HpLegacyKeyboard;Multiuser Legacy Keyboard Port Driver;C:\WINDOWS\system32\drivers\KmJBox.sys
R2 TBPanel;TBPanel;C:\WINDOWS\system32\drivers\TBPanel.sys
R3 HpXpKbdPnp;Multiuser Keyboard Control Service;C:\WINDOWS\system32\drivers\KmKbdPnp.sys
R3 HpXpMouPnp;Multiuser mouse Control Service;C:\WINDOWS\system32\drivers\KmMouPnp.sys
R3 htsatran;UTSA/UTMA Virtual Transport Driver;C:\WINDOWS\system32\DRIVERS\htsatran.sys
R3 htsaudio;UTMA Virtual Audio Driver;C:\WINDOWS\system32\DRIVERS\HtsAudio.sys
R3 HtsBusEnum;UTMA Devices Enumerator;C:\WINDOWS\system32\DRIVERS\HtsBus.sys
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys
S3 Cardex;Cardex;\??\C:\WINDOWS\system32\drivers\TBPANEL.SYS
S3 HpXpHidCls;Multiuser HID Device Control Service;C:\WINDOWS\system32\drivers\KmHidCls.sys
S3 htsxhci;NComputing UTMA USB Host Controller;C:\WINDOWS\system32\DRIVERS\htsxhci.sys
S3 KMUSBSC2;KM USB Scan Svc2;C:\WINDOWS\system32\Drivers\KMUSBSC2.sys
S3 KMUSBSCN;KM USB Scan Svc;C:\WINDOWS\system32\Drivers\KMUSBSCN.sys

*Newly Created Service* - KL1
.
Contents of the 'Scheduled Tasks' folder
"2007-10-04 03:21:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-05 02:27:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-05 2:34:03
C:\ComboFix-quarantined-files.txt … 2007-10-05 02:33
C:\ComboFix2.txt … 2007-10-04 22:56
C:\ComboFix3.txt … 2007-10-04 22:41
.
— E O F —


and here is my new hjt log:

Logfile of HijackThis v1.99.1
Scan saved at 3:14:58 AM, on 10/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\VDOTool\TBPanel.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
D:\Program Files\Winamp\winampa.exe
C:\Program Files\NCT-2000-XP\KmMsg.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft Student\Microsoft Student with Encarta Premium 2008 DVD\EDICT.EXE
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Common Files\NComputer\bootsrv.exe
C:\WINDOWS\System32\KmServc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [Gainward] C:\Program Files\VDOTool\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [PPort9reminder] "C:\Program Files\ScanSoft\PaperPort\WebEreg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\9\Config\ereg.ini"
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HpMessage] C:\Program Files\NCT-2000-XP\KmMsg.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [L08AXLRD_46486453] "C:\Program Files\Microsoft Student\Microsoft Student with Encarta Premium 2008 DVD\EDICT.EXE" -m
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: KmWinLog - C:\WINDOWS\SYSTEM32\Kmlogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Multiuser Boot Server for Miniterm (HpBootSrv) - Unknown owner - C:\Program Files\Common Files\NComputer\bootsrv.exe
O23 - Service: Multiuser Service (HpService) - NComputing Co.,Ltd. - Korea - C:\WINDOWS\System32\KmServc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe


my pc is a lot faster too!!! i think the pc is already clean.
Now that we've accomplished what we set out to do, I have some advice for you to heed.

* Files like these:

E:\New Folder\kapersky?091296.key
E:\New Folder\kapersky\HARPOON.key

Delete them. No matter what anyone tells you, these sort of files are never safe.


* You would see some newly created autorun.inf folders (not files), in each of your partitions. Do not delete them. It's for your protection

* Always keep your Security programs updated.

* Always scan your pendrives before you open them.

* Don't install any programs you don't need. Before installing anything, ask yourself if the program's really needed. Many things come in easy but refuses to leave.


* Uninstall ComboFix. You don't need it anymore. This process will perform some post cleanup measures. Do this by going to to Start > Run & typing in ComboFix /u

* F_Disinfector you can keep in your pendrive. Share it with your school mates. Run it on the school's computers to clean them


Check back on this thread later. Scotti may have other instructs for you.
THANK YOU SO MUCH, sUBs!!!! :thumbup: rest assured i will share this flash disinfector at school!!! ill also share my experience with my friends!!! i did follow your advise i deleted the two files in my pendrives…. SCOTTY, thanks a lot too!!! for your time and patience… :thumbup: i would like to ask please help me on how to protect my pc from being hijacked again!!!
Hi ricric

Good to see you cleaned up. This was a real toughie. If you have already covered any of this, just move onto the next step.

This is my usual speech for when you are clean, which you appear to be.

Please follow these simple steps in order to keep your computer clean and secure:
Disable and Enable System Restore.

It's also a good idea to Flush your System Restore points after ridding yourself of malware:
  • Click Start | Help and Support | Undo changes to your computer with System Restore.
  • Click Create A Restore Point then click Next. Give it a name it and then click Create, then Close.
  • Close the Help and Support Center box.
  • Click Start | Run and type Cleanmgr
  • Select (C: ) then click OK.
  • Click the More Options tab.
  • Click Clean Up in the System Restore Section.
This will remove all previous restore points except the newly created one.

Set correct settings for files that should be hidden in Windows XP
  • Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
  • Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
  • If unchecked please checkHide protected operating system files (Recommended)
  • If necessary check "Display content of system folders"
  • If necessary Uncheck Hide file extensions for known file types.
  • Click OK
Here are some free programs, I recommend.

Install SpyWare Blaster
Download it from here
Find here the tutorial on how to use Spyware Blaster here

Install WinPatrol
Download it from here
Here you can find information about how WinPatrol works here


Make sure your Windows is ALWAYS up to date!

An unpatched Windows is vulnerable and even with the "best" Antivirus and Firewall installed, malware will find its way through.
So visit http://windowsupdate.microsoft.com/ to download and install the latest updates.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Please check out Tony Klein's article "How did I get infected in the first place?"

Here is a more in-depth look at staying protected.
http
://users.telenet.be/bluepatchy/miekiem…revention.html



Follow this list and your potential for being infected again will reduce dramatically.

Glad we were able to help.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI