This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Black Desktop says Warning Spyware Threat Detected On Yo

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have run Ad-Aware 2007 and it cannot get everything. Also running Avast and while it is catching viruses, new Trojans keep popping up. Desperate for help!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:30:15 PM, on 11/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\vvgeowbv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\regsvr32.exe
C:\WINDOWS\plite731.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SYSTEM32\tbctray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\Brmfrmps.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\BRMFRSMG.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\vvgeowbv.exe,C:\WINDOWS\system32\userinit.exe
O1 - Hosts: 194.54.90.238 google.com
O1 - Hosts: 194.54.90.238 google.ca
O1 - Hosts: 194.54.90.238 www.google.com
O1 - Hosts: 194.54.90.238 search.yahoo.com
O1 - Hosts: 194.54.90.238 search.msn.com
O1 - Hosts: 194.54.90.238 search.live.com
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl03a\BrStDvPt.exe
O4 - HKLM\..\Run: [hcdcpyfq] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\hcdcpyfq.dll"
O4 - HKLM\..\Run: [plite731] C:\WINDOWS\plite731.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\SYSTEM32\tbctray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [07d00ab8] rundll32.exe "C:\WINDOWS\system32\bxkwcjre.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\System32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\System32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O16 - DPF: {B030900C-746A-47BF-8B1D-EA3FB3395563} (CoxFastConnect20 Control) - https://fastconnect.cox.net/cd20/CoxFastConnect20.ocx
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\SYSTEM32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 4841 bytes


StartupList report, 11/4/2007, 3:28:06 PM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\vvgeowbv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\regsvr32.exe
C:\WINDOWS\plite731.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SYSTEM32\tbctray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\Brmfrmps.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\BRMFRSMG.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\vvgeowbv.exe,C:\WINDOWS\system32\userinit.exe

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]


————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

SystemTray = SysTray.Exe
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
PaperPort PTD = C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
IndexSearch = C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
SetDefPrt = C:\Program Files\Brother\Brmfl03a\BrStDvPt.exe
hcdcpyfq = regsvr32 /u "C:\Documents and Settings\All Users\Application Data\hcdcpyfq.dll"
plite731 = C:\WINDOWS\plite731.exe
avast! = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
TraySantaCruz = C:\WINDOWS\SYSTEM32\tbctray.exe
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
07d00ab8 = rundll32.exe "C:\WINDOWS\system32\bxkwcjre.dll",b

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
swg = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
=

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Task Scheduler jobs:

Tune-up Application Start.job
PCHealth Scheduler for Data Collection.job
Maintenance-Defragment programs.job
Maintenance-Disk cleanup.job
FRU Task #Hewlett-Packard#hp officejet 6100 series#1100756386.job

————————————————–

Enumerating Download Program Files:

[{0000000A-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/d/4…0367/wmavax.CAB

[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB

[{9F1C11AA-197B-4942-BA54-47A8489BB47F}]
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/…7986.3518287037

[CoxFastConnect20 Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\COXFAS~1.OCX
CODEBASE = https://fastconnect.cox.net/cd20/CoxFastConnect20.ocx

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa…ash/swflash.cab

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

UPnPMonitor: C:\WINDOWS\system32\upnpui.dll
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

————————————————–
End of report, 5,817 bytes
Report generated in 0.090 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back in your next reply.

Download and Save ComboFix
  • Download this file from below:

    Here
  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
Still have the black wallpaper on my desktop. It was tough even to get safe mode to work - the desktop would go black (except for the safe mode verbiage in the corners) after about 10 seconds. I eventually copied a shortcut to runthis.bat on the desktop and hustled to click it to get SDFix to work….

Here are my new 3 logs in order (SDFix, combofix, and Hijack)


SDFix: Version 1.113

Run by [removed] on Sun 11/04/2007 at 07:50 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
core

ImagePath:
system32\drivers\core.sys

core - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\system32\aivskurq.dll - Deleted
C:\WINDOWS\system32\drivers\core.cache.dsk - Deleted
C:\WINDOWS\system32\drivers\core.sys - Deleted
C:\WINDOWS\uninstall_nmon.vbs - Deleted



Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1253 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-04 20:04:49
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\WINDOWS\\system32\\ejabvied.exe"="C:\\WINDOWS\\system32\\eja"
"C:\\WINDOWS\\system32\\kxlugkbi.exe"="C:\\WINDOWS\\system32\\kxl"
"C:\\WINDOWS\\system32\\olpxqbva.exe"="C:\\WINDOWS\\system32\\olp"
"C:\\WINDOWS\\system32\\ishewuon.exe"="C:\\WINDOWS\\system32\\ish"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
—————

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Thu 27 Nov 2003 298 ..SH. — "C:\AUTOEXEC.BAK"
Tue 30 Jan 2001 172,099 …H. — "C:\ZZ.EXE"
Thu 30 Sep 1993 1,754 …H. — "C:\CHOICE.COM"
Wed 19 Nov 2003 1,660 ..SHR — "C:\MSDOS.BAK"
Tue 23 Oct 2007 31 A..H. — "C:\WINDOWS\uccspecc.sys"
Tue 17 Apr 2001 6,711 …H. — "C:\DELL\RUN.BAK"
Tue 30 Oct 2007 408,327 ..SH. — "C:\WINDOWS\SYSTEM32\aacdd.bak1"
Wed 31 Oct 2007 411,029 ..SH. — "C:\WINDOWS\SYSTEM32\aacdd.tmp"
Sun 4 Nov 2007 379,482 ..SH. — "C:\WINDOWS\SYSTEM32\aacdd.bak2"
Fri 28 Jan 2005 48 ..SH. — "C:\WINDOWS\DRM\v2ks.sec.bak"
Fri 28 Jan 2005 400 ..SH. — "C:\WINDOWS\DRM\v2ks.bla.bak"
Sun 4 Sep 2005 4,348 ..SH. — "C:\WINDOWS\DRM\DRMv1.bak"
Tue 4 Sep 2007 5,903,928 A..H. — "C:\Program Files\Picasa2\setup.exe"
Sun 13 Nov 2005 224 A..H. — "C:\Program Files\InterActual\InterActual Player\iti2.tmp"
Tue 3 Jul 2007 5,388,088 A..H. — "C:\System Volume Information\_restore{C9B5D03B-A011-49E3-B731-E5CD1BEC3F4D}\RP1129\A0045866.exe"
Thu 25 Oct 2007 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\8361ae28fcfac79271825a6b2935fdb6\BIT8.tmp"
Fri 28 Nov 2003 574 A..HR — "C:\Program Files\Common Files\Symantec Shared\Registry Backup\ccReg.reg"
Fri 28 Nov 2003 6,415 A..HR — "C:\Program Files\Common Files\Symantec Shared\Registry Backup\CommonClient.reg"
Wed 14 Aug 2002 8,544 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\CATC USB Ethernet\Elndis.sys"
Wed 14 Aug 2002 33,149 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\CATC USB Ethernet\Usbd.sys"
Wed 14 Aug 2002 29,628 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPICD.SYS"
Wed 14 Aug 2002 161,792 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BOOTSRV.SYS"
Wed 14 Aug 2002 202,517 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\CMDS.EXE"
Wed 14 Aug 2002 22,158 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\COUNTRY.SYS"
Wed 14 Aug 2002 1,608 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DEVICE.COM"
Wed 14 Aug 2002 15,345 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DISPLAY.SYS"
Wed 14 Aug 2002 14,160 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\HIMEM.SYS"
Wed 14 Aug 2002 10,898 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\KEYB.COM"
Wed 14 Aug 2002 53,556 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\KEYBOARD.SYS"
Wed 14 Aug 2002 15,777 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MODE.COM"
Wed 14 Aug 2002 37,681 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MOUSE.COM"
Wed 14 Aug 2002 21,180 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MSCDEX.EXE"
Wed 14 Aug 2002 8,513 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\NETBIND.COM"
Wed 14 Aug 2002 129,240 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\OHCI.EXE"
Wed 14 Aug 2002 28,439 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\Paralink.com"
Wed 14 Aug 2002 13,770 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\PROTMAN.EXE"
Wed 14 Aug 2002 130,980 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\UHCI.EXE"
Wed 14 Aug 2002 174,080 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\bootsrv16.sys"
Wed 14 Aug 2002 354,304 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\msbootsrv16.sys"
Wed 14 Aug 2002 56,821 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\E.EXE"
Wed 14 Aug 2002 354,263 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\Net.exe"
Wed 14 Aug 2002 7,840 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DLSHELP.SYS"
Wed 14 Aug 2002 374,038 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\CMDS16.EXE"
Wed 14 Aug 2002 49,242 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIOHCI.SYS"
Wed 28 May 2003 52,106 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIEHCI.SYS"
Wed 28 May 2003 51,150 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI1394.SYS"
Wed 14 Aug 2002 32,396 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\GUEST.EXE"
Wed 14 Aug 2002 50,606 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIUHCI.SYS"
Wed 14 Aug 2002 35,340 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI2DOS.SYS"
Wed 14 Aug 2002 14,378 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI4DOS.SYS"
Wed 14 Aug 2002 37,984 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI8DOS.SYS"
Wed 14 Aug 2002 17,043 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DE400 Packet\De400pd.com"
Wed 14 Aug 2002 11,491 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DMF560-TX Packet\Lmpd.com"
Wed 14 Aug 2002 17,791 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DT620 Packet\Dt620pd.com"
Wed 14 Aug 2002 11,786 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\IBM Crystal LAN Packet\Epktisa.com"
Wed 14 Aug 2002 18,300 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Kingston EtheRx KNE110TX Packet\Ktc110p.com"
Wed 14 Aug 2002 13,360 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD-CDF Packet\Ldcdt.com"
Wed 14 Aug 2002 9,190 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD-PCI2TL Packet\Ldpcil.com"
Wed 14 Aug 2002 12,567 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Melco LPC2-T\Lpchkat2.com"
Wed 14 Aug 2002 44,640 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\FETPKT.COM"
Wed 14 Aug 2002 56,896 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\Rtspkt.com"
Wed 14 Aug 2002 9,692 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\PXE Packet Driver\Undipd.com"
Wed 14 Aug 2002 32,484 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\WaveLAN Packet\Wvlan42.com"
Wed 14 Aug 2002 50,795 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom CBE10-100BTX\Cbendis.exe"
Wed 14 Aug 2002 48,223 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom CBE10-100BTX Packet\Cbepd.com"
Wed 14 Aug 2002 48,641 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet II PS\Xpsndis.exe"
Wed 14 Aug 2002 49,015 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet II PS Packet\Xpspd.com"
Wed 14 Aug 2002 33,860 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom PE3-10Bx\Pe3ndis.exe"
Wed 14 Aug 2002 50,405 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom RE10 - RE100 Packet\Ce3pd.com"
Wed 14 Aug 2002 48,491 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom RE10BT\Ce3ndis.exe"
Wed 14 Aug 2002 44,640 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FNW9x00T - ENW8300T Packet\fetpkt.com"
Wed 14 Aug 2002 52,225 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet 10-100 + Modem\Cbendis.exe"
Wed 14 Aug 2002 50,175 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Re-100Btx + Ce3B-100Btx\Ce3ndis.exe"
Wed 14 Aug 2002 12,732 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c509 Packet\3C5X9PD.COM"
Wed 14 Aug 2002 26,424 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c59x Packet\3C59XPD.COM"
Wed 14 Aug 2002 17,952 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1200 Packet\EC32PD.COM"
Wed 14 Aug 2002 29,499 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1203 Packet\PCIPD.COM"
Wed 14 Aug 2002 12,660 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1204 Packet\VLNWPD.COM"
Wed 14 Aug 2002 11,031 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207 Packet\PCIPD.COM"
Wed 14 Aug 2002 10,710 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207C Packet\PCIPD.COM"
Wed 14 Aug 2002 10,083 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207D Packet\ACCPKT.COM"
Wed 14 Aug 2002 28,062 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207F Packet\EN5251PD.COM"
Wed 14 Aug 2002 10,257 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207TX Packet\PCIPD.COM"
Wed 14 Aug 2002 9,424 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1208 Packet\1208PD.COM"
Wed 14 Aug 2002 7,463 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1625 Packet\NEPD.COM"
Wed 14 Aug 2002 13,673 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1640 Packet\NWPD.COM"
Wed 14 Aug 2002 7,825 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1651 Packet\NWPD.COM"
Wed 14 Aug 2002 7,825 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1652 Packet\NWPD.COM"
Wed 14 Aug 2002 7,825 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1650 Packet\NWPD.COM"
Wed 14 Aug 2002 7,243 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1653 Packet\NE2PD.COM"
Wed 14 Aug 2002 7,825 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1656 Packet\NWPD.COM"
Wed 14 Aug 2002 14,438 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1657 Packet\NWPD.COM"
Wed 14 Aug 2002 14,438 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1658 Packet\NWPD.COM"
Wed 14 Aug 2002 7,825 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN166X Packet\NWPD.COM"
Wed 14 Aug 2002 24,767 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2216 Packet\PCMPD.COM"
Wed 14 Aug 2002 25,460 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2218 Packet\PCMPD.COM"
Wed 14 Aug 2002 10,286 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2228 Packet\PCMPD.COM"
Wed 14 Aug 2002 28,866 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2320 Packet\EN5251PD.COM"
Wed 14 Aug 2002 11,854 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWorks ISA (DE305) Packet\DE305.COM"
Wed 14 Aug 2002 62,391 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWORKS DE500 Packet\DE500.COM"
Wed 14 Aug 2002 52,715 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWORKS DE450 Packet\DE450.COM"
Wed 14 Aug 2002 48,224 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD 10-100AL Packet\L100al.com"
Wed 14 Aug 2002 9,537 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\SN 2000p Packet\PNPPD.COM"
Wed 14 Aug 2002 65,088 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c556 Packet\3C556.COM"
Wed 14 Aug 2002 53,786 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\command.com"
Wed 14 Aug 2002 44,240 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\IBMBIO.COM"
Wed 14 Aug 2002 42,550 A..H. — "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\IBMDOS.COM"

Finished!


ComboFix 07-11-05.1 - default 2007-11-04 20:11:21.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.114 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data.\hcdcpyfq.dll
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Program Files\3721
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\Accoona
C:\Program Files\Accoona\ASearchAssist.dll
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.dat
C:\Program Files\akl\unsetup.exe
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\e-zshopper
C:\Program Files\e-zshopper\BarLcher.dll
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\aconti.exe
C:\WINDOWS\adbar.dll
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\a13
C:\WINDOWS\SYSTEM32\aacdd.bak1
C:\WINDOWS\SYSTEM32\aacdd.bak2
C:\WINDOWS\SYSTEM32\aacdd.ini
C:\WINDOWS\SYSTEM32\aacdd.ini2
C:\WINDOWS\SYSTEM32\aacdd.tmp
C:\WINDOWS\system32\bhbsawpl.dll
C:\WINDOWS\system32\ctisvshu.dll
C:\WINDOWS\system32\ddcaa.dll
C:\WINDOWS\system32\dhjxlqmb.exe
C:\WINDOWS\system32\djmmmmno.dll
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\e2
C:\WINDOWS\system32\e2\caws83122.exe
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\i8
C:\WINDOWS\system32\i8\taldrvr11.exe
C:\WINDOWS\SYSTEM32\jviqvopl.ini
C:\WINDOWS\system32\keakppni.exe
C:\WINDOWS\system32\koibotxw.dll
C:\WINDOWS\system32\lpovqivj.dll
C:\WINDOWS\SYSTEM32\lpwasbhb.ini
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\system32\mtkucxop.exe
C:\WINDOWS\system32\mvyemthq.exe
C:\WINDOWS\system32\nusrmgr.exe
C:\WINDOWS\system32\opnllml.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\ssqpnkh.dll
C:\WINDOWS\system32\tyxbdrtm.exe
C:\WINDOWS\system32\vtxslofc.exe
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\SYSTEM32\wxtobiok.ini
C:\WINDOWS\system32\x22
C:\WINDOWS\system32\x22\c124wvr.exe
C:\WINDOWS\system32\ydhrrnen.exe
C:\WINDOWS\TTC-4444.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xxxvideo.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_CORE


((((((((((((((((((((((((( Files Created from 2007-10-05 to 2007-11-05 )))))))))))))))))))))))))))))))
.

2007-11-04 20:25 19,968 –a—— C:\WINDOWS\pbar.dll
2007-11-04 20:25 16,384 –a—— C:\WINDOWS\764.exe
2007-11-04 20:20 d——– C:\Program Files\3721
2007-11-04 20:20 18,432 –a—— C:\WINDOWS\fkwggshm.exe
2007-11-04 20:18 d——– C:\Program Files\p2pnetworks
2007-11-04 20:18 d——– C:\Program Files\e-zshopper
2007-11-04 20:18 d——– C:\Program Files\amsys
2007-11-04 20:18 d——– C:\Program Files\akl
2007-11-04 20:18 d——– C:\Program Files\Accoona
2007-11-04 19:49 d——– C:\WINDOWS\ERUNT
2007-11-04 19:20 d——– C:\Program Files\Windows Defender
2007-11-04 19:08 86,080 –a—— C:\WINDOWS\SYSTEM32\hbkafwfj.dll
2007-11-04 15:24 d——– C:\Program Files\Trend Micro
2007-11-04 15:12 d–hs—- C:\FOUND.003
2007-11-01 21:36 95,608 –a—— C:\WINDOWS\SYSTEM32\AvastSS.scr
2007-11-01 21:36 42,912 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswTdi.sys
2007-11-01 21:36 26,624 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aavmker4.sys
2007-11-01 21:36 23,152 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswRdr.sys
2007-11-01 21:35 d——– C:\Program Files\Alwil Software
2007-11-01 21:35 1,060,864 –a—— C:\WINDOWS\SYSTEM32\MFC71.dll
2007-11-01 21:35 801,144 –a—— C:\WINDOWS\SYSTEM32\aswBoot.exe
2007-11-01 21:35 94,416 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswmon2.sys
2007-11-01 21:35 92,848 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswmon.sys
2007-11-01 19:59 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-01 19:57 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-31 17:29 4 –a—— C:\WINDOWS\SYSTEM32\stfv.bin
2007-10-31 09:39 d——– C:\WINDOWS\SYSTEM32\acespy
2007-10-31 09:39 30,720 –a—— C:\WINDOWS\SYSTEM32\ace16win.dll
2007-10-31 09:22 d——– C:\WINDOWS\SYSTEM32\CatRoot2
2007-10-31 09:17 12 –a—— C:\WINDOWS\SYSTEM32\dpqaqlqx.bin
2007-10-31 09:16 84,480 –a—— C:\WINDOWS\efufypyn.dll
2007-10-31 09:15 123,908 –a—— C:\WINDOWS\SYSTEM32\vvgeowbv.exe
2007-10-31 09:14 d——– C:\WINDOWS\SYSTEM32\Mz15r
2007-10-31 09:14 d——– C:\WINDOWS\PerfInfo
2007-10-31 09:14 d——– C:\Temp\mZOr
2007-10-31 09:14 308,063 –a—— C:\Temp\ocli.exe
2007-10-29 18:29 d——– C:\WINDOWS\pss
2007-10-29 18:10 3,302 –a—— C:\WINDOWS\SYSTEM32\tmp.reg
2007-10-29 18:08 288,417 –a—— C:\WINDOWS\SYSTEM32\SrchSTS.exe
2007-10-29 18:08 53,248 –a—— C:\WINDOWS\SYSTEM32\Process.exe
2007-10-29 18:08 51,200 –a—— C:\WINDOWS\SYSTEM32\dumphive.exe
2007-10-29 17:54 d——– C:\Program Files\Microsoft Easy Assist
2007-10-29 17:49 3,638 –a—— C:\info.exe
2007-10-29 17:45 d–hs—- C:\FOUND.002
2007-10-29 17:06 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-29 11:06 d——– C:\Documents and Settings\default\Application Data\CoxFastConnect20
2007-10-27 17:26 d–hs—- C:\FOUND.001
2007-10-26 06:43 d–hs—- C:\FOUND.000
2007-10-25 21:41 d——– C:\Documents and Settings\LocalService\Application Data\Talkback
2007-10-25 16:02 d——– C:\Program Files\MalwareAlarm
2007-10-24 15:17 d——– C:\Documents and Settings\default\Application Data\systemerrorfixer
2007-10-24 15:11 d——– C:\Program Files\Common Files\SystemErrorFixer
2007-10-23 16:42 d——– C:\WINDOWS\Cache
2007-10-23 16:41 d——– C:\Program Files\Coupons
2007-10-23 16:41 31 –ah—– C:\WINDOWS\uccspecc.sys
2007-10-23 12:30 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-23 12:23 d——– C:\WINDOWS\SYSTEM32\tp2
2007-10-23 12:23 d——– C:\WINDOWS\SYSTEM32\oz3
2007-10-23 12:23 d——– C:\WINDOWS\SYSTEM32\fix1
2007-10-23 12:23 d——– C:\WINDOWS\SYSTEM32\cac2
2007-10-23 12:23 d–hs—- C:\WINDOWS\R3JlZ2cgS2FsbGlzaA
2007-10-23 12:23 118,784 –a—— C:\WINDOWS\SYSTEM32\artchker.exe
2007-10-23 12:23 45,056 –a—— C:\WINDOWS\SYSTEM32\katzpusxb.exe
2007-10-23 12:23 44,922 –a—— C:\WINDOWS\SYSTEM32\IKatzuUninstall.exe
2007-10-23 12:22 294,668 –a—— C:\WINDOWS\frexup2.exe
2007-10-23 12:22 13,824 –a—— C:\WINDOWS\plite731.exe
2007-10-23 12:22 41 –a—— C:\WINDOWS\plite731_uninstaller_.bat
2007-10-10 00:37 584,192 ——— C:\WINDOWS\SYSTEM32\dllcache\rpcrt4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-05 03:19 9,728 —-a-w C:\WINDOWS\kvnab.dll
2007-11-05 03:19 9,728 —-a-w C:\WINDOWS\fhfmm-Uninstaller.exe
2007-11-05 03:19 8,960 —-a-w C:\WINDOWS\settn.dll
2007-11-05 03:19 8,192 —-a-w C:\WINDOWS\kkcomp$.exe
2007-11-05 03:19 32,256 —-a-w C:\WINDOWS\liqui.dll
2007-11-05 03:19 30,464 —-a-w C:\WINDOWS\hcwprn.exe
2007-11-05 03:19 29,696 —-a-w C:\WINDOWS\kvnab$.exe
2007-11-05 03:19 29,184 —-a-w C:\WINDOWS\liqad$.exe
2007-11-05 03:19 28,672 —-a-w C:\WINDOWS\fhfmm.exe
2007-11-05 03:19 27,392 —-a-w C:\WINDOWS\SYSTEM32\msole32.exe
2007-11-05 03:19 27,392 —-a-w C:\WINDOWS\daxtime.dll
2007-11-05 03:19 25,600 —-a-w C:\WINDOWS\kkcomp.dll
2007-11-05 03:19 24,064 —-a-w C:\WINDOWS\xadbrk.exe
2007-11-05 03:19 24,064 —-a-w C:\WINDOWS\eventlowg.dll
2007-11-05 03:19 20,736 —-a-w C:\WINDOWS\kvnab.exe
2007-11-05 03:19 18,944 —-a-w C:\WINDOWS\kkcomp.exe
2007-11-05 03:19 17,664 —-a-w C:\WINDOWS\xadbrk_.exe
2007-11-05 03:19 17,152 —-a-w C:\WINDOWS\xadbrk.dll
2007-11-05 03:19 14,336 —-a-w C:\WINDOWS\liqad.dll
2007-11-05 03:19 12,800 —-a-w C:\WINDOWS\liqui-Uninstaller.exe
2007-11-05 03:19 11,008 —-a-w C:\WINDOWS\liqui.exe
2007-11-05 03:19 10,496 —-a-w C:\WINDOWS\liqad.exe
2007-11-05 03:18 9,984 —-a-w C:\WINDOWS\SYSTEM32\vxddsk.exe
2007-11-05 03:18 9,472 —-a-w C:\WINDOWS\wbeCheck.exe
2007-11-05 03:18 9,216 —-a-w C:\WINDOWS\ngd.dll
2007-11-05 03:18 9,216 —-a-w C:\WINDOWS\iexplorr23.dll
2007-11-05 03:18 28,928 —-a-w C:\WINDOWS\ie_32.exe
2007-11-05 03:18 28,160 —-a-w C:\WINDOWS\adbar.dll
2007-11-05 03:18 27,392 —-a-w C:\WINDOWS\SYSTEM32\wml.exe
2007-11-05 03:18 26,880 —-a-w C:\WINDOWS\7search.dll
2007-11-05 03:18 23,808 —-a-w C:\WINDOWS\pbsysie.dll
2007-11-05 03:18 23,296 —-a-w C:\WINDOWS\xxxvideo.exe
2007-11-05 03:18 23,040 —-a-w C:\WINDOWS\spredirect.dll
2007-11-05 03:18 22,272 —-a-w C:\WINDOWS\flt.dll
2007-11-05 03:18 20,992 —-a-w C:\WINDOWS\cbinst$.exe
2007-11-05 03:18 20,480 —-a-w C:\WINDOWS\wml.exe
2007-11-05 03:18 19,968 —-a-w C:\WINDOWS\SYSTEM32\ESHOPEE.exe
2007-11-05 03:18 19,456 —-a-w C:\WINDOWS\vxddsk.exe
2007-11-05 03:18 19,200 —-a-w C:\WINDOWS\jd2002.dll
2007-11-05 03:18 19,200 —-a-w C:\WINDOWS\hotporn.exe
2007-11-05 03:18 15,616 —-a-w C:\WINDOWS\dp0.dll
2007-11-05 03:18 14,080 —-a-w C:\WINDOWS\wbeInst$.exe
2007-11-05 03:18 12,288 —-a-w C:\WINDOWS\aconti.exe
2007-11-05 02:21 67,264 —-a-w C:\Documents and Settings\default\Application Data\GDIPFONTCACHEV1.DAT
2007-10-25 22:55 10 —-a-w C:\Program Files\.autoreg
2007-09-13 03:06 ——— d—–w C:\Program Files\Common Files\xing shared
2007-08-22 13:12 96,256 ——w C:\WINDOWS\SYSTEM32\dllcache\inseng.dll
2007-08-22 13:12 658,944 ——w C:\WINDOWS\SYSTEM32\dllcache\wininet.dll
2007-08-22 13:12 615,424 ——w C:\WINDOWS\SYSTEM32\dllcache\urlmon.dll
2007-08-22 13:12 55,808 ——w C:\WINDOWS\SYSTEM32\dllcache\extmgr.dll
2007-08-22 13:12 532,480 ——w C:\WINDOWS\SYSTEM32\dllcache\mstime.dll
2007-08-22 13:12 474,112 ——w C:\WINDOWS\SYSTEM32\dllcache\shlwapi.dll
2007-08-22 13:12 449,024 ——w C:\WINDOWS\SYSTEM32\dllcache\mshtmled.dll
2007-08-22 13:12 39,424 ——w C:\WINDOWS\SYSTEM32\dllcache\pngfilt.dll
2007-08-22 13:12 357,888 ——w C:\WINDOWS\SYSTEM32\dllcache\dxtmsft.dll
2007-08-22 13:12 3,058,176 ——w C:\WINDOWS\SYSTEM32\dllcache\mshtml.dll
2007-08-22 13:12 251,392 ——w C:\WINDOWS\SYSTEM32\dllcache\iepeers.dll
2007-08-22 13:12 205,312 ——w C:\WINDOWS\SYSTEM32\dllcache\dxtrans.dll
2007-08-22 13:12 16,384 ——w C:\WINDOWS\SYSTEM32\dllcache\jsproxy.dll
2007-08-22 13:12 151,040 ——w C:\WINDOWS\SYSTEM32\dllcache\cdfview.dll
2007-08-22 13:12 146,432 ——w C:\WINDOWS\SYSTEM32\dllcache\msrating.dll
2007-08-22 13:12 1,494,528 ——w C:\WINDOWS\SYSTEM32\dllcache\shdocvw.dll
2007-08-22 13:12 1,054,208 ——w C:\WINDOWS\SYSTEM32\dllcache\danim.dll
2007-08-22 13:12 1,022,976 ——w C:\WINDOWS\SYSTEM32\dllcache\browseui.dll
2007-08-21 10:30 18,432 ——w C:\WINDOWS\SYSTEM32\dllcache\iedw.exe
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\SYSTEM32\inetcomm.dll
2007-08-21 06:15 683,520 ——w C:\WINDOWS\SYSTEM32\dllcache\inetcomm.dll
2003-11-20 00:34 271 –sh–w C:\Program Files\desktop.ini
2003-11-20 00:34 23,357 —h–w C:\Program Files\folder.htt
2003-11-04 01:01 75 —-a-w C:\Documents and Settings\default\Application Data\fusioncache.dat
2003-11-28 06:38:32 32 –sha-w C:\WINDOWS\SYSTEM\{D8FF86A3-9250-48E1-ABCC-E300DF59C16D}.dat
2003-11-28 06:40:22 32 –sha-w C:\WINDOWS\SYSTEM\{3B347BA0-0173-40EE-941D-2BA2207845B0}.dat
2003-11-28 06:40:22 32 –sha-w C:\WINDOWS\SYSTEM\{B063700B-25CB-471C-90E5-4990663BE9CB}.dat
2003-11-28 06:40:22 32 –sha-w C:\WINDOWS\SYSTEM\{76DD8F04-D656-4288-AF5F-8C428A74BC06}.dat
2003-11-28 06:41:30 32 –sha-w C:\WINDOWS\SYSTEM\{B1C19C69-DC88-49E0-9F6B-9E0DC53389F6}.dat
2003-11-28 06:42:12 32 –sha-w C:\WINDOWS\SYSTEM\{78233E94-8145-401C-82A6-2862152BCC27}.dat
2005-07-29 23:24:26 472 –sha-r C:\WINDOWS\R3JlZ2cgS2FsbGlzaA\laL5tZw0mZIPv35WuE.vbs
.

((((((((((((((((((((((((((((( snapshot@2007-10-29_17.30.20.56 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-10-26 16:51:18 136,192 —-a-w C:\WINDOWS\catchme.exe
+ 2007-10-30 01:56:20 136,192 —-a-w C:\WINDOWS\catchme.exe
+ 2007-11-04 01:46:50 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2007-11-05 02:49:28 5,156,864 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2007-11-05 02:49:28 12,288 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2007-11-04 01:46:50 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2007-11-05 02:49:16 5,156,864 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
+ 2007-11-05 02:49:16 12,288 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2007-11-02 03:00:18 1,038,336 —-a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC.exe
+ 2007-11-02 03:00:18 178,688 —-a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC1.exe
+ 2007-11-02 03:00:18 171,008 —-a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B.exe
+ 2007-11-02 03:00:18 8,704 —-a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B1.exe
+ 2007-10-31 16:39:12 25,088 —-a-w C:\WINDOWS\SYSTEM32\acespy\systune.exe
+ 2007-07-11 21:37:26 6,272 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\AWRTPD.sys
+ 2007-08-07 20:58:08 8,320 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\AWRTRD.sys
+ 2007-08-07 20:56:58 9,344 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\NSDriver.sys
+ 2007-04-13 22:19:52 7,680 —-a-w C:\WINDOWS\SYSTEM32\lsdelete.exe
+ 2007-10-29 02:19:52 32,768 —-a-w C:\WINDOWS\SYSTEM32\Mz15r\Mz15r2281.exe
+ 2007-11-05 03:24:04 16,384 —-a-w C:\WINDOWS\TEMP\Perflib_Perfdata_450.dat
+ 2005-09-23 06:48:08 479,232 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2005-09-23 06:48:08 548,864 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2005-09-23 06:48:06 626,688 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{93101dcc-1dd2-11b2-b66c-f7b41b76bca8}]
2007-10-31 09:16 84480 –a—— C:\WINDOWS\efufypyn.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{98ABCD8B-B460-46BD-99C7-FE3C7CB0C9EB}]
C:\Program Files\Windows Media Player\merotev4444.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A6E432B4-D4C2-43B3-BF55-C364F8F7362A}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B43AA998-2F0C-4BDA-B4ED-C6F7FE52D8F8}]
C:\Program Files\Windows Media Player\merotev83122.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bb936323-19fa-4521-ba29-eca6a121bc78}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}"= C:\Program Files\Video Add-on\ictmdl.dll [ ]

[HKEY_CLASSES_ROOT\CLSID\{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-10-06 14:16]
"nwiz"="nwiz.exe" [2003-10-06 14:16 C:\WINDOWS\SYSTEM32\nwiz.exe]
"PaperPort PTD"="C:\Program Files\Scansoft\PaperPort\pptd40nt.exe" [2002-08-12 09:33]
"IndexSearch"="C:\Program Files\Scansoft\PaperPort\IndexSearch.exe" [2002-08-12 10:07]
"SetDefPrt"="C:\Program Files\Brother\Brmfl03a\BrStDvPt.exe" [2003-07-03 15:31]
"plite731"="C:\WINDOWS\plite731.exe" [2007-10-23 12:22]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 03:06]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-04 16:20]
"07d00ab8"="C:\WINDOWS\system32\hbkafwfj.dll" [2007-11-04 19:08]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"TraySantaCruz"="C:\WINDOWS\SYSTEM32\tbctray.exe" [2002-04-03 15:47]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-05 04:18]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"Printing Migration"=rundll32.exe C:\WINDOWS\System32\spool\migrate.dll,ProcessWin9xNetworkPrinters

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\\WINDOWS\\system32\\vvgeowbv.exe,C:\\WINDOWS\\system32\\userinit.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"="lsass.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\ddcaa.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
backup=C:\WINDOWS\pss\hpoddt01.exe.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^officejet 6100.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\officejet 6100.lnk
backup=C:\WINDOWS\pss\officejet 6100.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CheckWinPerf]
C:\DOCUME~1\default\LOCALS~1\Temp\poewmekwr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\plite731]
C:\WINDOWS\plite731.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
"C:\Program Files\Realplayer\realplay.exe" /RunUPGToolCommandReBoot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"POINTER"=C:\Program Files\Microsoft Hardware\Mouse\point32.exe
"TCASUTIEXE"=TCAUDIAG -off
"LTWinModem1"=ltmsg.exe 9
"LoadQM"=loadqm.exe
"LexmarkPrinTray"=PrinTray.exe
"Share-to-Web Namespace Daemon"=C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
"IST Service"=C:\Program Files\ISTsvc\istsvc.exe
"ClrSchLoader"=\Program Files\ClearSearch\Loader.exe
"WhenUSave"=C:\Program Files\Save\Save.exe
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
"ccRegVfy"="C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
"GhostStartTrayApp"=C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
"NPROTECT"=C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVCPL.DLL,NvStartup
"nwiz"=nwiz.exe /install
"TraySantaCruz"=C:\WINDOWS\SYSTEM32\TBCTRAY.EXE

R3 brfilt;Brother MFC Filter Driver;C:\WINDOWS\system32\Drivers\Brfilt.sys
R3 BrSerWDM;Brother WDM Serial driver;C:\WINDOWS\system32\Drivers\BrSerWdm.sys
R3 BrUsbMdm;Brother MFC USB Fax Only Modem;C:\WINDOWS\system32\Drivers\BrUsbMdm.sys
R3 BrUsbScn;Brother MFC USB Scanner driver;C:\WINDOWS\system32\Drivers\BrUsbScn.sys
R3 tbcspud;Santa Cruz Driver;C:\WINDOWS\system32\drivers\tbcspud.sys
R3 tbcwdm;Santa Cruz WDM Driver;C:\WINDOWS\system32\drivers\tbcwdm.sys
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S3 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe"
S3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
S3 WmHidLo;Logitech WingMan USB Filter Driver;C:\WINDOWS\system32\drivers\WmHidLo.sys
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\^RNA]
rundll rnasetup.dll,installoptionalcomponent rna

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:WIN9X /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
C:\WINDOWS\SYSTEM32\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl
.
Contents of the 'Scheduled Tasks' folder
"2007-10-07 06:00:02 C:\WINDOWS\Tasks\Tune-up Application Start.job"
"2007-11-05 03:15:06 C:\WINDOWS\Tasks\PCHealth Scheduler for Data Collection.job"
"2007-10-31 08:00:02 C:\WINDOWS\Tasks\Maintenance-Defragment programs.job"
"2007-10-22 08:30:02 C:\WINDOWS\Tasks\Maintenance-Disk cleanup.job"
- C:\WINDOWS\CLEANMGR.EXE
"2005-06-09 17:26:02 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1100756386.job"
"2007-11-05 03:05:36 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-04 20:25:27
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-04 20:26:58 - machine was rebooted
C:\ComboFix2.txt … 2007-10-29 17:36
.
— E O F —


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:28:02 PM, on 11/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\vvgeowbv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\SYSTEM32\Brmfrmps.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\BRMFRSMG.EXE
C:\WINDOWS\plite731.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\SYSTEM32\tbctray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: (no name) - {93101dcc-1dd2-11b2-b66c-f7b41b76bca8} - C:\WINDOWS\efufypyn.dll
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {98ABCD8B-B460-46BD-99C7-FE3C7CB0C9EB} - C:\Program Files\Windows Media Player\merotev4444.dll (file missing)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: (no name) - {A6E432B4-D4C2-43B3-BF55-C364F8F7362A} - (no file)
O2 - BHO: (no name) - {B43AA998-2F0C-4BDA-B4ED-C6F7FE52D8F8} - C:\Program Files\Windows Media Player\merotev83122.dll (file missing)
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file)
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl03a\BrStDvPt.exe
O4 - HKLM\..\Run: [plite731] C:\WINDOWS\plite731.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [07d00ab8] rundll32.exe "C:\WINDOWS\system32\hbkafwfj.dll",b
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\SYSTEM32\tbctray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\System32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\System32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O16 - DPF: {B030900C-746A-47BF-8B1D-EA3FB3395563} (CoxFastConnect20 Control) - https://fastconnect.cox.net/cd20/CoxFastConnect20.ocx
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\SYSTEM32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 6665 bytes
Hi

This one is a mess. :o


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\pbar.dll 
C:\WINDOWS\764.exe
C:\WINDOWS\fkwggshm.exe
C:\WINDOWS\SYSTEM32\hbkafwfj.dll
C:\FOUND.003
C:\WINDOWS\SYSTEM32\stfv.bin
C:\WINDOWS\SYSTEM32\ace16win.dll
C:\WINDOWS\SYSTEM32\dpqaqlqx.bin
C:\WINDOWS\efufypyn.dll
C:\WINDOWS\SYSTEM32\vvgeowbv.exe
C:\WINDOWS\SYSTEM32\Mz15r
C:\Temp\mZOr
C:\Temp\ocli.exe
C:\info.exe
C:\FOUND.002
C:\FOUND.001
C:\FOUND.000
C:\WINDOWS\uccspecc.sys
C:\WINDOWS\SYSTEM32\tp2
C:\WINDOWS\SYSTEM32\oz3
C:\WINDOWS\SYSTEM32\fix1
C:\WINDOWS\SYSTEM32\cac2
C:\WINDOWS\SYSTEM32\artchker.exe
C:\WINDOWS\SYSTEM32\katzpusxb.exe
C:\WINDOWS\SYSTEM32\IKatzuUninstall.exe
C:\WINDOWS\frexup2.exe
C:\WINDOWS\plite731.exe
C:\WINDOWS\plite731_uninstaller_.bat
C:\WINDOWS\kvnab.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\settn.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\SYSTEM32\msole32.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.exe
C:\WINDOWS\liqad.exe
C:\WINDOWS\SYSTEM32\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\ie_32.exe
C:\WINDOWS\adbar.dll
C:\WINDOWS\SYSTEM32\wml.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\xxxvideo.exe
C:\WINDOWS\spredirect.dll
C:\WINDOWS\flt.dll
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\SYSTEM32\ESHOPEE.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\jd2002.dll
C:\WINDOWS\hotporn.exe
C:\WINDOWS\dp0.dll
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\aconti.exe
C:\WINDOWS\SYSTEM\{D8FF86A3-9250-48E1-ABCC-E300DF59C16D}.dat
C:\WINDOWS\SYSTEM\{3B347BA0-0173-40EE-941D-2BA2207845B0}.dat
C:\WINDOWS\SYSTEM\{B063700B-25CB-471C-90E5-4990663BE9CB}.dat
C:\WINDOWS\SYSTEM\{76DD8F04-D656-4288-AF5F-8C428A74BC06}.dat
C:\WINDOWS\SYSTEM\{B1C19C69-DC88-49E0-9F6B-9E0DC53389F6}.dat
C:\WINDOWS\SYSTEM\{78233E94-8145-401C-82A6-2862152BCC27}.dat
C:\WINDOWS\R3JlZ2cgS2FsbGlzaA\laL5tZw0mZIPv35WuE.vbs
C:\WINDOWS\efufypyn.dll
C:\Program Files\Windows Media Player\merotev4444.dll
C:\DOCUME~1\default\LOCALS~1\Temp\poewmekwr.exe

Folder::
C:\Program Files\p2pnetworks
C:\Program Files\e-zshopper
C:\Program Files\amsys
C:\Program Files\akl
C:\Program Files\Accoona
C:\WINDOWS\SYSTEM32\acespy
C:\Program Files\MalwareAlarm
C:\Documents and Settings\default\Application Data\systemerrorfixer
C:\Program Files\Common Files\SystemErrorFixer
C:\Program Files\Coupons
C:\WINDOWS\R3JlZ2cgS2FsbGlzaA
C:\WINDOWS\SYSTEM32\Mz15r
C:\Program Files\Video Add-on
C:\Program Files\ISTsvc
C:\Program Files\ClearSearch
C:\Program Files\Save

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{93101dcc-1dd2-11b2-b66c-f7b41b76bca8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{98ABCD8B-B460-46BD-99C7-FE3C7CB0C9EB}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A6E432B4-D4C2-43B3-BF55-C364F8F7362A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B43AA998-2F0C-4BDA-B4ED-C6F7FE52D8F8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bb936323-19fa-4521-ba29-eca6a121bc78}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}"=-
[-HKEY_CLASSES_ROOT\CLSID\{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"plite731"=-
"07d00ab8"=-
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CheckWinPerf]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\plite731]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"IST Service"=-
"ClrSchLoader"=-
"WhenUSave"=-

DirLook::
C:\Program Files\desktop.ini
C:\Program Files\folder.htt

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.
You couldn't be more correct - it is a mess! I won't be able to do this until this evening (or maybe even tomorrow night)… When I copy the text file into combofix, does the program start working automatically, or will I have to launch it myself? Really appreciate all your help!!!! :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI