This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

my computer is highly infected and i've done all i can but use hij

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ok so first of all my computer is running really, i keep getting pop ups for stuff like ad-ware removal and same with spyware, malware, trojan's, and varitie's of other viruses. i've use other applications to remove them but i'm not getting them all with app's such as spy-bot search and destroy. ad-aware se personal and other's i can't think of at the top of my head… but my problem is i have all these pop up's of spy-ware remover, ad-ware remover, mal-ware remover, the "best" anti virus program there is, and my computer is telling me that i have a back door trojan. i've done a scan with hijackthis and here is the log. if someone can help me fix my computer i would greatly appreciate it.



Logfile of HijackThis v1.99.1
Scan saved at 8:26:45 AM, on 11/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Video Add-on\icthis.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\Program Files\Common Files\AOL\1126962645\ee\AOLSoftware.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\windows\system32\zbndyevnu.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Creative\ShareDLL\MEDIADET.EXE
C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe
C:\Program Files\Microsoft Money\System\Money Express.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\TimeLeft3\TimeLeft.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\a-squared Free\a2service.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Tabitha\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: IE Custom Tools - {6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16} - C:\Program Files\Video Add-on\ictmdl.dll
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1126962645\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Startup: TimeLeft.lnk = C:\Program Files\TimeLeft3\TimeLeft.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm117YYUS
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - C:\Program Files\TimeLeft3\TLIntergIE.html (HKCU)
O9 - Extra 'Tools' menuitem: Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - C:\Program Files\TimeLeft3\TLIntergIE.html (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAcc…e/bridge-c6.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/zenpuzzlegarden/mi…pGameLoader.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1114888937327
O16 - DPF: {6AA85413-165C-4200-8154-71166077B22E} - http://scripts.downloadv3.com/binaries/IA/…svc32_EN_XP.cab
O16 - DPF: {71CBDCD9-0830-4470-A890-35D364DA352C} - http://scripts.downloadv3.com/binaries/P2E…_1047_EN_XP.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8B3B8135-9DAA-40E7-8941-962795F9C1CB} - http://scripts.downloadv3.com/binaries/IA/…svc32_EN_XP.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v61/swapit/swapit.cab
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - http://www.worldwinner.com/games/v40/hangman/hangman.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BD3653E4-884B-43C4-970B-670802501B7F} - http://akamai.downloadv3.com/binaries/P2EC…_1043_EN_XP.cab
O16 - DPF: {D68217F4-1DF9-45C1-BFA6-61DBD5464527} (Genealogy Browser) - http://66.119.139.74/cabs/zinst.cab
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} - http://static.zangocash.com/cab/Zango/ie/b…e55e39bbcd1b030
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

oh yeah and a few more things to add to this… i can't access any type of e-mail on my computer it'll keep saying thing's like "this page can not be displayed.", and also two pop up's are program downloads
Howdy theirishguy,

Welcome to WTT. The log shows as least a Zango ActiveX installer there, so let's start repairs here.

Be sure to temporarily disable any protective software when running the scan tools we use here.


Download ComboFix.exe from here to your desktop, and click the downloaded file to run the repair.

When the command window opens, select 1 (and Enter). Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt.

A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

Post back the C:\ComboFix.txt log as well as a new HijackThis log please.
ComboFix 07-11-08.1 - Tabitha 2007-11-08 6:20:05.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.177 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Local Settings\Temporary Internet Files\Content.IE5\OHE3C9QN\ComboFix[1].exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\livestream
C:\Program Files\livestream\img\p2e_1_3.bmp
C:\Program Files\livestream\img\p2e_2_3.bmp
C:\Program Files\livestream\img\p2e_3_3.bmp
C:\Program Files\livestream\img\p2e_go_3.bmp
C:\Program Files\livestream\img\p2e_logo_2.bmp
C:\Program Files\livestream\img\Thumbs.db
C:\Program Files\livestream\p2e\p2e_1.206.1.htm
C:\Program Files\livestream\p2e\p2eredir.htm
C:\WINDOWS\Downloaded Program Files.\egauth.inf
C:\WINDOWS\Downloaded Program Files.\sysiasvc32.inf
C:\WINDOWS\Downloaded Program Files.\syswbsvc32.inf
C:\WINDOWS\msskinner
C:\WINDOWS\system32\zbndyevnu.dat
C:\WINDOWS\system32\zbndyevnu.exe
C:\WINDOWS\system32\zbndyevnu_nav.dat
C:\WINDOWS\system32\zbndyevnu_navps.dat
C:\WINDOWS\tmlpcert2005
C:\WINDOWS\tmlpcert2007

.
((((((((((((((((((((((((( Files Created from 2007-10-08 to 2007-11-08 )))))))))))))))))))))))))))))))
.

2007-11-08 06:18 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-31 06:13 d——– C:\Program Files\a-squared Free
2007-10-29 08:42 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-10-29 08:32 d——– C:\Program Files\Video Add-on
2007-10-29 08:06 d——– C:\Program Files\Onyx
2007-10-24 14:36 d——– C:\Documents and Settings\Tabitha\Application Data\OpenOffice.org2
2007-10-24 14:29 d——– C:\Program Files\OpenOffice.org 2.3
2007-10-24 14:01 1,613,824 –a—— C:\WINDOWS\system32\cdintf250.dll
2007-10-24 14:00 d——– C:\Program Files\Common Files\Palo Alto Software
2007-10-24 14:00 d——– C:\Program Files\Common Files\Intuit
2007-10-24 13:59 d——– C:\Program Files\Quicken
2007-10-24 13:59 d——– C:\Documents and Settings\Tabitha\Application Data\Intuit
2007-10-24 13:59 d——– C:\Documents and Settings\All Users\Application Data\Intuit
2007-10-24 09:19 d——– C:\Recovered
2007-10-24 09:19 d——– C:\Documents and Settings\Tabitha\Application Data\Temp
2007-10-24 09:18 d——– C:\Program Files\TPRecDT
2007-10-24 09:18 d——– C:\Program Files\Manual
2007-10-20 22:40 d——– C:\Documents and Settings\Tabitha\Application Data\PlayFirst
2007-10-20 22:40 d——– C:\Documents and Settings\All Users\Application Data\PlayFirst
2007-10-19 05:45 d——– C:\Documents and Settings\Tabitha\Application Data\TuneUp Software
2007-10-19 05:44 d——– C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-10-19 05:44 29,704 –a—— C:\WINDOWS\system32\uxtuneup.dll
2007-10-19 05:42 d——– C:\Program Files\TuneUp Utilities 2007
2007-10-19 05:39 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-18 02:04 128,896 —–c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2007-10-18 02:04 23,040 —–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2007-10-18 02:04 16,896 —–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2007-10-17 19:09 dr-h—– C:\Documents and Settings\Tabitha\Application Data\SecuROM
2007-10-17 19:09 108,144 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-10-17 18:25 442,368 -ra—— C:\WINDOWS\system32\vp6vfw.dll
2007-10-17 17:18 d——– C:\Program Files\Common Files\xing shared
2007-10-17 17:16 d——– C:\Program Files\Google
2007-10-17 15:20 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-16 18:48 d——– C:\Program Files\WinMX Music
2007-10-16 13:21 d——– C:\Documents and Settings\Tabitha\Application Data\AVG7
2007-10-16 13:19 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-16 13:19 d——– C:\Documents and Settings\All Users\Application Data\avg7
2007-10-16 13:08 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-03 12:19 ——— d—–w C:\Program Files\Symantec
2007-11-03 12:19 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-03 12:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-01 17:07 ——— d—–w C:\Documents and Settings\Tabitha\Application Data\WeatherBug
2007-10-31 15:09 ——— d—–w C:\Program Files\CompuServe 7.0
2007-10-30 22:22 ——— d—–w C:\Program Files\Plaxo
2007-10-30 00:32 955,014 —-a-w C:\Program Files\Temp.BMP
2007-10-29 20:30 ——— d—–w C:\Program Files\Free Offers from Freeze.com
2007-10-27 01:27 ——— d—–w C:\Program Files\IncrediMail
2007-10-25 11:43 ——— d—–w C:\Program Files\Microsoft Works
2007-10-24 20:28 ——— d—–w C:\Program Files\Java
2007-10-24 15:35 3,750 —-a-w C:\Program Files\tempy.bmp
2007-10-21 04:40 ——— d—–w C:\Program Files\Yahoo! Games
2007-10-17 23:18 ——— d—–w C:\Program Files\Common Files\Real
2007-10-17 23:17 ——— d—–w C:\Program Files\Common Files\csshare
2007-10-17 06:04 ——— d—–w C:\Program Files\WB01d2se
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2005-05-05 21:32 774,144 —-a-w C:\Program Files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}"= C:\Program Files\Video Add-on\ictmdl.dll [2007-10-29 08:34 79360]

[HKEY_CLASSES_ROOT\CLSID\{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}"= C:\Program Files\Video Add-on\ictmdl.dll [2007-10-29 08:34 79360]

[HKEY_CLASSES_ROOT\CLSID\{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXSUPMON"="C:\WINDOWS\System32\LXSUPMON.exe" [2002-01-28 06:48]
"HostManager"="C:\Program Files\Common Files\AOL\1126962645\ee\AOLSoftware.exe" [2005-11-02 21:01]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-09-28 22:40]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-06-14 17:32]
"Disc Detector"="C:\Program Files\Creative\ShareDLL\CtNotify.exe" [1998-12-16 00:53]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-17 17:17]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-29 08:41]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2004-09-09 16:35]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-07-13 14:00]
"Aim6"="C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" [2005-11-02 21:01]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [2005-12-08 13:55]
"PlaxoUpdate"="C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe" [2005-11-15 14:55]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\Money Express.exe" [2001-07-25 11:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-22 05:16]

C:\Documents and Settings\Tabitha\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 21:57:56]
TimeLeft.lnk - C:\Program Files\TimeLeft3\TimeLeft.exe [2006-02-22 15:07:08]


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

*Newly Created Service* - A2FREE
*Newly Created Service* - APPMGMT
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-11-02 22:17:37 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2005-04-30 21:11:08 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-08 06:42:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Disc Detector = C:\Program Files\Creative\ShareDLL\CtNotify.exe?X?????????????????B?????Disc Detector?B???A???????A?@ ????B???@???@???B???????@?????????0?B???A???????A?? ????B???@?????P?????@?P ????????A~??????????@???????????????????B?????? ????????????????????????????B

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-08 6:45:57
.
— E O F —

hijackthis log




Logfile of HijackThis v1.99.1
Scan saved at 6:53:10 AM, on 11/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Video Add-on\icthis.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\Program Files\Common Files\AOL\1126962645\ee\AOLSoftware.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Creative\ShareDLL\MEDIADET.EXE
C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe
C:\Program Files\Microsoft Money\System\Money Express.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\TimeLeft3\TimeLeft.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\a-squared Free\a2service.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: IE Custom Tools - {6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16} - C:\Program Files\Video Add-on\ictmdl.dll
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1126962645\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Startup: TimeLeft.lnk = C:\Program Files\TimeLeft3\TimeLeft.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm117YYUS
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - C:\Program Files\TimeLeft3\TLIntergIE.html (HKCU)
O9 - Extra 'Tools' menuitem: Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - C:\Program Files\TimeLeft3\TLIntergIE.html (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAcc…e/bridge-c6.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/zenpuzzlegarden/mi…pGameLoader.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1114888937327
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v61/swapit/swapit.cab
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - http://www.worldwinner.com/games/v40/hangman/hangman.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {D68217F4-1DF9-45C1-BFA6-61DBD5464527} (Genealogy Browser) - http://66.119.139.74/cabs/zinst.cab
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} - http://static.zangocash.com/cab/Zango/ie/b…e55e39bbcd1b030
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Looks like ComboFix located and removed some Navipromo rootkit, which is often difficult to locate.



Go to Start – Settings – Control Panel. Click on Add/Remove Programs. If any of the following programs are listed there, click on the program to highlight it, and click on Remove. Then close the Control Panel.

My Way/MyWebSearch/My Search
Freeze.com (any listings or screensavers from this software)


———————————

Open Notepad (Start - Run, type notepad and press Enter) and copy/paste the following text into the Notepad textbox:

Folder::
C:\Program Files\Video Add-on
C:\Program Files\Free Offers from Freeze.com
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}"=-
[-HKEY_CLASSES_ROOT\CLSID\{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}"=-
[-HKEY_CLASSES_ROOT\CLSID\{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}]
DirLook::
C:\Program Files\WB01d2se

Save this as "CFScript"

(include the "quotation marks" with the name)


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe


ComboFix will now run as it did before. When the command window opens, select 1 (and Enter). Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt.

A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

————————————

Go here and run the Kaspersky online scan, and post back the log it creates (it requires IE).

To use the scan, once the download has completed click Scan Settings, then make sure the "extended option" is checked (leave all others as they are) and click OK. Then click My Computer to begin the scan. Save the Report as a text file and post that back here.


To save it as a text file, still with the page in Internet Explorer, go to the top of the page and select File - Save As… Then make sure in the "Save as type" drop down you change it to "Text File(*.txt)".


Then post back a new HijackThis log, along with the combofix.txt log and the Kaspersky log please.
ComboFix 07-11-08.1 - Tabitha 2007-11-08 18:03:55.2 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tabitha\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Free Offers from Freeze.com
C:\Program Files\Free Offers from Freeze.com\FREE_Ringtone_or_Wallpaper1.ico
C:\Program Files\Free Offers from Freeze.com\FREE_Ringtone_or_Wallpaper1.url
C:\Program Files\Free Offers from Freeze.com\graflatscreen.ico
C:\Program Files\Free Offers from Freeze.com\graflatscreen.url
C:\Program Files\Free Offers from Freeze.com\mcc.ico
C:\Program Files\Free Offers from Freeze.com\mcc.url
C:\Program Files\Free Offers from Freeze.com\wfallsaw.url
C:\Program Files\Video Add-on
C:\Program Files\Video Add-on\icthis.exe
C:\Program Files\Video Add-on\ictmdl.dll
C:\Program Files\Video Add-on\ot.ico
C:\Program Files\Video Add-on\ts.ico
C:\WINDOWS\system32\msclock32.dll
C:\WINDOWS\system32\msplock32.dll

.
((((((((((((((((((((((((( Files Created from 2007-10-09 to 2007-11-09 )))))))))))))))))))))))))))))))
.

2007-11-08 06:18 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-31 06:13 d——– C:\Program Files\a-squared Free
2007-10-29 08:42 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-10-29 08:06 d——– C:\Program Files\Onyx
2007-10-24 14:36 d——– C:\Documents and Settings\Tabitha\Application Data\OpenOffice.org2
2007-10-24 14:29 d——– C:\Program Files\OpenOffice.org 2.3
2007-10-24 14:01 1,613,824 –a—— C:\WINDOWS\system32\cdintf250.dll
2007-10-24 14:00 d——– C:\Program Files\Common Files\Palo Alto Software
2007-10-24 14:00 d——– C:\Program Files\Common Files\Intuit
2007-10-24 13:59 d——– C:\Program Files\Quicken
2007-10-24 13:59 d——– C:\Documents and Settings\Tabitha\Application Data\Intuit
2007-10-24 13:59 d——– C:\Documents and Settings\All Users\Application Data\Intuit
2007-10-24 09:19 d——– C:\Recovered
2007-10-24 09:19 d——– C:\Documents and Settings\Tabitha\Application Data\Temp
2007-10-24 09:18 d——– C:\Program Files\TPRecDT
2007-10-24 09:18 d——– C:\Program Files\Manual
2007-10-20 22:40 d——– C:\Documents and Settings\Tabitha\Application Data\PlayFirst
2007-10-20 22:40 d——– C:\Documents and Settings\All Users\Application Data\PlayFirst
2007-10-19 05:45 d——– C:\Documents and Settings\Tabitha\Application Data\TuneUp Software
2007-10-19 05:44 d——– C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-10-19 05:44 29,704 –a—— C:\WINDOWS\system32\uxtuneup.dll
2007-10-19 05:42 d——– C:\Program Files\TuneUp Utilities 2007
2007-10-19 05:39 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-18 02:04 128,896 —–c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2007-10-18 02:04 23,040 —–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2007-10-18 02:04 16,896 —–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2007-10-17 19:09 dr-h—– C:\Documents and Settings\Tabitha\Application Data\SecuROM
2007-10-17 19:09 108,144 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-10-17 18:25 442,368 -ra—— C:\WINDOWS\system32\vp6vfw.dll
2007-10-17 17:18 d——– C:\Program Files\Common Files\xing shared
2007-10-17 17:16 d——– C:\Program Files\Google
2007-10-17 15:20 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-16 18:48 d——– C:\Program Files\WinMX Music
2007-10-16 13:21 d——– C:\Documents and Settings\Tabitha\Application Data\AVG7
2007-10-16 13:19 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-16 13:19 d——– C:\Documents and Settings\All Users\Application Data\avg7
2007-10-16 13:08 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-03 12:19 ——— d—–w C:\Program Files\Symantec
2007-11-03 12:19 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-03 12:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-01 17:07 ——— d—–w C:\Documents and Settings\Tabitha\Application Data\WeatherBug
2007-10-31 15:09 ——— d—–w C:\Program Files\CompuServe 7.0
2007-10-30 22:22 ——— d—–w C:\Program Files\Plaxo
2007-10-30 00:32 955,014 —-a-w C:\Program Files\Temp.BMP
2007-10-27 01:27 ——— d—–w C:\Program Files\IncrediMail
2007-10-25 11:43 ——— d—–w C:\Program Files\Microsoft Works
2007-10-24 20:28 ——— d—–w C:\Program Files\Java
2007-10-24 15:35 3,750 —-a-w C:\Program Files\tempy.bmp
2007-10-21 04:40 ——— d—–w C:\Program Files\Yahoo! Games
2007-10-17 23:18 ——— d—–w C:\Program Files\Common Files\Real
2007-10-17 23:17 ——— d—–w C:\Program Files\Common Files\csshare
2007-10-17 06:04 ——— d—–w C:\Program Files\WB01d2se
2005-05-05 21:32 774,144 —-a-w C:\Program Files\RngInterstitial.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Program Files\WB01d2se —-

2007-11-03 05:54 284672 –ahs—- C:\Program Files\WB01d2se\Download\Thumbs.db
2007-10-17 00:04 83 –a—— C:\Program Files\WB01d2se\Hilite.dat
2007-10-17 00:04 394 –a—— C:\Program Files\WB01d2se\Wb01d2sr.ini
2007-10-17 00:04 2 –a—— C:\Program Files\WB01d2se\Sticky.nte
2006-06-02 15:51 25243648 –a—— C:\Program Files\WB01d2se\Wb01d2.mdb
2006-06-02 15:34 23981 –a—— C:\Program Files\WB01d2se\Uninst.isu
2000-08-17 11:05 286720 –a—— C:\Program Files\WB01d2se\Notepad.exe
2000-08-17 11:01 4100096 –a—— C:\Program Files\WB01d2se\wb01d2sr.exe
2000-08-17 05:37 1658880 -ra—— C:\Program Files\WB01d2se\wb_res2.dll
2000-08-11 13:42 30214 –a—— C:\Program Files\WB01d2se\Readme.txt
2000-08-07 08:47 849 –a—— C:\Program Files\WB01d2se\Jlookcd1.ndx
2000-08-07 08:47 24 –a—— C:\Program Files\WB01d2se\Jlookcd2.ndx
2000-08-04 12:24 5940 –a—— C:\Program Files\WB01d2se\Jlookcd2.dat
2000-08-04 12:24 315919 –a—— C:\Program Files\WB01d2se\Jlookcd1.dat
2000-08-01 12:02 854688 –a—— C:\Program Files\WB01d2se\Titlelnk.dat
2000-07-27 16:17 3625 –a—— C:\Program Files\WB01d2se\Jlshow.ndx
2000-07-27 15:54 15379 -r——- C:\Program Files\WB01d2se\Download\YB201902.rcv
2000-07-27 15:54 15129 -r——- C:\Program Files\WB01d2se\Download\YB201911.rcv
2000-07-27 15:54 15129 -r——- C:\Program Files\WB01d2se\Download\YB200911.rcv
2000-07-27 15:54 14490 -r——- C:\Program Files\WB01d2se\Download\YB201906.rcv
2000-07-27 15:54 14277 -r——- C:\Program Files\WB01d2se\Download\YB201901.rcv
2000-07-27 15:54 14083 -r——- C:\Program Files\WB01d2se\Download\YB201909.rcv
2000-07-27 15:54 14083 -r——- C:\Program Files\WB01d2se\Download\YB200909.rcv
2000-07-27 15:54 13976 -r——- C:\Program Files\WB01d2se\Download\YB201907.rcv
2000-07-27 15:54 13976 -r——- C:\Program Files\WB01d2se\Download\YB200907.rcv
2000-07-27 15:54 13920 -r——- C:\Program Files\WB01d2se\Download\YB201908.rcv
2000-07-27 15:54 13920 -r——- C:\Program Files\WB01d2se\Download\YB200908.rcv
2000-07-27 15:54 13755 -r——- C:\Program Files\WB01d2se\Download\YB201912.rcv
2000-07-27 15:54 13755 -r——- C:\Program Files\WB01d2se\Download\YB200912.rcv
2000-07-27 15:54 12905 -r——- C:\Program Files\WB01d2se\Download\YB201910.rcv
2000-07-27 15:54 12905 -r——- C:\Program Files\WB01d2se\Download\YB200910.rcv
2000-07-27 15:54 12818 -r——- C:\Program Files\WB01d2se\Download\YB201905.rcv
2000-07-27 15:54 12389 -r——- C:\Program Files\WB01d2se\Download\YB201904.rcv
2000-07-27 15:54 11798 -r——- C:\Program Files\WB01d2se\Download\YB201903.rcv
2000-07-27 15:52 966050 –a—— C:\Program Files\WB01d2se\Jlshow.dat
2000-07-26 20:14 18365 –a—— C:\Program Files\WB01d2se\Download\mb200003.003
2000-06-28 18:21 36864 –a—— C:\Program Files\WB01d2se\Wbuninst.exe
2000-06-24 00:10 473548 –a—— C:\Program Files\WB01d2se\wb01d2sr.hlp
2000-05-22 15:11 12535 –a—— C:\Program Files\WB01d2se\Download\pc306076.gif
2000-05-22 14:57 18179 –a—— C:\Program Files\WB01d2se\Download\mb200004.001
2000-04-18 18:30 13742 –a—— C:\Program Files\WB01d2se\Download\pc305887.gif
2000-03-16 15:09 15712 –a—— C:\Program Files\WB01d2se\Download\mb200002.001
2000-03-16 15:06 14821 –a—— C:\Program Files\WB01d2se\Download\pc305543.gif
2000-02-11 15:58 23082 –a—— C:\Program Files\WB01d2se\Download\mb200001.001
2000-02-11 15:51 11815 –a—— C:\Program Files\WB01d2se\Download\pc305128.gif
2000-01-18 16:57 11948 –a—— C:\Program Files\WB01d2se\Download\mb199912.002
2000-01-18 16:57 10378 –a—— C:\Program Files\WB01d2se\Download\pc304374.gif
1999-12-12 23:00 14586 –a—— C:\Program Files\WB01d2se\Download\pc303568.gif
1999-12-12 23:00 12287 –a—— C:\Program Files\WB01d2se\Download\mb199911.001
1999-11-11 23:00 14108 –a—— C:\Program Files\WB01d2se\Download\mb199910.001
1999-11-11 23:00 12682 –a—— C:\Program Files\WB01d2se\Download\pc303131.gif
1999-10-05 23:00 20578 –a—— C:\Program Files\WB01d2se\Download\mb199909.001
1999-10-05 23:00 14194 –a—— C:\Program Files\WB01d2se\Download\pc301952.gif
1999-09-16 23:00 18253 –a—— C:\Program Files\WB01d2se\Download\mb199908.001
1999-09-16 23:00 12290 –a—— C:\Program Files\WB01d2se\Download\pc301372.gif
1999-08-16 23:00 20837 –a—— C:\Program Files\WB01d2se\Download\mb199907.001
1999-08-16 23:00 11594 –a—— C:\Program Files\WB01d2se\Download\pc301348.gif
1999-07-13 23:00 17258 –a—— C:\Program Files\WB01d2se\Download\mb199906.001
1999-07-13 23:00 14165 –a—— C:\Program Files\WB01d2se\Download\pc301187.gif
1999-06-09 23:00 20024 –a—— C:\Program Files\WB01d2se\Download\mb199905.001
1999-06-08 23:00 13971 –a—— C:\Program Files\WB01d2se\Download\pc300403.gif
1999-05-09 23:00 15372 –a—— C:\Program Files\WB01d2se\Download\pc300004.gif
1999-05-09 23:00 15360 –a—— C:\Program Files\WB01d2se\Download\mb199904.001
1999-04-26 05:48 45056 –a—— C:\Program Files\WB01d2se\CTICIS.dll
1999-04-26 05:48 45056 –a—— C:\Program Files\WB01d2se\CTIAOL.dll
1999-04-23 16:54 40960 –a—— C:\Program Files\WB01d2se\CTIW95.dll
1999-04-23 16:54 40960 –a—— C:\Program Files\WB01d2se\CTIGENRC.dll
1999-04-23 16:54 36864 –a—— C:\Program Files\WB01d2se\CTIDIRCT.dll
1999-04-23 16:54 24576 –a—— C:\Program Files\WB01d2se\CTINONE.dll
1999-04-23 16:43 65536 –a—— C:\Program Files\WB01d2se\IspWsock.dll
1999-04-23 16:42 24576 –a—— C:\Program Files\WB01d2se\ISPnull.dll
1999-04-23 16:41 90112 –a—— C:\Program Files\WB01d2se\TrueIP.dll
1999-04-23 16:40 45056 –a—— C:\Program Files\WB01d2se\TrueCmn.dll
1999-04-04 23:00 8554 –a—— C:\Program Files\WB01d2se\Download\pc202924.gif
1999-04-04 23:00 18064 –a—— C:\Program Files\WB01d2se\Download\mb199903.001
1999-03-14 23:00 16571 –a—— C:\Program Files\WB01d2se\Download\mb199902.001
1999-03-14 23:00 12481 –a—— C:\Program Files\WB01d2se\Download\pc202653.gif
1999-02-26 07:29 143360 –a—— C:\Program Files\WB01d2se\araisf.dll
1999-02-24 15:58 9886 –a—— C:\Program Files\WB01d2se\Download\pc202498.gif
1999-02-24 15:58 20006 –a—— C:\Program Files\WB01d2se\Download\mb199901.001
1999-01-15 18:41 10089 –a—— C:\Program Files\WB01d2se\Download\pc202301.gif
1999-01-15 18:38 12506 –a—— C:\Program Files\WB01d2se\Download\mb199812.001
1998-12-17 18:31 16279 –a—— C:\Program Files\WB01d2se\Download\mb199811.001
1998-12-17 18:30 12576 –a—— C:\Program Files\WB01d2se\Download\pc201979.gif
1998-11-16 21:34 13025 –a—— C:\Program Files\WB01d2se\Download\pc201734.gif
1998-11-16 21:33 17522 –a—— C:\Program Files\WB01d2se\Download\mb199810.001
1998-11-16 10:35 126976 –a—— C:\Program Files\WB01d2se\Al21mfc.dll
1998-10-12 13:18 16729 –a—— C:\Program Files\WB01d2se\Download\mb199809.001
1998-10-12 09:15 10794 –a—— C:\Program Files\WB01d2se\Download\pc201507.gif
1998-09-10 13:15 18991 –a—— C:\Program Files\WB01d2se\Download\mb199808.001
1998-09-10 13:14 13087 –a—— C:\Program Files\WB01d2se\Download\pc201462.gif
1998-08-11 10:54 17676 –a—— C:\Program Files\WB01d2se\Download\mb199807.001
1998-08-11 10:37 15394 –a—— C:\Program Files\WB01d2se\Download\pc201434.gif
1998-07-10 22:39 11750 –a—— C:\Program Files\WB01d2se\Download\pc201347.gif
1998-07-10 22:35 14944 –a—— C:\Program Files\WB01d2se\Download\mb199806.001
1998-06-26 16:16 17408 –a—— C:\Program Files\WB01d2se\truthk32.dll
1998-06-26 16:16 17408 –a—— C:\Program Files\WB01d2se\trthk32s.dll
1998-06-10 23:00 11058 –a—— C:\Program Files\WB01d2se\Download\pc201083.gif
1998-06-10 20:26 18660 –a—— C:\Program Files\WB01d2se\Download\mb199805.001
1998-05-28 13:22 636928 –a—— C:\Program Files\WB01d2se\Ipx32_53.dll
1998-05-11 12:01 17869 –a—— C:\Program Files\WB01d2se\Download\mb199804.001
1998-05-11 12:01 11828 –a—— C:\Program Files\WB01d2se\Download\pc016287.gif
1998-04-10 12:27 22917 –a—— C:\Program Files\WB01d2se\Download\mb199803.001
1998-04-10 12:27 18779 –a—— C:\Program Files\WB01d2se\Download\pc016286.gif
1998-04-08 13:57 72718 –a—— C:\Program Files\WB01d2se\Araisf.lib
1998-03-26 16:37 229888 –a—— C:\Program Files\WB01d2se\qtmlClient.dll
1998-03-10 17:59 19173 –a—— C:\Program Files\WB01d2se\Download\mb199802.001
1998-03-10 17:59 12089 –a—— C:\Program Files\WB01d2se\Download\pc016285.gif
1998-02-18 07:55 42421 –a—— C:\Program Files\WB01d2se\Picn1113.ssm
1998-02-18 07:55 42181 –a—— C:\Program Files\WB01d2se\Picn1313.ssm
1998-02-18 07:55 22016 –a—— C:\Program Files\WB01d2se\Picn13.dll
1998-02-10 11:56 15669 –a—— C:\Program Files\WB01d2se\Download\mb199801.001
1998-02-10 11:56 15333 –a—— C:\Program Files\WB01d2se\Download\pc016284.gif
1998-01-09 12:03 14444 –a—— C:\Program Files\WB01d2se\Download\pc016283.gif
1998-01-09 11:54 12962 –a—— C:\Program Files\WB01d2se\Download\mb199712.003
1997-12-09 23:00 18362 –a—— C:\Program Files\WB01d2se\Download\mb199711.001
1997-12-09 23:00 11239 –a—— C:\Program Files\WB01d2se\Download\pc016282.gif
1997-11-10 23:00 17729 –a—— C:\Program Files\WB01d2se\Download\pc016280.gif
1997-11-10 23:00 14348 –a—— C:\Program Files\WB01d2se\Download\mb199710.001
1997-10-09 23:00 15837 –a—— C:\Program Files\WB01d2se\Download\mb199709.001
1997-10-08 23:00 17240 –a—— C:\Program Files\WB01d2se\Download\pc016279.gif
1997-10-08 23:00 16709 –a—— C:\Program Files\WB01d2se\Download\pc016278.gif
1997-09-13 23:00 14601 –a—— C:\Program Files\WB01d2se\Download\pc016271.gif
1997-09-12 23:00 16689 –a—— C:\Program Files\WB01d2se\Download\pc016273.gif
1997-09-12 23:00 16274 –a—— C:\Program Files\WB01d2se\Download\mb199707.001
1997-09-12 23:00 15697 –a—— C:\Program Files\WB01d2se\Download\pc016274.gif
1997-09-12 23:00 15200 –a—— C:\Program Files\WB01d2se\Download\pc016272.gif
1997-09-12 23:00 14839 –a—— C:\Program Files\WB01d2se\Download\mb199705.001
1997-09-12 23:00 14571 –a—— C:\Program Files\WB01d2se\Download\pc016275.gif
1997-09-12 23:00 14466 –a—— C:\Program Files\WB01d2se\Download\pc016276.gif
1997-09-12 23:00 13910 –a—— C:\Program Files\WB01d2se\Download\mb199703.001
1997-09-12 23:00 13853 –a—— C:\Program Files\WB01d2se\Download\mb199706.001
1997-09-12 23:00 12812 –a—— C:\Program Files\WB01d2se\Download\pc016277.gif
1997-09-12 23:00 12659 –a—— C:\Program Files\WB01d2se\Download\mb199702.001
1997-09-12 23:00 12515 –a—— C:\Program Files\WB01d2se\Download\mb199704.001
1997-09-12 23:00 12449 –a—— C:\Program Files\WB01d2se\Download\mb199701.001
1997-09-10 23:00 14654 –a—— C:\Program Files\WB01d2se\Download\mb199708.001
1997-07-08 13:06 13564 –a—— C:\Program Files\WB01d2se\Trthk16s.dll
1997-07-07 14:50 49152 –a—— C:\Program Files\WB01d2se\Wsock32.thk
1997-07-07 14:50 46592 –a—— C:\Program Files\WB01d2se\Wsa32srv.thk
1997-07-03 10:34 13440 –a—— C:\Program Files\WB01d2se\Truthk16.dll
1997-01-02 23:00 11851 –a—— C:\Program Files\WB01d2se\Download\pc016270.gif
1997-01-02 23:00 11211 –a—— C:\Program Files\WB01d2se\Download\pc016269.gif
1996-11-10 23:00 14589 –a—— C:\Program Files\WB01d2se\Download\pc016268.gif
1996-11-07 23:00 14194 –a—— C:\Program Files\WB01d2se\Download\pc016267.gif
1996-11-04 23:00 13880 –a—— C:\Program Files\WB01d2se\Download\pc016266.gif
1996-10-16 23:00 10585 –a—— C:\Program Files\WB01d2se\Download\pc016265.gif
1996-06-27 07:54 35840 –a—— C:\Program Files\WB01d2se\launch32.dll


((((((((((((((((((((((((((((( snapshot@2007-11-08_ 6.44.28.04 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-10-29 21:57:02 139,648 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2007-11-09 01:02:45 134,872 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXSUPMON"="C:\WINDOWS\System32\LXSUPMON.exe" [2002-01-28 06:48]
"HostManager"="C:\Program Files\Common Files\AOL\1126962645\ee\AOLSoftware.exe" [2005-11-02 21:01]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-09-28 22:40]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-06-14 17:32]
"Disc Detector"="C:\Program Files\Creative\ShareDLL\CtNotify.exe" [1998-12-16 00:53]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-17 17:17]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-29 08:41]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2004-09-09 16:35]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-07-13 14:00]
"Aim6"="C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" [2005-11-02 21:01]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [2005-12-08 13:55]
"PlaxoUpdate"="C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe" [2005-11-15 14:55]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\Money Express.exe" [2001-07-25 11:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-22 05:16]

C:\Documents and Settings\Tabitha\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 21:57:56]
TimeLeft.lnk - C:\Program Files\TimeLeft3\TimeLeft.exe [2006-02-22 15:07:08]

R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

.
Contents of the 'Scheduled Tasks' folder
"2007-11-02 22:17:37 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2005-04-30 21:11:08 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-08 19:03:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Disc Detector = C:\Program Files\Creative\ShareDLL\CtNotify.exe?X?????????????????B?????Disc Detector?B???A???????A?@ ????B???@???@???B???????@?????????0?B???A???????A?? ????B???@?????P?????@?P ????????A~??????????@?M?????????????????B?????? ????????????????????????????B

scanning hidden files …

C:\WINDOWS\system32\PerfStringBackup.TMP

scan completed successfully
hidden files: 1

**************************************************************************
.
Completion time: 2007-11-08 19:06:37 - machine was rebooted
C:\ComboFix2.txt … 2007-11-08 06:46
.
— E O F —

Kaspersky log



Kaspersky Online ScannerWelcome to the Kaspersky Online Scanner! Use it to
scan your PC for viruses and other malware for free
Warning: if you have installed Kaspersky Online Scanner Pro, please
manually uninstall it using "Add/Remove Programs" before installing this
version! Otherwise this version will not function correctly.

Benefits:


Kaspersky Anti-Virus exceptional detection rates and thorough scanning
Hourly AV database updates available each time the Online Scanner is
launched
Heuristic analysis to detect unknown viruses
Simple installation (just click on a link)

Requirements and limitations:


When using this service for the first time, you have to run with
Administrator privileges in order to install the product. Also, you will
need to download and install files about 400 KB in size followed by 9 MB
of virus definitions.
However, if you use the Online Scanner again, you will only need to
download the files that have been updated since your last scan.
The Online Scanner service offered by Kaspersky Lab uses Microsoft ActiveX
technology. Microsoft ActiveX Technology and the Kaspersky Online Scanner
work only with MS Internet Explorer 6.0 or higher.
We cannot guarantee that the Online Scanner will function correctly if you
are using any other browser or any Internet Explorer extensions (such as
AvantBrowser). If you use a different browser, you can use the Kaspersky
File Scanner to scan individual files.
The free Kaspersky Online Scanner does not scan boot sectors and MBRs, so
it cannot detect malicious code located in these areas.
Please note: The free Kaspersky Online Scanner does not protect against
malicious code, and cannot prevent future infections. It only detects
malware that has already penetrated your computer. We strongly recommend
that you install a full antivirus solution to protect your system.

Privacy statement:

The Kaspersky Online Scanner will collect information about the malicious
programs found on your computer during the scanning process. The
information will be sent to the Kaspersky Virus Lab for statistical
purposes. No personal information about you or specific information about
your system will be collected or transmitted to Kaspersky Lab.





Clean infected files. Protect your PC from future infection.
BUY KASPERSKY ANTI-VIRUS NOW





Select: All, None, Suspicious Selected objects: 0




Scan settings:
Here you can configure the scanning process.

Scan using the following antivirus database:
standard - detect viruses, worms, Trojans,
rootkits
extended - protect your computer from Spyware,
adware, dialers and potentially dangerous
software such as remote access utilities, prank
programs and jokes. We do not recommend this
option to beginners or inexperienced users.

Scan options:
Scan Archives - scan files inside archives
Note: affects all targets except 'A
File…' scan target.
Scan Mail Bases - scan e-mails/attachments
inside mail base files
Note: affects all targets except 'My
Email' and 'A File…' scan targets.







Initialize Kaspersky Online Scanner
(downloading and installing Kaspersky Online
Scanner ActiveX from the server into your
computer)





Update Kaspersky Anti-Virus Databases [100%]:
(downloading and installing the latest Kaspersky
Anti-Virus Databases)





Please wait to update the virus definitions…
Downloading from url:
ftp://downloads2.kaspersky-labs.com
Downloading remote file: master.xml
Downloading remote file: kavset.xml
Downloading remote file: soft.xml
Downloading remote file: updcfg.xml
Downloading remote file: kernel.avc
Downloading remote file: krnunp.avc
Downloading remote file: krnexe.avc
Downloading remote file: krnmacro.avc
Downloading remote file: krnjava.avc
Downloading remote file: krndos.avc
Downloading remote file: krn001.avc
Downloading remote file: krn002.avc
Downloading remote file: krn003.avc
Downloading remote file: krn004.avc
Downloading remote file: krn005.avc
Downloading remote file: krnexe32.avc
Downloading remote file: krnengn.avc
Downloading remote file: smart.avc
Downloading remote file: ocr.avc
Downloading remote file: chuka.avc
Downloading remote file: fa001.avc
Downloading remote file: base001c.avc
Downloading remote file: base002c.avc
Downloading remote file: base003c.avc
Downloading remote file: base004c.avc
Downloading remote file: base005c.avc
Downloading remote file: base006c.avc
Downloading remote file: base007c.avc
Downloading remote file: base008c.avc
Downloading remote file: base009c.avc
Downloading remote file: base010c.avc
Downloading remote file: base011c.avc
Downloading remote file: base012c.avc
Downloading remote file: base013c.avc
Downloading remote file: base014c.avc
Downloading remote file: base015c.avc
Downloading remote file: base016c.avc
Downloading remote file: base017c.avc
Downloading remote file: base018c.avc
Downloading remote file: base019c.avc
Downloading remote file: base020c.avc
Downloading remote file: base021c.avc
Downloading remote file: base022c.avc
Downloading remote file: base023c.avc
Downloading remote file: base024c.avc
Downloading remote file: base025c.avc
Downloading remote file: base026c.avc
Downloading remote file: base027c.avc
Downloading remote file: base028c.avc
Downloading remote file: base029c.avc
Downloading remote file: base030c.avc
Downloading remote file: base031c.avc
Downloading remote file: base032c.avc
Downloading remote file: base033c.avc
Downloading remote file: base034c.avc
Downloading remote file: base035c.avc
Downloading remote file: base036c.avc
Downloading remote file: base037c.avc
Downloading remote file: base038c.avc
Downloading remote file: base039c.avc
Downloading remote file: base040c.avc
Downloading remote file: base041c.avc
Downloading remote file: base042c.avc
Downloading remote file: base043c.avc
Downloading remote file: base044c.avc
Downloading remote file: base045c.avc
Downloading remote file: base046c.avc
Downloading remote file: base047c.avc
Downloading remote file: base048c.avc
Downloading remote file: base049c.avc
Downloading remote file: base050c.avc
Downloading remote file: base051c.avc
Downloading remote file: base052c.avc
Downloading remote file: base053c.avc
Downloading remote file: base054c.avc
Downloading remote file: base055c.avc
Downloading remote file: base056c.avc
Downloading remote file: base057c.avc
Downloading remote file: base058c.avc
Downloading remote file: base059c.avc
Downloading remote file: base060c.avc
Downloading remote file: base061c.avc
Downloading remote file: base062c.avc
Downloading remote file: base063c.avc
Downloading remote file: dailyc.avc
Downloading from url:
http://downloads2.kaspersky-labs.com
Downloading remote file: master.xml
Downloading remote file: kavset.xml
Downloading remote file: ext001c.avc
Downloading remote file: ext002c.avc
Downloading remote file: ext003c.avc
Downloading remote file: ext004c.avc
Downloading remote file: ext005c.avc
Downloading remote file: ext006c.avc
Downloading remote file: daily-ec.avc
Downloading remote file: base001.avc
Downloading remote file: base002.avc
Downloading remote file: base003.avc
Downloading remote file: base004.avc
Downloading remote file: base005.avc
Downloading remote file: base006.avc
Downloading remote file: base007.avc
Downloading remote file: base008.avc
Downloading remote file: base009.avc
Downloading remote file: base010.avc
Downloading remote file: base011.avc
Downloading remote file: base012.avc
Downloading remote file: base013.avc
Downloading remote file: base014.avc
Downloading remote file: base015.avc
Downloading remote file: base016.avc
Downloading remote file: base017.avc
Downloading remote file: base018.avc
Downloading remote file: base019.avc
Downloading remote file: base020.avc
Downloading remote file: base021.avc
Downloading remote file: base022.avc
Downloading remote file: base023.avc
Downloading remote file: base024.avc
Downloading remote file: base025.avc
Downloading remote file: base026.avc
Downloading remote file: base027.avc
Downloading remote file: base028.avc
Downloading remote file: base029.avc
Downloading remote file: base030.avc
Downloading remote file: base031.avc
Downloading remote file: base032.avc
Downloading remote file: base033.avc
Downloading remote file: base034.avc
Downloading remote file: base035.avc
Downloading remote file: base036.avc
Downloading remote file: base037.avc
Downloading remote file: base038.avc
Downloading remote file: base039.avc
Downloading remote file: base040.avc
Downloading remote file: base041.avc
Downloading remote file: base042.avc
Downloading remote file: base043.avc
Downloading remote file: base044.avc
Downloading remote file: base045.avc
Downloading remote file: base046.avc
Downloading remote file: base047.avc
Downloading remote file: base048.avc
Downloading remote file: base049.avc
Downloading remote file: base050.avc
Downloading remote file: base051.avc
Downloading remote file: base052.avc
Downloading remote file: base053.avc
Downloading remote file: base054.avc
Downloading remote file: base055.avc
Downloading remote file: base056.avc
Downloading remote file: base057.avc
Downloading remote file: base058.avc
Downloading remote file: base059.avc
Downloading remote file: base060.avc
Downloading remote file: base061.avc
Downloading remote file: base062.avc
Downloading remote file: base063.avc
Downloading remote file: base064.avc
Downloading remote file: base065.avc
Downloading remote file: base066.avc
Downloading remote file: base067.avc
Downloading remote file: base068.avc
Downloading remote file: base069.avc
Downloading remote file: base070.avc
Downloading remote file: base071.avc
Downloading remote file: base072.avc
Downloading remote file: base073.avc
Downloading remote file: base074.avc
Downloading remote file: base075.avc
Downloading remote file: base076.avc
Downloading remote file: base077.avc
Downloading remote file: base078.avc
Downloading remote file: base079.avc
Downloading remote file: base080.avc
Downloading remote file: base081.avc
Downloading remote file: base082.avc
Downloading remote file: base083.avc
Downloading remote file: base084.avc
Downloading remote file: base085.avc
Downloading remote file: base086.avc
Downloading remote file: base087.avc
Downloading remote file: base088.avc
Downloading remote file: base089.avc
Downloading remote file: base090.avc
Downloading remote file: base091.avc
Downloading remote file: base092.avc
Downloading remote file: base093.avc
Downloading remote file: base094.avc
Downloading remote file: base095.avc
Downloading remote file: base096.avc
Downloading remote file: base097.avc
Downloading remote file: base098.avc
Downloading remote file: base099.avc
Downloading remote file: base100.avc
Downloading remote file: base101.avc
Downloading remote file: base102.avc
Downloading remote file: base103.avc
Downloading remote file: base104.avc
Downloading remote file: base105.avc
Downloading remote file: base106.avc
Downloading remote file: base107.avc
Downloading remote file: base108.avc
Downloading remote file: base109.avc
Downloading remote file: base110.avc
Downloading remote file: base111.avc
Downloading remote file: base112.avc
Downloading remote file: base113.avc
Downloading remote file: base114.avc
Downloading remote file: base115.avc
Downloading remote file: base116.avc
Downloading remote file: base117.avc
Downloading remote file: base118.avc
Downloading remote file: base119.avc
Downloading remote file: base120.avc
Downloading remote file: base121.avc
Downloading remote file: base122.avc
Downloading remote file: base123.avc
Downloading remote file: base124.avc
Downloading remote file: base125.avc
Downloading remote file: base126.avc
Downloading remote file: base127.avc
Downloading remote file: base128.avc
Downloading remote file: base129.avc
Downloading remote file: base130.avc
Downloading remote file: base131.avc
Downloading remote file: base132.avc
Downloading remote file: base133.avc
Downloading remote file: base134.avc
Downloading remote file: base135.avc
Downloading remote file: base136.avc
Downloading remote file: base137.avc
Downloading remote file: base138.avc
Downloading remote file: base139.avc
Downloading remote file: base140.avc
Downloading remote file: base141.avc
Downloading remote file: base142.avc
Downloading remote file: base143.avc
Downloading remote file: base144.avc
Downloading remote file: base145.avc
Downloading remote file: base146.avc
Downloading remote file: base147.avc
Downloading remote file: base148.avc
Downloading remote file: base149.avc
Downloading remote file: base150.avc
Downloading remote file: base151.avc
Downloading remote file: base152.avc
Downloading remote file: base153.avc
Downloading remote file: base154.avc
Downloading remote file: base155.avc
Downloading remote file: base156.avc
Downloading remote file: base157.avc
Downloading remote file: base158.avc
Downloading remote file: base999.avc
Downloading remote file: unp000.avc
Downloading remote file: unp001.avc
Downloading remote file: unp002.avc
Downloading remote file: unp003.avc
Downloading remote file: unp004.avc
Downloading remote file: unp005.avc
Downloading remote file: unp006.avc
Downloading remote file: unp007.avc
Downloading remote file: unp008.avc
Downloading remote file: unp009.avc
Downloading remote file: unp010.avc
Downloading remote file: unp011.avc
Downloading remote file: unp012.avc
Downloading remote file: unp013.avc
Downloading remote file: unp014.avc
Downloading remote file: unp015.avc
Downloading remote file: unp016.avc
Downloading remote file: unp017.avc
Downloading remote file: unp018.avc
Downloading remote file: unp019.avc
Downloading remote file: unp020.avc
Downloading remote file: unp021.avc
Downloading remote file: unp022.avc
Downloading remote file: unp023.avc
Downloading remote file: unp024.avc
Downloading remote file: unp025.avc
Downloading remote file: unp026.avc
Downloading remote file: unp027.avc
Downloading remote file: unp028.avc
Downloading remote file: unp029.avc
Downloading remote file: unp030.avc
Downloading remote file: unp031.avc
Downloading remote file: unp032.avc
Downloading remote file: unp033.avc
Downloading remote file: unp034.avc
Downloading remote file: unp035.avc
Downloading remote file: unp036.avc
Downloading remote file: unp037.avc
Downloading remote file: unp038.avc
Downloading remote file: unp039.avc
Downloading remote file: daily.avc
Downloading remote file: daily-ex.avc
Downloading remote file: urgent.avc
Downloading remote file: mail.avc
Downloading remote file: ext001.avc
Downloading remote file: ext002.avc
Downloading remote file: ext003.avc
Downloading remote file: ext004.avc
Downloading remote file: ext005.avc
Downloading remote file: ext006.avc
Downloading remote file: ext007.avc
Downloading remote file: ext008.avc
Downloading remote file: ext009.avc
Downloading remote file: ext999.avc
Downloading remote file: gen001.avc
Downloading remote file: gen002.avc
Downloading remote file: gen003.avc
Downloading remote file: gen004.avc
Downloading remote file: gen005.avc
Downloading remote file: gen999.avc
Downloading remote file: ca.avc
Downloading remote file: fa.avc
Downloading remote file: eicar.avc
Downloading remote file: verdicts.ini
Downloading remote file: engine.dt
Downloading remote file: engine.cfg
Downloading remote file: avcmhk5.mhk
Downloading remote file: black.lst
Downloading remote file: avp.set
Downloading remote file: avp_ext.set
Downloading remote file: avp_x.set
Downloading remote file: avp.vnd
Downloading remote file: soft.ver
Update finished. Ready to scan.
Next
Please select a target to scan:
You can configure the scanning process by
pressing "Scan Settings" button.



Critical Areas
scan critical areas of your hard disks
specified in %windir% and %tmp% system variables
Memory
scan disk modules of running processes
My Computer
scan all your hard and mapped disks
My Email
scan all your hard and mapped disks only for the
following extensions: *.PST; *.MSG; *.OST;
*.MDB; *.DBX; *.EML; *.MBS
Folders…
scan selected folders
A File…
scan a one file





Warning: The Kaspersky Online Scanner may not
run successfully while any other Anti-Virus
software is running. If you have Anti-Virus
software installed, please disable your AV
protection before running the Kaspersky Online
Scanner.
Scan complete.
Verdict: Your computer is infected
The following infected files/objects were
detected:


Report is empty.
Please note: The free Kaspersky Online Scanner
does not provide comprehensive protection and
cannot prevent future infections. It only
detects malware that has already penetrated your
storage devices. We strongly recommend that you

Highjackthis log


Logfile of HijackThis v1.99.1
Scan saved at 10:12:44 PM, on 11/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\a-squared Free\a2service.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\Program Files\Common Files\AOL\1126962645\ee\AOLSoftware.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe
C:\Program Files\Microsoft Money\System\Money Express.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\TimeLeft3\TimeLeft.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Creative\ShareDLL\MEDIADET.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1126962645\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Startup: TimeLeft.lnk = C:\Program Files\TimeLeft3\TimeLeft.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm117YYUS
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - C:\Program Files\TimeLeft3\TLIntergIE.html (HKCU)
O9 - Extra 'Tools' menuitem: Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - C:\Program Files\TimeLeft3\TLIntergIE.html (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAcc…e/bridge-c6.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/zenpuzzlegarden/mi…pGameLoader.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1114888937327
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v61/swapit/swapit.cab
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - http://www.worldwinner.com/games/v40/hangman/hangman.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {D68217F4-1DF9-45C1-BFA6-61DBD5464527} (Genealogy Browser) - http://66.119.139.74/cabs/zinst.cab
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} - http://static.zangocash.com/cab/Zango/ie/b…e55e39bbcd1b030
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Looks good - let's follow with a scan now. That folder info has some unique files that aren't well documented, but most appear related to some IBM Interactive Media software and at least one Pegasus. Perhaps you might recognize their use there.


Go Here and download ATF cleaner. Click on the downloaded file to run it, and select "Select All", then click Empty Selected (and close ATF).

If you have them, also click on Firefox/Opera at the top and repeat the steps (and close ATF). Firefox/Opera will need to be closed first for the cleaning to be effective.


Then Go here for an online AV scan (requires IE to run). If your AV alerts you while the scan installs ignore this - Panda's Active Scan method is often mistaken for infection activity.

Scan "Local Disks" and when finished save the scan log and then post the log here. To save the log first select the See Report button, then select the Save report button, and post that log back here.
Incident Status Location Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Tabitha\Application Data\Mozilla\Firefox\Profiles\l0p31lii.default\cookies.txt[.perf.overture.com/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Tabitha\Cookies\tabitha@2o7[2].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Tabitha\Cookies\tabitha@atdmt[2].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Tabitha\Cookies\tabitha@doubleclick[1].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Tabitha\Cookies\tabitha@fastclick[1].txt Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Tabitha\Desktop\ComboFix.exe[nircmd.exe] Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Tabitha\Desktop\ComboFix.exe[nircmd.cfexe] Virus:Trj/Downloader.PME Disinfected C:\Documents and Settings\Tabitha\Local Settings\Application Data\Wildtangent\Cdacache\\\1A.dat Hacktool:HackTool/KillProcWin.A Not disinfected C:\Documents and Settings\Tabitha\Local Settings\Application Data\Wildtangent\Cdacache\\\1D.dat[simple_killw.exe] Virus:Generic Malware Disinfected C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll Adware:Adware/Zango Not disinfected C:\Program Files\Common Files\csshare\plugins0942\npclntax.dll Adware:Adware/Zango Not disinfected C:\Program Files\Common Files\csshare\plugins0942\npzango.dll Adware:Adware/Zango Not disinfected C:\Program Files\Netscape\Netscape 6\Plugins\npzango.dll Adware:Adware/VideoAddon Not disinfected C:\qoobox\Quarantine\c\Program Files\Video Add-on\icthis.exe.vir Adware:Adware/VideoAddon Not disinfected C:\qoobox\Quarantine\c\Program Files\Video Add-on\ictmdl.dll.vir Adware:Adware/NaviPromo Not disinfected C:\qoobox\Quarantine\c\WINDOWS\system32\msclock32.dll.vir Adware:Adware/NaviPromo Not disinfected C:\qoobox\Quarantine\c\WINDOWS\system32\msplock32.dll.vir Adware:Adware/nCase Not disinfected C:\temp\180SAInstaller.exe Potentially unwanted tool:Application/FunWeb Not disinfected C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\NirCmd.exe
Looks much improved - harmless cookies, bad files already quarantined by the work you did (ComboFix's Qoobox folder) and some files needing removal now. The can identifies WildTangent and Weatherbug - both have bad past reputations as spyware/adware in some form but have since been mostly removed from active scan signatures. WildTangent is often pre-installed along with AOL by computer manufacturers and many choose to uninstall it through Add/Remove Programs as not needed. How are things running there now?

Open notepad (go to Start, Run, type notepad and press Enter) and copy/paste the text in the codebox below into it:

File::
C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf 
C:\Program Files\Common Files\csshare\plugins0942\npclntax.dll
C:\Program Files\Common Files\csshare\plugins0942\npzango.dll
C:\Program Files\Netscape\Netscape 6\Plugins\npzango.dll 
Folder::
C:\temp
DirLook::
C:\Program Files\Common Files\csshare\plugins0942

Save this as "CFScript"

(include the "quotation marks" with the name)


[external image: Posted Image]

Referring to the picture above, drag CFScript.txt into ComboFix.exe

ComboFix will now run as it did before. When the command window opens, select 1 (and Enter). Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt.

A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

Then reboot, and run and post back a new Panda scan log along with the combofix.txt log please.
ComboFix 07-11-08.1 - Tabitha 2007-11-13 12:25:58.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tabitha\Desktop\CFScript.txt

FILE
C:\Program Files\Common Files\csshare\plugins0942\npclntax.dll
C:\Program Files\Common Files\csshare\plugins0942\npzango.dll
C:\Program Files\Netscape\Netscape 6\Plugins\npzango.dll
C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Common Files\csshare\plugins0942\npclntax.dll
C:\Program Files\Common Files\csshare\plugins0942\npzango.dll
C:\Program Files\Netscape\Netscape 6\Plugins\npzango.dll
C:\temp
C:\temp\180SAInstaller.exe
C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf

.
((((((((((((((((((((((((( Files Created from 2007-10-13 to 2007-11-13 )))))))))))))))))))))))))))))))
.

2007-11-09 07:02 d——– C:\WINDOWS\system32\ActiveScan
2007-11-08 19:49 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-11-08 19:49 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-08 06:18 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-31 06:13 d——– C:\Program Files\a-squared Free
2007-10-29 08:42 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-10-29 08:06 d——– C:\Program Files\Onyx
2007-10-24 14:36 d——– C:\Documents and Settings\Tabitha\Application Data\OpenOffice.org2
2007-10-24 14:29 d——– C:\Program Files\OpenOffice.org 2.3
2007-10-24 14:01 1,613,824 –a—— C:\WINDOWS\system32\cdintf250.dll
2007-10-24 14:00 d——– C:\Program Files\Common Files\Palo Alto Software
2007-10-24 14:00 d——– C:\Program Files\Common Files\Intuit
2007-10-24 13:59 d——– C:\Program Files\Quicken
2007-10-24 13:59 d——– C:\Documents and Settings\Tabitha\Application Data\Intuit
2007-10-24 13:59 d——– C:\Documents and Settings\All Users\Application Data\Intuit
2007-10-24 09:19 d——– C:\Recovered
2007-10-24 09:19 d——– C:\Documents and Settings\Tabitha\Application Data\Temp
2007-10-24 09:18 d——– C:\Program Files\TPRecDT
2007-10-24 09:18 d——– C:\Program Files\Manual
2007-10-20 22:40 d——– C:\Documents and Settings\Tabitha\Application Data\PlayFirst
2007-10-20 22:40 d——– C:\Documents and Settings\All Users\Application Data\PlayFirst
2007-10-19 05:45 d——– C:\Documents and Settings\Tabitha\Application Data\TuneUp Software
2007-10-19 05:44 d——– C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-10-19 05:44 29,704 –a—— C:\WINDOWS\system32\uxtuneup.dll
2007-10-19 05:42 d——– C:\Program Files\TuneUp Utilities 2007
2007-10-19 05:39 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-18 02:04 128,896 —–c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2007-10-18 02:04 23,040 —–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2007-10-18 02:04 16,896 —–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2007-10-17 19:09 dr-h—– C:\Documents and Settings\Tabitha\Application Data\SecuROM
2007-10-17 19:09 108,144 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-10-17 18:25 442,368 -ra—— C:\WINDOWS\system32\vp6vfw.dll
2007-10-17 17:18 d——– C:\Program Files\Common Files\xing shared
2007-10-17 17:16 d——– C:\Program Files\Google
2007-10-17 15:20 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-16 18:48 d——– C:\Program Files\WinMX Music
2007-10-16 13:21 d——– C:\Documents and Settings\Tabitha\Application Data\AVG7
2007-10-16 13:19 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-16 13:19 d——– C:\Documents and Settings\All Users\Application Data\avg7
2007-10-16 13:08 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-13 18:39 ——— d—–w C:\Documents and Settings\Tabitha\Application Data\WeatherBug
2007-11-13 18:37 ——— d—–w C:\Program Files\Plaxo
2007-11-09 14:05 ——— d—–w C:\Program Files\TimeLeft3
2007-11-09 14:03 ——— d—–w C:\Program Files\QuickTime
2007-11-03 12:19 ——— d—–w C:\Program Files\Symantec
2007-11-03 12:19 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-03 12:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-10-31 15:09 ——— d—–w C:\Program Files\CompuServe 7.0
2007-10-30 00:32 955,014 —-a-w C:\Program Files\Temp.BMP
2007-10-27 01:27 ——— d—–w C:\Program Files\IncrediMail
2007-10-25 11:43 ——— d—–w C:\Program Files\Microsoft Works
2007-10-24 20:28 ——— d—–w C:\Program Files\Java
2007-10-24 15:35 3,750 —-a-w C:\Program Files\tempy.bmp
2007-10-21 04:40 ——— d—–w C:\Program Files\Yahoo! Games
2007-10-17 23:18 ——— d—–w C:\Program Files\Common Files\Real
2007-10-17 23:17 ——— d—–w C:\Program Files\Common Files\csshare
2007-10-17 06:04 ——— d—–w C:\Program Files\WB01d2se
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2005-05-05 21:32 774,144 —-a-w C:\Program Files\RngInterstitial.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Program Files\Common Files\csshare\plugins0942 —-

2007-10-17 17:18 24576 –a—— C:\Program Files\Common Files\csshare\plugins0942\nprjplug.dll
2007-10-17 17:17 81920 –a—— C:\Program Files\Common Files\csshare\plugins0942\nprpjplug.dll
2007-10-17 17:17 6789 –a—— C:\Program Files\Common Files\csshare\plugins0942\nppl3260.xpt
2007-10-17 17:17 531 –a—— C:\Program Files\Common Files\csshare\plugins0942\nsJSRealPlayerPlugin.xpt
2007-10-17 17:17 144720 –a—— C:\Program Files\Common Files\csshare\plugins0942\nppl3260.dll
2006-04-18 14:59 39424 –a—— C:\Program Files\Common Files\csshare\plugins0942\npclntax.dll
2006-01-06 14:59 86016 –a—— C:\Program Files\Common Files\csshare\plugins0942\npDivxPlayerPlugin.dll
2006-01-06 10:52 297 –a—— C:\Program Files\Common Files\csshare\plugins0942\nsIDivxPlayerPlugin.xpt
2005-09-28 22:40 4208 –a—— C:\Program Files\Common Files\csshare\plugins0942\QuickTimePlugin.class
2005-09-28 22:40 2394 –a—— C:\Program Files\Common Files\csshare\plugins0942\nsIQTScriptablePlugin.xpt
2005-09-28 22:40 106496 –a—— C:\Program Files\Common Files\csshare\plugins0942\npqtplugin7.dll
2005-09-28 22:40 106496 –a—— C:\Program Files\Common Files\csshare\plugins0942\npqtplugin6.dll
2005-09-28 22:40 106496 –a—— C:\Program Files\Common Files\csshare\plugins0942\npqtplugin5.dll
2005-09-28 22:40 106496 –a—— C:\Program Files\Common Files\csshare\plugins0942\npqtplugin4.dll
2005-09-28 22:40 106496 –a—— C:\Program Files\Common Files\csshare\plugins0942\npqtplugin3.dll
2005-09-28 22:40 106496 –a—— C:\Program Files\Common Files\csshare\plugins0942\npqtplugin2.dll
2005-09-28 22:40 106496 –a—— C:\Program Files\Common Files\csshare\plugins0942\npqtplugin.dll
2005-08-09 12:42 57344 –a—— C:\Program Files\Common Files\csshare\plugins0942\npunagi2.dll
2005-08-09 12:42 2298 –a—— C:\Program Files\Common Files\csshare\plugins0942\npunagi2.xpt
2005-07-09 20:14 23040 –a—— C:\Program Files\Common Files\csshare\plugins0942\npzango.dll
2005-04-27 14:10 102400 –a—— C:\Program Files\Common Files\csshare\plugins0942\npracplug.dll
2005-04-27 08:14 415 –a—— C:\Program Files\Common Files\csshare\plugins0942\npscriptable.xpt
2004-09-08 22:03 49152 –a—— C:\Program Files\Common Files\csshare\plugins0942\np32dsw.dll
2004-09-08 20:38 1144 –a—— C:\Program Files\Common Files\csshare\plugins0942\ShockwavePlugin.class
2004-04-26 13:19 337 –a—— C:\Program Files\Common Files\csshare\plugins0942\nsiwthostplugin.xpt
2004-04-26 13:19 32768 –a—— C:\Program Files\Common Files\csshare\plugins0942\npwthost.dll
2002-03-04 16:37 53341 –a—— C:\Program Files\Common Files\csshare\plugins0942\NPJava12.dll
2002-03-04 16:37 53338 –a—— C:\Program Files\Common Files\csshare\plugins0942\NPJava131_02.dll
2002-03-04 16:37 49245 –a—— C:\Program Files\Common Files\csshare\plugins0942\NPJava32.dll
2002-03-04 16:37 49245 –a—— C:\Program Files\Common Files\csshare\plugins0942\NPJava11.dll
2002-03-04 16:37 45150 –a—— C:\Program Files\Common Files\csshare\plugins0942\NPOJI600.dll
2002-02-13 10:42 155648 –a—— C:\Program Files\Common Files\csshare\plugins0942\npViewpoint.dll
2002-01-02 10:14 266 –a—— C:\Program Files\Common Files\csshare\plugins0942\npViewpoint.xpt
2001-09-25 10:39 319488 –a—— C:\Program Files\Common Files\csshare\plugins0942\NPSWF32.dll
2001-09-10 04:47 103344 –a—— C:\Program Files\Common Files\csshare\plugins0942\nppdf32.dll


((((((((((((((((((((((((((((( snapshot@2007-11-08_ 6.44.28.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-08-24 14:28:54 141,424 —-a-w C:\WINDOWS\Downloaded Program Files\asinst.dll
+ 2007-03-29 15:20:50 110,592 —-a-w C:\WINDOWS\system32\ActiveScan\as.dll
+ 2006-10-05 22:15:26 233,472 —-a-w C:\WINDOWS\system32\ActiveScan\ascontrol.dll
+ 2005-06-03 20:03:18 96,256 —-a-w C:\WINDOWS\system32\ActiveScan\asmdat.dll
+ 2003-08-01 17:00:16 36,864 —-a-w C:\WINDOWS\system32\ActiveScan\certdll.dll
+ 2005-05-20 19:42:44 86,016 —-a-w C:\WINDOWS\system32\ActiveScan\instlsp.dll
+ 2006-02-17 00:20:20 4,608 —-a-w C:\WINDOWS\system32\ActiveScan\memvfile.dll
+ 2005-10-26 00:08:32 348,160 —-a-w C:\WINDOWS\system32\ActiveScan\msvcr71.dll
+ 2004-05-04 21:01:02 139,264 —-a-w C:\WINDOWS\system32\ActiveScan\pavaleas.dll
+ 2006-07-14 19:04:10 45,056 —-a-w C:\WINDOWS\system32\ActiveScan\pavdr.exe
+ 2006-04-10 16:50:02 159,832 —-a-w C:\WINDOWS\system32\ActiveScan\pavexcom.dll
+ 2006-02-14 19:05:38 94,208 —-a-w C:\WINDOWS\system32\ActiveScan\pavinas.dll
+ 2006-02-17 00:35:38 180,224 —-a-w C:\WINDOWS\system32\ActiveScan\pavoe.dll
+ 2006-10-05 22:15:38 122,880 —-a-w C:\WINDOWS\system32\ActiveScan\pavpz.dll
+ 2006-06-30 20:13:38 8,704 —-a-w C:\WINDOWS\system32\ActiveScan\pfdnnt.exe
+ 2004-02-04 20:08:42 49,152 —-a-w C:\WINDOWS\system32\ActiveScan\port32.dll
+ 2006-08-01 19:23:10 69,632 —-a-w C:\WINDOWS\system32\ActiveScan\pscpu.dll
+ 2006-08-23 19:06:08 1,388,544 —-a-w C:\WINDOWS\system32\ActiveScan\pskahk.dll
+ 2006-08-17 17:38:14 10,752 —-a-w C:\WINDOWS\system32\ActiveScan\pskalloc.dll
+ 2006-09-04 17:49:54 61,440 —-a-w C:\WINDOWS\system32\ActiveScan\pskas.dll
+ 2006-08-18 14:46:18 779,264 —-a-w C:\WINDOWS\system32\ActiveScan\pskavs.dll
+ 2007-03-26 20:25:34 417,792 —-a-w C:\WINDOWS\system32\ActiveScan\pskcmp.dll
+ 2006-08-09 16:42:24 90,112 —-a-w C:\WINDOWS\system32\ActiveScan\pskfss.dll
+ 2006-07-19 16:55:58 208,896 —-a-w C:\WINDOWS\system32\ActiveScan\pskhtml.dll
+ 2006-01-20 22:57:00 9,728 —-a-w C:\WINDOWS\system32\ActiveScan\pskmas.dll
+ 2006-05-17 15:50:12 14,336 —-a-w C:\WINDOWS\system32\ActiveScan\pskmdfs.dll
+ 2006-08-16 16:58:12 33,280 —-a-w C:\WINDOWS\system32\ActiveScan\pskpack.dll
+ 2006-06-30 20:42:36 266,240 —-a-w C:\WINDOWS\system32\ActiveScan\pskscs.dll
+ 2006-08-17 20:33:14 62,976 —-a-w C:\WINDOWS\system32\ActiveScan\pskutil.dll
+ 2006-08-08 19:13:10 13,312 —-a-w C:\WINDOWS\system32\ActiveScan\pskvfile.dll
+ 2006-08-18 14:53:08 69,632 —-a-w C:\WINDOWS\system32\ActiveScan\pskvfs.dll
+ 2006-08-18 14:49:50 167,936 —-a-w C:\WINDOWS\system32\ActiveScan\pskvm.dll
+ 2007-04-18 23:16:04 353,840 —-a-w C:\WINDOWS\system32\ActiveScan\psscan.dll
+ 2007-01-22 20:42:48 35,328 —-a-w C:\WINDOWS\system32\ActiveScan\rawvfile.dll
+ 1997-09-18 12:12:32 9,488 —-a-w C:\WINDOWS\system32\ActiveScan\sporder.dll
+ 2006-02-28 23:23:40 69,632 —-a-w C:\WINDOWS\system32\ActiveScan\tcpvfile.dll
+ 2006-08-02 18:39:06 73,728 —-a-w C:\WINDOWS\system32\asuninst.exe
- 2007-10-29 14:42:03 821,728 —-a-w C:\WINDOWS\system32\drivers\avg7core.sys
+ 2007-11-09 14:19:54 821,856 —-a-w C:\WINDOWS\system32\drivers\avg7core.sys
- 2007-10-29 21:57:02 139,648 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2007-11-09 01:02:45 134,872 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2005-05-24 18:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 21:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 21:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2007-10-18 08:18:10 40,196 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-11-09 01:05:51 40,196 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2007-10-18 08:18:10 311,934 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-11-09 01:05:51 311,934 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2003-03-26 00:53:50 11,776 —-a-w C:\WINDOWS\system32\ZPORT4AS.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXSUPMON"="C:\WINDOWS\System32\LXSUPMON.exe" [2002-01-28 06:48]
"HostManager"="C:\Program Files\Common Files\AOL\1126962645\ee\AOLSoftware.exe" [2005-11-02 21:01]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-09-28 22:40]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-06-14 17:32]
"Disc Detector"="C:\Program Files\Creative\ShareDLL\CtNotify.exe" [1998-12-16 00:53]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-17 17:17]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-11-09 08:20]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2004-09-09 16:35]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-07-13 14:00]
"Aim6"="C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" [2005-11-02 21:01]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [2005-12-08 13:55]
"PlaxoUpdate"="C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe" [2006-11-16 12:42]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\Money Express.exe" [2001-07-25 11:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-22 05:16]

C:\Documents and Settings\Tabitha\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 21:57:56]
TimeLeft.lnk - C:\Program Files\TimeLeft3\TimeLeft.exe [2006-02-22 15:07:08]

R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

.
Contents of the 'Scheduled Tasks' folder
"2007-11-09 23:17:26 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2005-04-30 21:11:08 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-13 12:38:06
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Disc Detector = C:\Program Files\Creative\ShareDLL\CtNotify.exe?X?????????????????B?????Disc Detector?B???A???????A?@ ????B???@???@???B???????@?????????0?B???A???????A?? ????B???@?????P?????@?P ????????A~??????????@???????????????????B?????? ???????????????????`????????B

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-13 12:40:40 - machine was rebooted
C:\ComboFix2.txt … 2007-11-08 19:06
C:\ComboFix3.txt … 2007-11-08 06:46
.
— E O F —


Panda Scan

everything is running very good. i can restart my computer with no problem's what so ever. pop up's are gone. the only thing now is it run's slow sometime's not all the time just everynow and then, but eh it's old and has a few program's that need to be taken off of it. thank you for helping me, it is much appreciated.
In looking through the files located in that ccshare folder I see known infection items, so with the missing Kaspersky results let's do a different scan and ID things to remove. Also check on installed items remaining to remove (such as Kaspersky, actually). This scanner will add to the load there, but we will be cleaning up after it is used.


Go here and download the free version of SUPERAntiSpyware and install it.

After installation accept any prompts to allow SUPERAntiSpyware to install the latest infection definition files. Next follow the prompts to complete the installation. For now, uncheck the option to have SUPERAntiSpyware "Automatically check for program and definition updates". Providing an email address and allowing the software to send diagnostic reports to it's research center are up to you. Do NOT allow SUPERAntiSpyware to Protect your Home Page settings.

Once the installation is complete open SUPERAntiSpyware and press the Preferences button. Under the General and Startup tab, uncheck the following (leaving all other settings as is).

Start-up Options:
*Start SUPERAntiSpyware when Windows starts

Automatic Updates:
*Check for program updates when the application starts.
Start-up Scanning:
*Check for updates before scanning on startup.

Then select Close. Don't scan just yet though.


Also Go Here and download ATF cleaner. Click on the downloaded file to run it, and select "Select All", then click Empty Selected (and close ATF).

If you have them, also click on Firefox/Opera at the top and repeat the steps (and close ATF). Firefox/Opera will need to be closed first for the cleaning to be effective.

===============================================


Reboot into Safe Mode (at startup tap the F8 key and select Safe Mode).


Open SUPERAntiSpyware and click the Scan your Computer button. You may need to start SUPERAntiSpyware, then right click the Taskbar icon (the little bug shaped icon) and select "Scan for Spyware, Adware, Malware…" to access the scan panel. Making sure that Fixed Drive (NTFS) is checked (typically the C Drive), check "Perform Complete Scan", then click Next. SUPERAntiSpyware will now complete a system scan.


SUPERAntiSpyware will now scan your computer and when its finished it will list all the infections it has found. Make sure that they all have a check next to them and click next. If prompted allow the reboot (or manually reboot at this time), and after the reboot open SUPERAntiSpyware again (double click the bug-shaped Taskbar icon).

Click Preferences, then under the Statistics/Logs tab, click to select the most recent Scan Log, then click View Log. Save the log to your desktop, and copy/paste the text from the log back here.


Run a new ComboFix scan, and post that back here along with a new HijackThis log, and the SUPERAntiSpyware log please.


Also Open Hijackthis.
Click Config - Misc Tools - Open Uninstall Manager.
A list of the entries in Add/Remove programs will appear.
Click on Save List…
The list will be saved as 'Uninstall_list.txt'
Copy & Paste the contents back here for review.

A lot of log posting so take your time.

SUPERantispyware log



SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/27/2007 at 08:33 PM

Application Version : 3.9.1008

Core Rules Database Version : 3351
Trace Rules Database Version: 1350

Scan type : Complete Scan
Total Scan Time : 00:47:45

Memory items scanned : 199
Memory threats detected : 0
Registry items scanned : 4825
Registry threats detected : 7
File items scanned : 30148
File threats detected : 4

Adware.180solutions/Search Assistant
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MediaGatewayX.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MediaGatewayX.dll#.Owner
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MediaGatewayX.dll#{15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6}

Adware.180solutions/ZangoSearch
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/SAIX.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/SAIX.dll#.Owner
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/SAIX.dll#{DECEAAA2-370A-49BB-9362-68C3A58DDC62}
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\CSSHARE\PLUGINS0942\NPZANGO.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\NETSCAPE\NETSCAPE 6\PLUGINS\NPZANGO.DLL.VIR
C:\QOOBOX\QUARANTINE\C\TEMP\180SAINSTALLER.EXE.VIR

Trojan.Security Toolbar
C:\Documents and Settings\All Users\Start Menu\Security Troubleshooting.url

Trojan.Media-Codec/V4
HKU\S-1-5-21-80132939-3691808436-3916994021-1005\Software\Online Add-on

Combofix log



ComboFix 07-11-19.4B - Tabitha 2007-11-28 7:26:02.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.194 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Local Settings\Temporary Internet Files\Content.IE5\HRBB5PCQ\ComboFix[1].exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-10-28 to 2007-11-28 )))))))))))))))))))))))))))))))
.

2007-11-27 19:10 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-27 19:09 d——– C:\Program Files\SUPERAntiSpyware
2007-11-27 19:09 d——– C:\Documents and Settings\Tabitha\Application Data\SUPERAntiSpyware.com
2007-11-24 20:12 d——– C:\Documents and Settings\Tabitha\Application Data\Viewpoint
2007-11-09 07:02 30,590 –a—— C:\WINDOWS\system32\pavas.ico
2007-11-09 07:02 2,550 –a—— C:\WINDOWS\system32\Uninstall.ico
2007-11-09 07:02 1,406 –a—— C:\WINDOWS\system32\Help.ico
2007-11-08 19:49 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-31 06:13 d——– C:\Program Files\a-squared Free
2007-10-29 08:42 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-10-29 08:06 d——– C:\Program Files\Onyx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-28 04:27 ——— d—–w C:\Documents and Settings\Tabitha\Application Data\OpenOffice.org2
2007-11-28 04:25 ——— d—–w C:\Program Files\Plaxo
2007-11-28 01:09 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-27 14:00 ——— d—–w C:\Documents and Settings\Tabitha\Application Data\AVG7
2007-11-13 18:39 ——— d—–w C:\Documents and Settings\Tabitha\Application Data\WeatherBug
2007-11-09 14:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2007-11-09 14:05 ——— d—–w C:\Program Files\TimeLeft3
2007-11-09 14:03 ——— d—–w C:\Program Files\QuickTime
2007-11-09 13:52 ——— d—–w C:\Program Files\Google
2007-11-03 12:19 ——— d—–w C:\Program Files\Symantec
2007-11-03 12:19 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-03 12:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-03 11:53 ——— d—–w C:\Program Files\TPRecDT
2007-11-03 11:53 ——— d—–w C:\Program Files\Manual
2007-10-31 15:09 ——— d—–w C:\Program Files\CompuServe 7.0
2007-10-30 00:32 955,014 —-a-w C:\Program Files\Temp.BMP
2007-10-29 22:27 ——— d—–w C:\Program Files\WinMX Music
2007-10-29 21:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-27 01:27 ——— d—–w C:\Program Files\IncrediMail
2007-10-25 11:43 ——— d—–w C:\Program Files\Microsoft Works
2007-10-24 20:29 ——— d—–w C:\Program Files\OpenOffice.org 2.3
2007-10-24 20:28 ——— d—–w C:\Program Files\Java
2007-10-24 20:07 ——— d—–w C:\Program Files\Quicken
2007-10-24 20:00 ——— d—–w C:\Program Files\Common Files\Palo Alto Software
2007-10-24 20:00 ——— d—–w C:\Program Files\Common Files\Intuit
2007-10-24 19:59 ——— d—–w C:\Documents and Settings\Tabitha\Application Data\Intuit
2007-10-24 19:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\Intuit
2007-10-24 15:35 3,750 —-a-w C:\Program Files\tempy.bmp
2007-10-24 15:19 ——— d—–w C:\Documents and Settings\Tabitha\Application Data\Temp
2007-10-21 04:40 ——— d—–w C:\Program Files\Yahoo! Games
2007-10-21 04:40 ——— d—–w C:\Documents and Settings\Tabitha\Application Data\PlayFirst
2007-10-21 04:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\PlayFirst
2007-10-19 12:20 ——— d—–w C:\Program Files\TuneUp Utilities 2007
2007-10-19 11:45 ——— d—–w C:\Documents and Settings\Tabitha\Application Data\TuneUp Software
2007-10-19 11:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-10-18 01:09 108,144 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-10-18 01:09 ——— d–h–r C:\Documents and Settings\Tabitha\Application Data\SecuROM
2007-10-17 23:18 ——— d—–w C:\Program Files\Common Files\xing shared
2007-10-17 23:18 ——— d—–w C:\Program Files\Common Files\Real
2007-10-17 23:17 ——— d—–w C:\Program Files\Common Files\csshare
2007-10-17 06:04 ——— d—–w C:\Program Files\WB01d2se
2007-10-16 19:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2005-05-05 21:32 774,144 —-a-w C:\Program Files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-07-13 14:00]
"Aim6"="C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" [2005-11-02 21:01]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [2005-12-08 13:55]
"PlaxoUpdate"="C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe" [2006-11-16 12:42]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\Money Express.exe" [2001-07-25 11:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-22 05:16]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXSUPMON"="C:\WINDOWS\System32\LXSUPMON.exe" [2002-01-28 06:48]
"HostManager"="C:\Program Files\Common Files\AOL\1126962645\ee\AOLSoftware.exe" [2005-11-02 21:01]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-09-28 22:40]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-06-14 17:32]
"Disc Detector"="C:\Program Files\Creative\ShareDLL\CtNotify.exe" [1998-12-16 00:53]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-17 17:17]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-11-09 08:20]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-09 08:20]

C:\Documents and Settings\Tabitha\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 21:57:56]
TimeLeft.lnk - C:\Program Files\TimeLeft3\TimeLeft.exe [2006-02-22 15:07:08]

[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

.
Contents of the 'Scheduled Tasks' folder
"2007-11-16 23:19:46 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2005-04-30 21:11:08 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-28 07:28:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Disc Detector = C:\Program Files\Creative\ShareDLL\CtNotify.exe?X?????????????????B?????Disc Detector?B???A???????A?@ ????B???@???@???B???????@?????????0?B???A???????A?? ????B???@?????P?????@?P ????????A~??????????@???????????????????B?????? ????????????????????????????B

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-28 7:30:02
C:\ComboFix2.txt … 2007-11-13 12:40
C:\ComboFix3.txt … 2007-11-08 19:06
.
— E O F —


Hijackthis log



Logfile of HijackThis v1.99.1
Scan saved at 8:01:31 AM, on 11/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\a-squared Free\a2service.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\AOL\1126962645\ee\AOLSoftware.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Creative\ShareDLL\MEDIADET.EXE
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
C:\Program Files\Microsoft Money\System\Money Express.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\TimeLeft3\TimeLeft.exe
C:\Program Files\Microsoft Works\WksWP.exe
C:\Program Files\Microsoft Works\MSWorks.exe
C:\Program Files\Microsoft Works\wkgdcach.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1126962645\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Startup: TimeLeft.lnk = C:\Program Files\TimeLeft3\TimeLeft.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm117YYUS
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - C:\Program Files\TimeLeft3\TLIntergIE.html (HKCU)
O9 - Extra 'Tools' menuitem: Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - C:\Program Files\TimeLeft3\TLIntergIE.html (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAcc…e/bridge-c6.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/zenpuzzlegarden/mi…pGameLoader.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1114888937327
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v61/swapit/swapit.cab
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - http://www.worldwinner.com/games/v40/hangman/hangman.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {D68217F4-1DF9-45C1-BFA6-61DBD5464527} (Genealogy Browser) - http://66.119.139.74/cabs/zinst.cab
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} - http://static.zangocash.com/cab/Zango/ie/b…e55e39bbcd1b030
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


Hijackthis uninstall

list



2001 World Book Premium Edition
Ad-Aware SE Personal
Adobe Acrobat 5.0
Algebra World
AOL Instant Messenger
AOL Uninstaller (Choose which Products to Remove)
a-squared Free 3.0
AVG 7.5
CompuServe
Conexant SoftK56 Modem(M)
Diner Dash
DivX Player
Family Feud (remove only)
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Hijackthis 1.99.1
HijackThis 1.99.1
Intel® Extreme Graphics Driver
InterActual Player
J2SE Runtime Environment 5.0 Update 4
Java 2 Runtime Environment Standard Edition v1.3.1
Java 2 Runtime Environment Standard Edition v1.3.1_02
Java™ 6 Update 2
Jewel Thief (remove only)
Kaspersky Online Scanner
Lexmark Supplies Monitor
Lexmark Z25-Z35
LiveReg (Symantec Corporation)
LiveUpdate 2.0 (Symantec Corporation)
Macromedia Shockwave Player
Microsoft 3D Movie Maker 1.0
Microsoft Money 2002
Microsoft Money 2002 System Pack
Microsoft Works 6.0
Mozilla Firefox (2.0.0.9)
OpenOffice.org 2.3
Panda ActiveScan
PC-DVD Encore
PCFriendly
Plaxo Toolbar for Outlook (with AIM Enhancements)
Quicken 2006
QuickTime
RealPlayer
Realtek AC'97 Audio
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB943460)
Spybot - Search & Destroy 1.4
SUPERAntiSpyware Free Edition
The Merriam-Webster Reference Library
TimeLeft 3 Freeware edition
TuneUp Utilities 2007
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Viewpoint Media Player
Wedding Dash (remove only)
Windows Backup Utility
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
World Book 2001 (Deluxe)
Yahoo! extras
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Ten Pin Championship Bowling
Yahoo! Toolbar
YOU DON'T KNOW JACK Volume 2 Lite
Zoo Vet (remove only)
Zuma Deluxe
That was a bit of time lagged response huh? The SuperAntiSpyware log shows only registry remnants and infected files already removed by ComboFix, but no active infection which is good. Installed programs do not reflect any know malware bundled items as well, but some things there we can address as we clean things up here.


Close Internet Explorer and all running programs and run a scan in HijackThis. Place a check next to all of the following lines, then select “Fix Checked” and close HijackThis.

O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} - http://static.zangocash.com/cab/Zango/ie/b…e55e39bbcd1b030


——————————————

Make sure you can View Hidden Files. Also uncheck "Hide Extensions for Known File Types"

Do a search ( Start - Search/Find - Files or Folders) for the following hilighted folders (shown in Bold), and if found, see if you recognize the contents to inform me in your next reply. If either are empty you can delete them now.

C:\Program Files\TPRecDT
C:\Program Files\WB01d2se

——————————————-

Go to Start – Settings – Control Panel. Click on Add/Remove Programs. If any of the following programs are listed there, click on the program to highlight it, and click on Remove. Then close the Control Panel.

Viewpoint Media Player (installed without user knowledge, can be removed without issues - see here Here is their main web page, where they tell folks all about how to advertise to us users).

I did ask about this in another thread, so perhaps you can give me more information on it's source and uses there:
YOU DON'T KNOW JACK Volume 2 Lite

Then you need to remove older Java versions and the vulnerabilities they bring and update to the very latest version (and stay with that after we are done here):

J2SE Runtime Environment 5.0 Update 4
Java 2 Runtime Environment Standard Edition v1.3.1
Java 2 Runtime Environment Standard Edition v1.3.1_02
Java™ 6 Update 2
(recent, but already replaced)

Then go here and download and install the latest version of Sun Java (Java Runtime Environment (JRE) 6 Update 2). The current file name for that is jre-6u2-windows-i586-p.exe, though may have recently updated again to 6u3.

Reboot after, and let me know if things are running well, and also info on those folders please.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI