This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] So many trojans

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi guys, wondering if anyone can help me out. My dell laptop just recently started to drastically slow down. the spu usage periodically jumps to 100% so it has to be some sort of malware infection. i ran avg antivirus, and spyware doctor. avg never picks anything up, however spywarre doc finds tons of different trojans and other harmful programs. even after fixing with spyware doctor, the problem persists and eventually returns. heres my HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:46:55 AM, on 11/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Anti-AD Guard 2.1\adguard.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Starcraft\starcraft.exe
C:\Documents and Settings\Tam P\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?.home=ytie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?.home=ytie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?.home=ytie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {51387345-62E7-4F63-B77F-F9A2E1956D8C} - C:\WINDOWS\system32\awtss.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: 0 - {79CE2F1B-E2E4-44CD-E6AD-8B39C529FD93} - C:\Program Files\ComPlus Applications\lavujat908.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {92EB362F-231B-4D89-AE0C-888873BFA453} - C:\Program Files\Common Files\hokep83122.dll (file missing)
O2 - BHO: (no name) - {C062BE98-1642-430B-9EBF-2FE24BE2ACA1} - C:\WINDOWS\system32\hgswrtan.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC315NC Webcam
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [C-Media Speaker Configuration] C:\PROGRA~1\C-Media\WIN_ME\Setup.exe /SPEAKER
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Anti-AD Guard 2.1] "C:\Program Files\Anti-AD Guard 2.1\adguard.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: TA_Start.lnk = C:\Documents and Settings\Tam P\Local Settings\Temp\thinksnet.exe
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: awtss - C:\WINDOWS\system32\awtss.dll (file missing)
O20 - Winlogon Notify: ljjhhee - ljjhhee.dll (file missing)
O22 - SharedTaskScheduler: comitatus - {98013eb8-258b-4979-bfd5-04ecd93f765c} - C:\WINDOWS\system32\txxkb.dll (file missing)
O22 - SharedTaskScheduler: inquisitionist - {12a8c4e6-06c8-4ab3-9274-a0cde148e3da} - C:\WINDOWS\system32\clbrcek.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\ComPlus Applications\profsywuyn.html

–
End of file - 11948 bytes


thnx a bunch
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.


Disable Teatimer
First:
  • Right click Spybot in the System Tray (looks like a calendar with a padlock symbol)
  • Choose Exit Spybot S&D Resident
Second:
  • Open Spybot S&D
  • Click Mode, check Advanced Mode
  • Go To Left Panel, Click Tools, then also in left panel, click Resident
  • If your firewall raises a question, say OK
  • Uncheck the box labeled Resident Tea-Timer and OK any prompts.
  • Use File, Exit to terminate Spybot
  • Reboot your machine for the changes to take effect.


Download and Save ComboFix
  • Download this file from below:

    Here
  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
hey scotty thanks a bunch for your time. hers is the uninstall list: ————————————————————————————————————– Ad-Aware 2007 Adobe Acrobat - Reader 6.0.2 Update Adobe Flash Player ActiveX Adobe Flash Player Plugin Adobe Reader 6.0.1 AIM 6 Aim Plugin for QQ Games AIMTunes (remove only) Anti-AD Guard 2.1 Apple Mobile Device Support Apple Software Update a-squared Anti-Malware 3.0 AVG 7.5 AVG Anti-Spyware 7.5 BCM V.92 56K Modem BlackBerry Desktop Software 4.2 BlackBerry Desktop Software 4.2 BlueSoleil Broadcom Management Programs Dell Media Experience Dell Media Experience Update Dell Photo Printer 720 Dell Photo Printer 720 Logger Dell Picture Studio v3.0 Dell Support 5.0.0 (630) Dell Wireless WLAN Utility DFX 8 for Winamp eMusic - 50 Free MP3 offer HijackThis 2.0.2 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB926239) Internet Explorer Default Page iPod for Windows 2006-03-23 iTunes Jasc Paint Shop Photo Album Jasc Paint Shop Pro 8 Dell Edition Java™ 6 Update 2 Java™ 6 Update 3 K-Lite Mega Codec Pack 3.4.5 LimeWire 4.14.10 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft Compression Client Pack 1.0 for Windows XP Microsoft DirectX Transform optional components Microsoft Encarta Encyclopedia Standard 2004 Microsoft Money 2004 Microsoft Money 2004 System Pack Microsoft Picture It! Photo Premium 9 Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft Streets and Trips 2004 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Word 2002 Microsoft Works Microsoft Works 2004 Setup Launcher Microsoft Works Suite Add-in for Microsoft Word MioNet Modem Helper Mozilla Firefox (2.0.0.9) NVIDIA Drivers PCI Audio Applications Philips SPC315NC Webcam Philips VLounge Photo Click PowerDVD 5.1 QuickSet QuickTime Registry Mechanic 7.0 Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939653) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB943460) Shockwave Skype™ 3.5 Sonic DLA Sonic RecordNow! Sonic Update Manager
sorry the comb took a while, also towards the end a stop error occurred and i had to reboot my system. here it is:

—————————————————————————————————————————————————–

ComboFix 07-11-08.3 - Tam P 2007-11-15 14:47:12.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.434 [GMT -5:00]Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\Tam P\Application Data\ICROSO~1.NET
C:\Documents and Settings\Tam P\Application Data\macromedia\Flash Player\#SharedObjects\EZB85Y7R\www.broadcaster.com
C:\Documents and Settings\Tam P\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Tam P\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\Tam P\Application Data\RACLE~1
C:\Documents and Settings\Tam P\Application Data\RACLE~1\?racle\
C:\Documents and Settings\Tam P\err.log
C:\Documents and Settings\Tam P\My Documents\DOBE~1
C:\Documents and Settings\Tam P\Start Menu\Programs\Startup\ta_start.lnk
C:\Program Files\Common Files\sembly~1
C:\Program Files\ComPlus Applications\profsywuyn.html
C:\Program Files\crosof~1
C:\temp\tn3
C:\WINDOWS\cookies.ini
C:\WINDOWS\keyboard1.dat
C:\WINDOWS\mantec~1
C:\WINDOWS\system32\crosof~1
C:\WINDOWS\system32\crunner
C:\WINDOWS\system32\crunner\Version.txt
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f10WtR
C:\WINDOWS\system32\o09PrEz
C:\WINDOWS\system32\win
C:\WINDOWS\system32\X2
C:\WINDOWS\system32\X3
C:\WINDOWS\system32\X4
C:\WINDOWS\system32\X9
C:\WINDOWS\wr.txt

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_CORE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\core


((((((((((((((((((((((((( Files Created from 2007-10-15 to 2007-11-15 )))))))))))))))))))))))))))))))
.

2007-11-15 14:45 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-15 13:48 d——– C:\Program Files\a-squared Anti-Malware
2007-11-13 14:50 d——– C:\Program Files\Spyware Doctor
2007-11-13 14:50 d——– C:\Documents and Settings\Tam P\Application Data\PC Tools
2007-11-13 14:50 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-13 14:50 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-13 14:50 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-13 14:50 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-13 14:50 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-11-13 03:21 d——– C:\Program Files\Common Files\Scanner
2007-11-13 01:01 d——– C:\Documents and Settings\Tam P\.housecall6.6
2007-11-08 20:24 d——– C:\Documents and Settings\All Users\Application Data\DFX
2007-11-08 16:42 d——– C:\Program Files\DFX
2007-11-08 13:45 d——– C:\Program Files\Winamp Toolbar
2007-11-08 13:45 d——– C:\Program Files\Winamp Remote
2007-11-08 13:45 d——– C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
2007-11-08 13:45 d——– C:\Documents and Settings\All Users\Application Data\OrbNetworks
2007-11-08 13:41 d——– C:\Program Files\Winamp
2007-11-08 13:41 d——– C:\Documents and Settings\Tam P\Application Data\Winamp
2007-11-08 13:41 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2007-11-08 13:41 9,464 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-08 13:41 9,336 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-02 18:09 d——– C:\Program Files\Windows Live Safety Center
2007-11-01 17:35 d——– C:\Program Files\Lavasoft
2007-11-01 17:31 d——– C:\Program Files\Anti-AD Guard 2.1
2007-11-01 17:31 d——– C:\Documents and Settings\All Users\Application Data\Anti-AD Guard 2
2007-10-29 14:54 139,264 –a—— C:\WINDOWS\War3Unin.exe
2007-10-29 14:54 76,242 –a—— C:\WINDOWS\War3Unin.dat
2007-10-29 14:54 2,829 –a—— C:\WINDOWS\War3Unin.pif
2007-10-28 21:28 12,288 –a—— C:\WINDOWS\system32\URLHelp.dll
2007-10-28 20:19 d——– C:\Program Files\SpywareGuard
2007-10-27 13:10 d——– C:\Documents and Settings\Administrator\Application Data\QQ Games Plugin
2007-10-27 13:09 d——– C:\Documents and Settings\Administrator\Application Data\acccore
2007-10-27 13:07 d——– C:\Documents and Settings\Administrator\Application Data\AVG7
2007-10-27 13:06 d——– C:\Documents and Settings\Administrator\Application Data\Sonic
2007-10-27 13:06 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-10-27 13:06 d–h—– C:\Documents and Settings\Administrator\Application Data\Gtek
2007-10-23 13:10 d——– C:\Documents and Settings\Tam P\Application Data\QQ Games Plugin
2007-10-23 13:09 d——– C:\Program Files\Tencent
2007-10-23 13:09 d——– C:\Program Files\AIMTunes
2007-10-17 21:23 d——– C:\Program Files\iTunes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-15 19:43 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Skype
2007-11-15 18:02 ——— d—–w C:\Documents and Settings\Tam P\Application Data\AVG7
2007-11-15 10:57 ——— d—–w C:\Documents and Settings\Tam P\Application Data\LimeWire
2007-11-15 10:04 ——— d—–w C:\Program Files\Starcraft
2007-11-15 05:21 ——— d—–w C:\Program Files\Warcraft III
2007-11-13 08:21 ——— d—–w C:\Program Files\Yahoo!
2007-11-13 07:28 ——— d—–w C:\Program Files\MioNet
2007-11-03 17:11 ——— d—–w C:\Program Files\SpywareBlaster
2007-11-01 22:33 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-10-27 03:55 ——— d—–w C:\Program Files\LimeWire
2007-10-26 21:28 ——— d—–w C:\Program Files\Java
2007-10-23 18:10 ——— d—–w C:\Program Files\AIM6
2007-10-23 18:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-10-23 18:08 ——— d—–w C:\Program Files\Viewpoint
2007-10-23 18:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-23 18:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-10-22 16:21 12,386 —-a-w C:\Documents and Settings\Tam P\Application Data\wklnhst.dat
2007-10-22 16:06 71,768 —-a-w C:\Documents and Settings\Tam P\Application Data\GDIPFONTCACHEV1.DAT
2007-10-22 02:33 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-18 02:23 ——— d—–w C:\Program Files\iPod
2007-10-13 23:08 ——— d—–w C:\Program Files\K-Lite Codec Pack
2007-10-13 23:07 ——— d—–w C:\Program Files\Common Files\Real
2007-10-09 01:44 ——— d—–w C:\Documents and Settings\Tam P\Application Data\ArcSoft
2007-10-09 01:36 ——— d—–w C:\Program Files\Common Files\ArcSoft
2007-10-09 01:35 ——— d—–w C:\Program Files\Philips
2007-09-27 21:08 ——— d—–w C:\Program Files\Skype
2007-09-27 21:08 ——— d—–w C:\Program Files\Common Files\Skype
2007-09-27 21:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2007-09-27 17:08 ——— d—–w C:\Program Files\WC3Banlist
2007-09-25 22:48 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Research In Motion
2007-09-25 20:54 ——— d—–w C:\Program Files\Common Files\Research In Motion
2007-09-25 20:54 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Blackberry Desktop
2007-09-25 20:53 ——— d—–w C:\Program Files\Research In Motion
2007-09-25 14:35 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Yahoo!
2007-09-24 15:12 ——— d—–w C:\Program Files\MTV Networks
2007-09-24 15:09 ——— d—–w C:\Program Files\Windows Media Connect 2
2007-09-22 22:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Dell Photo Printer 720
2007-09-22 22:21 ——— d—–w C:\Program Files\Jasc Software Inc
2007-09-22 22:21 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Jasc Software Inc
2007-09-22 22:19 ——— d—–w C:\Program Files\Dell Photo Printer 720
2007-09-22 22:19 ——— d—–w C:\Program Files\Dell Computer
2007-09-22 22:17 ——— d—–w C:\Program Files\Dell 720
2007-09-18 15:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\TEMP
2007-09-17 05:51 ——— d—–w C:\Program Files\QuickTime
2007-09-17 05:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-09-17 05:49 ——— d—–w C:\Program Files\Common Files\Apple
2007-09-17 05:49 ——— d—–w C:\Program Files\Apple Software Update
2007-09-17 05:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-09-17 05:36 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Apple Computer
2007-09-15 15:57 94,208 —-a-w C:\WINDOWS\ScUnin.exe
2007-07-30 05:13:01 1,735,881 –sh–w C:\WINDOWS\system32\sstwa.bak1
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-10-04 15:06 1135968 –a—— C:\Program Files\Winamp Toolbar\winamptb.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51387345-62E7-4F63-B77F-F9A2E1956D8C}]
C:\WINDOWS\system32\awtss.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{79CE2F1B-E2E4-44CD-E6AD-8B39C529FD93}]
C:\Program Files\ComPlus Applications\lavujat908.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{92EB362F-231B-4D89-AE0C-888873BFA453}]
C:\Program Files\Common Files\hokep83122.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C062BE98-1642-430B-9EBF-2FE24BE2ACA1}]
C:\WINDOWS\system32\hgswrtan.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 15:06 1135968]

[HKEY_CLASSES_ROOT\CLSID\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-10-26 11:01]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-24 09:57]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2004-06-09 14:37]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 02:01]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-14 01:23]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 15:35]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 12:43]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2004-09-15 02:01]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2004-10-07 20:44]
"C-Media Speaker Configuration"="C:\PROGRA~1\C-Media\WIN_ME\Setup.exe" [2001-11-14 08:26]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 06:00 C:\WINDOWS\system32\bthprops.cpl]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 09:59]
"nwiz"="nwiz.exe" [2004-10-26 11:01 C:\WINDOWS\system32\nwiz.exe]
"RegistryMechanic"="" []
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2007-08-31 20:24]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-09-29 15:22]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-29 10:09]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-09-13 12:31]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 09:59]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 15:46]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 13:00]
"Anti-AD Guard 2.1"="C:\Program Files\Anti-AD Guard 2.1\adguard.exe" [2007-08-22 11:10]

C:\Documents and Settings\Tam P\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 18:05:35]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtss]
C:\WINDOWS\system32\awtss.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjhhee]
ljjhhee.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=C:\WINDOWS\pss\Desktop Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^dlbcserv.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dlbcserv.lnk
backup=C:\WINDOWS\pss\dlbcserv.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TrayMin315.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TrayMin315.exe.lnk
backup=C:\WINDOWS\pss\TrayMin315.exe.lnkCommon Startup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
"C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLTRYSVC"=2 (0x2)
"MioNet"=2 (0x2)
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)

S3 BOCDRIVE;BOClean Kernel Monitor.;\??\C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
S4 MioNet;MioNet Service;"C:\Program Files\MioNet\MioNetManager.exe" -s "C:\Program Files\MioNet\wrapper.conf"

.
Contents of the 'Scheduled Tasks' folder
"2007-11-15 02:02:13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-15 15:25:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-15 15:28:57 - machine was rebooted
.
— E O F —
p.s. i did shut all the antivirus and antispyware down befoe hand. i dont know if rebooting effected the log.
I forgot to disable teatimer on the previous one, heres an updated combfix log:



_________________________________


ComboFix 07-11-08.3 - Tam P 2007-11-15 18:07:21.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.417 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-10-15 to 2007-11-15 )))))))))))))))))))))))))))))))
.

2007-11-15 14:45 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-15 13:48 d——– C:\Program Files\a-squared Anti-Malware
2007-11-13 14:50 d——– C:\Program Files\Spyware Doctor
2007-11-13 14:50 d——– C:\Documents and Settings\Tam P\Application Data\PC Tools
2007-11-13 14:50 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-13 14:50 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-13 14:50 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-13 14:50 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-13 14:50 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-11-13 03:21 d——– C:\Program Files\Common Files\Scanner
2007-11-13 01:01 d——– C:\Documents and Settings\Tam P\.housecall6.6
2007-11-08 20:24 d——– C:\Documents and Settings\All Users\Application Data\DFX
2007-11-08 16:42 d——– C:\Program Files\DFX
2007-11-08 13:45 d——– C:\Program Files\Winamp Toolbar
2007-11-08 13:45 d——– C:\Program Files\Winamp Remote
2007-11-08 13:45 d——– C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
2007-11-08 13:45 d——– C:\Documents and Settings\All Users\Application Data\OrbNetworks
2007-11-08 13:41 d——– C:\Program Files\Winamp
2007-11-08 13:41 d——– C:\Documents and Settings\Tam P\Application Data\Winamp
2007-11-08 13:41 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2007-11-08 13:41 9,464 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-08 13:41 9,336 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-02 18:09 d——– C:\Program Files\Windows Live Safety Center
2007-11-01 17:35 d——– C:\Program Files\Lavasoft
2007-11-01 17:31 d——– C:\Program Files\Anti-AD Guard 2.1
2007-11-01 17:31 d——– C:\Documents and Settings\All Users\Application Data\Anti-AD Guard 2
2007-10-29 14:54 139,264 –a—— C:\WINDOWS\War3Unin.exe
2007-10-29 14:54 76,242 –a—— C:\WINDOWS\War3Unin.dat
2007-10-29 14:54 2,829 –a—— C:\WINDOWS\War3Unin.pif
2007-10-28 21:28 12,288 –a—— C:\WINDOWS\system32\URLHelp.dll
2007-10-28 20:19 d——– C:\Program Files\SpywareGuard
2007-10-27 13:10 d——– C:\Documents and Settings\Administrator\Application Data\QQ Games Plugin
2007-10-27 13:09 d——– C:\Documents and Settings\Administrator\Application Data\acccore
2007-10-27 13:07 d——– C:\Documents and Settings\Administrator\Application Data\AVG7
2007-10-27 13:06 d——– C:\Documents and Settings\Administrator\Application Data\Sonic
2007-10-27 13:06 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-10-27 13:06 d–h—– C:\Documents and Settings\Administrator\Application Data\Gtek
2007-10-23 13:10 d——– C:\Documents and Settings\Tam P\Application Data\QQ Games Plugin
2007-10-23 13:09 d——– C:\Program Files\Tencent
2007-10-23 13:09 d——– C:\Program Files\AIMTunes
2007-10-17 21:23 d——– C:\Program Files\iTunes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-15 23:02 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Skype
2007-11-15 21:31 ——— d—–w C:\Program Files\Starcraft
2007-11-15 18:02 ——— d—–w C:\Documents and Settings\Tam P\Application Data\AVG7
2007-11-15 10:57 ——— d—–w C:\Documents and Settings\Tam P\Application Data\LimeWire
2007-11-15 05:21 ——— d—–w C:\Program Files\Warcraft III
2007-11-13 08:21 ——— d—–w C:\Program Files\Yahoo!
2007-11-13 07:28 ——— d—–w C:\Program Files\MioNet
2007-11-03 17:11 ——— d—–w C:\Program Files\SpywareBlaster
2007-11-01 22:33 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-10-27 03:55 ——— d—–w C:\Program Files\LimeWire
2007-10-26 21:28 ——— d—–w C:\Program Files\Java
2007-10-26 03:36 8,454,656 ——w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-23 18:10 ——— d—–w C:\Program Files\AIM6
2007-10-23 18:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-10-23 18:08 ——— d—–w C:\Program Files\Viewpoint
2007-10-23 18:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-23 18:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-10-22 16:21 12,386 —-a-w C:\Documents and Settings\Tam P\Application Data\wklnhst.dat
2007-10-22 16:06 71,768 —-a-w C:\Documents and Settings\Tam P\Application Data\GDIPFONTCACHEV1.DAT
2007-10-22 02:33 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-18 02:23 ——— d—–w C:\Program Files\iPod
2007-10-13 23:08 ——— d—–w C:\Program Files\K-Lite Codec Pack
2007-10-13 23:07 ——— d—–w C:\Program Files\Common Files\Real
2007-10-09 01:44 ——— d—–w C:\Documents and Settings\Tam P\Application Data\ArcSoft
2007-10-09 01:36 ——— d—–w C:\Program Files\Common Files\ArcSoft
2007-10-09 01:35 ——— d—–w C:\Program Files\Philips
2007-09-27 21:08 ——— d—–w C:\Program Files\Skype
2007-09-27 21:08 ——— d—–w C:\Program Files\Common Files\Skype
2007-09-27 21:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2007-09-27 17:08 ——— d—–w C:\Program Files\WC3Banlist
2007-09-25 22:48 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Research In Motion
2007-09-25 20:54 ——— d—–w C:\Program Files\Common Files\Research In Motion
2007-09-25 20:54 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Blackberry Desktop
2007-09-25 20:53 ——— d—–w C:\Program Files\Research In Motion
2007-09-25 14:35 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Yahoo!
2007-09-24 15:12 ——— d—–w C:\Program Files\MTV Networks
2007-09-24 15:09 ——— d—–w C:\Program Files\Windows Media Connect 2
2007-09-22 22:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Dell Photo Printer 720
2007-09-22 22:21 ——— d—–w C:\Program Files\Jasc Software Inc
2007-09-22 22:21 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Jasc Software Inc
2007-09-22 22:19 ——— d—–w C:\Program Files\Dell Photo Printer 720
2007-09-22 22:19 ——— d—–w C:\Program Files\Dell Computer
2007-09-22 22:17 ——— d—–w C:\Program Files\Dell 720
2007-09-18 15:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\TEMP
2007-09-17 05:51 ——— d—–w C:\Program Files\QuickTime
2007-09-17 05:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-09-17 05:49 ——— d—–w C:\Program Files\Common Files\Apple
2007-09-17 05:49 ——— d—–w C:\Program Files\Apple Software Update
2007-09-17 05:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-09-17 05:36 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Apple Computer
2007-09-15 15:57 94,208 —-a-w C:\WINDOWS\ScUnin.exe
2007-09-13 17:13 4,608 —-a-w C:\WINDOWS\system32\w95inf32.dll
2007-09-13 03:53 1,971,700 –sh–w C:\WINDOWS\system32\sstwa.bak2
2007-08-22 13:12 96,256 ——w C:\WINDOWS\system32\dllcache\inseng.dll
2007-08-22 13:12 658,944 ——w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-22 13:12 615,424 ——w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-22 13:12 55,808 ——w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-22 13:12 532,480 ——w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-22 13:12 474,112 ——w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-08-22 13:12 449,024 ——w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-22 13:12 39,424 ——w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-08-22 13:12 357,888 ——w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-08-22 13:12 3,058,176 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-22 13:12 251,392 ——w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-08-22 13:12 205,312 ——w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-22 13:12 16,384 ——w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-22 13:12 151,040 ——w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-08-22 13:12 146,432 ——w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-22 13:12 1,494,528 ——w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-08-22 13:12 1,054,208 ——w C:\WINDOWS\system32\dllcache\danim.dll
2007-08-22 13:12 1,022,976 ——w C:\WINDOWS\system32\dllcache\browseui.dll
2007-08-21 10:30 18,432 —-a-w C:\WINDOWS\system32\dllcache\iedw.exe
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ——w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-07-30 05:13:01 1,735,881 –sh–w C:\WINDOWS\system32\sstwa.bak1
.

((((((((((((((((((((((((((((( snapshot@2007-11-15_15.27.10.39 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-15 18:08:30 17,145 —-a-w C:\WINDOWS\system32\nvModes.dat
+ 2007-11-15 22:53:52 17,145 —-a-w C:\WINDOWS\system32\nvModes.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-10-04 15:06 1135968 –a—— C:\Program Files\Winamp Toolbar\winamptb.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51387345-62E7-4F63-B77F-F9A2E1956D8C}]
C:\WINDOWS\system32\awtss.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{79CE2F1B-E2E4-44CD-E6AD-8B39C529FD93}]
C:\Program Files\ComPlus Applications\lavujat908.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{92EB362F-231B-4D89-AE0C-888873BFA453}]
C:\Program Files\Common Files\hokep83122.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C062BE98-1642-430B-9EBF-2FE24BE2ACA1}]
C:\WINDOWS\system32\hgswrtan.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 15:06 1135968]

[HKEY_CLASSES_ROOT\CLSID\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 15:06 1135968]

[HKEY_CLASSES_ROOT\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-10-26 11:01]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-24 09:57]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2004-06-09 14:37]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 02:01]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-14 01:23]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 15:35]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 12:43]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2004-09-15 02:01]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2004-10-07 20:44]
"C-Media Speaker Configuration"="C:\PROGRA~1\C-Media\WIN_ME\Setup.exe" [2001-11-14 08:26]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 06:00 C:\WINDOWS\system32\bthprops.cpl]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 09:59]
"nwiz"="nwiz.exe" [2004-10-26 11:01 C:\WINDOWS\system32\nwiz.exe]
"RegistryMechanic"="" []
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2007-08-31 20:24]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-09-29 15:22]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-29 10:09]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-09-13 12:31]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 09:59]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 13:00]
"Anti-AD Guard 2.1"="C:\Program Files\Anti-AD Guard 2.1\adguard.exe" [2007-08-22 11:10]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtss]
C:\WINDOWS\system32\awtss.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjhhee]
ljjhhee.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=C:\WINDOWS\pss\Desktop Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^dlbcserv.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dlbcserv.lnk
backup=C:\WINDOWS\pss\dlbcserv.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TrayMin315.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TrayMin315.exe.lnk
backup=C:\WINDOWS\pss\TrayMin315.exe.lnkCommon Startup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
"C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLTRYSVC"=2 (0x2)
"MioNet"=2 (0x2)
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)

S3 BOCDRIVE;BOClean Kernel Monitor.;\??\C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
S4 MioNet;MioNet Service;"C:\Program Files\MioNet\MioNetManager.exe" -s "C:\Program Files\MioNet\wrapper.conf"

.
Contents of the 'Scheduled Tasks' folder
"2007-11-15 02:02:13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-15 18:09:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-15 18:09:50
C:\ComboFix2.txt … 2007-11-15 15:28
.
— E O F —
sorry forgot to post new hijackthis log. And once agains thank you so much for your time:

———————————————————————————————————————————–


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:04:42 PM, on 11/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\explorer.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Tam P\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?.home=ytie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?.home=ytie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?.home=ytie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {51387345-62E7-4F63-B77F-F9A2E1956D8C} - C:\WINDOWS\system32\awtss.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: 0 - {79CE2F1B-E2E4-44CD-E6AD-8B39C529FD93} - C:\Program Files\ComPlus Applications\lavujat908.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {92EB362F-231B-4D89-AE0C-888873BFA453} - C:\Program Files\Common Files\hokep83122.dll (file missing)
O2 - BHO: (no name) - {C062BE98-1642-430B-9EBF-2FE24BE2ACA1} - C:\WINDOWS\system32\hgswrtan.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC315NC Webcam
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [C-Media Speaker Configuration] C:\PROGRA~1\C-Media\WIN_ME\Setup.exe /SPEAKER
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Anti-AD Guard 2.1] "C:\Program Files\Anti-AD Guard 2.1\adguard.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: awtss - C:\WINDOWS\system32\awtss.dll (file missing)
O20 - Winlogon Notify: ljjhhee - ljjhhee.dll (file missing)
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 10386 bytes
Hi

I see that Viewpoint Manager Service is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto‑updating for the Viewpoint Manager ‑‑ the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.

Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware.
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight Viewpoint Manager Service , click Remove.
  • Do the same for each Viewpoint component.


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File:;
C:\WINDOWS\system32\sstwa.bak2 
C:\WINDOWS\system32\sstwa.bak1
C:\WINDOWS\system32\awtss.dll
C:\Program Files\ComPlus Applications\lavujat908.dll
C:\Program Files\Common Files\hokep83122.dll
C:\WINDOWS\system32\hgswrtan.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51387345-62E7-4F63-B77F-F9A2E1956D8C}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{79CE2F1B-E2E4-44CD-E6AD-8B39C529FD93}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{92EB362F-231B-4D89-AE0C-888873BFA453}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C062BE98-1642-430B-9EBF-2FE24BE2ACA1}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtss] 
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjhhee]

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.
heya scotty, here are the resulting logs from combofix:
—————————————————————————


ComboFix 07-11-08.3 - Tam P 2007-11-16 13:22:21.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.292 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tam P\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-10-16 to 2007-11-16 )))))))))))))))))))))))))))))))
.

2007-11-15 14:45 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-15 13:48 d——– C:\Program Files\a-squared Anti-Malware
2007-11-13 14:50 d——– C:\Program Files\Spyware Doctor
2007-11-13 14:50 d——– C:\Documents and Settings\Tam P\Application Data\PC Tools
2007-11-13 14:50 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-13 14:50 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-13 14:50 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-13 14:50 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-13 14:50 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-11-13 03:21 d——– C:\Program Files\Common Files\Scanner
2007-11-13 01:01 d——– C:\Documents and Settings\Tam P\.housecall6.6
2007-11-08 20:24 d——– C:\Documents and Settings\All Users\Application Data\DFX
2007-11-08 16:42 d——– C:\Program Files\DFX
2007-11-08 13:45 d——– C:\Program Files\Winamp Toolbar
2007-11-08 13:45 d——– C:\Program Files\Winamp Remote
2007-11-08 13:45 d——– C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
2007-11-08 13:45 d——– C:\Documents and Settings\All Users\Application Data\OrbNetworks
2007-11-08 13:41 d——– C:\Program Files\Winamp
2007-11-08 13:41 d——– C:\Documents and Settings\Tam P\Application Data\Winamp
2007-11-08 13:41 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2007-11-08 13:41 9,464 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-08 13:41 9,336 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-02 18:09 d——– C:\Program Files\Windows Live Safety Center
2007-11-01 17:35 d——– C:\Program Files\Lavasoft
2007-11-01 17:31 d——– C:\Program Files\Anti-AD Guard 2.1
2007-11-01 17:31 d——– C:\Documents and Settings\All Users\Application Data\Anti-AD Guard 2
2007-10-29 14:54 139,264 –a—— C:\WINDOWS\War3Unin.exe
2007-10-29 14:54 76,242 –a—— C:\WINDOWS\War3Unin.dat
2007-10-29 14:54 2,829 –a—— C:\WINDOWS\War3Unin.pif
2007-10-28 21:28 12,288 –a—— C:\WINDOWS\system32\URLHelp.dll
2007-10-28 20:19 d——– C:\Program Files\SpywareGuard
2007-10-27 13:10 d——– C:\Documents and Settings\Administrator\Application Data\QQ Games Plugin
2007-10-27 13:09 d——– C:\Documents and Settings\Administrator\Application Data\acccore
2007-10-27 13:07 d——– C:\Documents and Settings\Administrator\Application Data\AVG7
2007-10-27 13:06 d——– C:\Documents and Settings\Administrator\Application Data\Sonic
2007-10-27 13:06 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-10-27 13:06 d–h—– C:\Documents and Settings\Administrator\Application Data\Gtek
2007-10-23 13:10 d——– C:\Documents and Settings\Tam P\Application Data\QQ Games Plugin
2007-10-23 13:09 d——– C:\Program Files\Tencent
2007-10-23 13:09 d——– C:\Program Files\AIMTunes
2007-10-17 21:23 d——– C:\Program Files\iTunes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-16 18:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-16 18:15 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Skype
2007-11-16 10:56 ——— d—–w C:\Program Files\Starcraft
2007-11-16 10:56 ——— d—–w C:\Program Files\LimeWire
2007-11-15 18:02 ——— d—–w C:\Documents and Settings\Tam P\Application Data\AVG7
2007-11-15 10:57 ——— d—–w C:\Documents and Settings\Tam P\Application Data\LimeWire
2007-11-15 05:21 ——— d—–w C:\Program Files\Warcraft III
2007-11-13 08:21 ——— d—–w C:\Program Files\Yahoo!
2007-11-13 07:28 ——— d—–w C:\Program Files\MioNet
2007-11-03 17:11 ——— d—–w C:\Program Files\SpywareBlaster
2007-11-01 22:33 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-10-26 21:28 ——— d—–w C:\Program Files\Java
2007-10-26 03:36 8,454,656 ——w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-23 18:10 ——— d—–w C:\Program Files\AIM6
2007-10-23 18:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-10-23 18:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-10-22 16:21 12,386 —-a-w C:\Documents and Settings\Tam P\Application Data\wklnhst.dat
2007-10-22 16:06 71,768 —-a-w C:\Documents and Settings\Tam P\Application Data\GDIPFONTCACHEV1.DAT
2007-10-22 02:33 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-18 02:23 ——— d—–w C:\Program Files\iPod
2007-10-13 23:08 ——— d—–w C:\Program Files\K-Lite Codec Pack
2007-10-13 23:07 ——— d—–w C:\Program Files\Common Files\Real
2007-10-09 01:44 ——— d—–w C:\Documents and Settings\Tam P\Application Data\ArcSoft
2007-10-09 01:36 ——— d—–w C:\Program Files\Common Files\ArcSoft
2007-10-09 01:35 ——— d—–w C:\Program Files\Philips
2007-09-27 21:08 ——— d—–w C:\Program Files\Skype
2007-09-27 21:08 ——— d—–w C:\Program Files\Common Files\Skype
2007-09-27 21:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2007-09-27 17:08 ——— d—–w C:\Program Files\WC3Banlist
2007-09-25 22:48 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Research In Motion
2007-09-25 20:54 ——— d—–w C:\Program Files\Common Files\Research In Motion
2007-09-25 20:54 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Blackberry Desktop
2007-09-25 20:53 ——— d—–w C:\Program Files\Research In Motion
2007-09-25 14:35 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Yahoo!
2007-09-24 15:12 ——— d—–w C:\Program Files\MTV Networks
2007-09-24 15:09 ——— d—–w C:\Program Files\Windows Media Connect 2
2007-09-22 22:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Dell Photo Printer 720
2007-09-22 22:21 ——— d—–w C:\Program Files\Jasc Software Inc
2007-09-22 22:21 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Jasc Software Inc
2007-09-22 22:19 ——— d—–w C:\Program Files\Dell Photo Printer 720
2007-09-22 22:19 ——— d—–w C:\Program Files\Dell Computer
2007-09-22 22:17 ——— d—–w C:\Program Files\Dell 720
2007-09-18 15:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\TEMP
2007-09-17 05:51 ——— d—–w C:\Program Files\QuickTime
2007-09-17 05:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-09-17 05:49 ——— d—–w C:\Program Files\Common Files\Apple
2007-09-17 05:49 ——— d—–w C:\Program Files\Apple Software Update
2007-09-17 05:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-09-17 05:36 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Apple Computer
2007-09-15 15:57 94,208 —-a-w C:\WINDOWS\ScUnin.exe
2007-09-13 17:13 4,608 —-a-w C:\WINDOWS\system32\w95inf32.dll
2007-09-13 03:53 1,971,700 –sh–w C:\WINDOWS\system32\sstwa.bak2
2007-08-22 13:12 96,256 ——w C:\WINDOWS\system32\dllcache\inseng.dll
2007-08-22 13:12 658,944 ——w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-22 13:12 615,424 ——w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-22 13:12 55,808 ——w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-22 13:12 532,480 ——w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-22 13:12 474,112 ——w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-08-22 13:12 449,024 ——w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-22 13:12 39,424 ——w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-08-22 13:12 357,888 ——w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-08-22 13:12 3,058,176 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-22 13:12 251,392 ——w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-08-22 13:12 205,312 ——w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-22 13:12 16,384 ——w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-22 13:12 151,040 ——w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-08-22 13:12 146,432 ——w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-22 13:12 1,494,528 ——w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-08-22 13:12 1,054,208 ——w C:\WINDOWS\system32\dllcache\danim.dll
2007-08-22 13:12 1,022,976 ——w C:\WINDOWS\system32\dllcache\browseui.dll
2007-08-21 10:30 18,432 —-a-w C:\WINDOWS\system32\dllcache\iedw.exe
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ——w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-07-30 05:13:01 1,735,881 –sh–w C:\WINDOWS\system32\sstwa.bak1
.

((((((((((((((((((((((((((((( snapshot@2007-11-15_15.27.10.39 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-15 18:08:30 17,145 —-a-w C:\WINDOWS\system32\nvModes.dat
+ 2007-11-16 18:13:20 17,145 —-a-w C:\WINDOWS\system32\nvModes.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-10-04 15:06 1135968 –a—— C:\Program Files\Winamp Toolbar\winamptb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 15:06 1135968]

[HKEY_CLASSES_ROOT\CLSID\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 15:06 1135968]

[HKEY_CLASSES_ROOT\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-10-26 11:01]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-24 09:57]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2004-06-09 14:37]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 02:01]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-14 01:23]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 15:35]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 12:43]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2004-09-15 02:01]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2004-10-07 20:44]
"C-Media Speaker Configuration"="C:\PROGRA~1\C-Media\WIN_ME\Setup.exe" [2001-11-14 08:26]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 06:00 C:\WINDOWS\system32\bthprops.cpl]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 09:59]
"nwiz"="nwiz.exe" [2004-10-26 11:01 C:\WINDOWS\system32\nwiz.exe]
"RegistryMechanic"="" []
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2007-08-31 20:24]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-09-29 15:22]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-29 10:09]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-09-13 12:31]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 09:59]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 13:00]
"Anti-AD Guard 2.1"="C:\Program Files\Anti-AD Guard 2.1\adguard.exe" [2007-08-22 11:10]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=C:\WINDOWS\pss\Desktop Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^dlbcserv.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dlbcserv.lnk
backup=C:\WINDOWS\pss\dlbcserv.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TrayMin315.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TrayMin315.exe.lnk
backup=C:\WINDOWS\pss\TrayMin315.exe.lnkCommon Startup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
"C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLTRYSVC"=2 (0x2)
"MioNet"=2 (0x2)
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)

S3 BOCDRIVE;BOClean Kernel Monitor.;\??\C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
S4 MioNet;MioNet Service;"C:\Program Files\MioNet\MioNetManager.exe" -s "C:\Program Files\MioNet\wrapper.conf"

.
Contents of the 'Scheduled Tasks' folder
"2007-11-15 02:02:13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-16 13:23:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-16 13:24:38
C:\ComboFix2.txt … 2007-11-15 18:09
C:\ComboFix3.txt … 2007-11-15 15:28
.
— E O F —
Hi

Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\system32\sstwa.bak2
C:\WINDOWS\system32\sstwa.bak1

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post with a new HijackThis log.
With the exception of Internet Explorer, which is needed for the Kaspersky Scan, keep ALL programs closed until the scan is complete.
hers the new log from combofix:
—————————————————–

ComboFix 07-11-08.3 - Tam P 2007-11-16 19:50:14.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.303 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tam P\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\sstwa.bak1
C:\WINDOWS\system32\sstwa.bak2
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\sstwa.bak1
C:\WINDOWS\system32\sstwa.bak2

.
((((((((((((((((((((((((( Files Created from 2007-10-17 to 2007-11-17 )))))))))))))))))))))))))))))))
.

2007-11-15 14:45 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-15 13:48 d——– C:\Program Files\a-squared Anti-Malware
2007-11-13 14:50 d——– C:\Program Files\Spyware Doctor
2007-11-13 14:50 d——– C:\Documents and Settings\Tam P\Application Data\PC Tools
2007-11-13 14:50 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-13 14:50 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-13 14:50 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-13 14:50 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-13 14:50 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-11-13 03:21 d——– C:\Program Files\Common Files\Scanner
2007-11-13 01:01 d——– C:\Documents and Settings\Tam P\.housecall6.6
2007-11-08 20:24 d——– C:\Documents and Settings\All Users\Application Data\DFX
2007-11-08 16:42 d——– C:\Program Files\DFX
2007-11-08 13:45 d——– C:\Program Files\Winamp Toolbar
2007-11-08 13:45 d——– C:\Program Files\Winamp Remote
2007-11-08 13:45 d——– C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
2007-11-08 13:45 d——– C:\Documents and Settings\All Users\Application Data\OrbNetworks
2007-11-08 13:41 d——– C:\Program Files\Winamp
2007-11-08 13:41 d——– C:\Documents and Settings\Tam P\Application Data\Winamp
2007-11-08 13:41 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2007-11-08 13:41 9,464 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-08 13:41 9,336 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-02 18:09 d——– C:\Program Files\Windows Live Safety Center
2007-11-01 17:35 d——– C:\Program Files\Lavasoft
2007-11-01 17:31 d——– C:\Program Files\Anti-AD Guard 2.1
2007-11-01 17:31 d——– C:\Documents and Settings\All Users\Application Data\Anti-AD Guard 2
2007-10-29 14:54 139,264 –a—— C:\WINDOWS\War3Unin.exe
2007-10-29 14:54 76,242 –a—— C:\WINDOWS\War3Unin.dat
2007-10-29 14:54 2,829 –a—— C:\WINDOWS\War3Unin.pif
2007-10-28 21:28 12,288 –a—— C:\WINDOWS\system32\URLHelp.dll
2007-10-28 20:19 d——– C:\Program Files\SpywareGuard
2007-10-27 13:10 d——– C:\Documents and Settings\Administrator\Application Data\QQ Games Plugin
2007-10-27 13:09 d——– C:\Documents and Settings\Administrator\Application Data\acccore
2007-10-27 13:07 d——– C:\Documents and Settings\Administrator\Application Data\AVG7
2007-10-27 13:06 d——– C:\Documents and Settings\Administrator\Application Data\Sonic
2007-10-27 13:06 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-10-27 13:06 d–h—– C:\Documents and Settings\Administrator\Application Data\Gtek
2007-10-23 13:10 d——– C:\Documents and Settings\Tam P\Application Data\QQ Games Plugin
2007-10-23 13:09 d——– C:\Program Files\Tencent
2007-10-23 13:09 d——– C:\Program Files\AIMTunes
2007-10-17 21:23 d——– C:\Program Files\iTunes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 00:01 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Skype
2007-11-16 23:16 ——— d—–w C:\Program Files\Starcraft
2007-11-16 18:36 ——— d—–w C:\Program Files\Warcraft III
2007-11-16 18:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-16 10:56 ——— d—–w C:\Program Files\LimeWire
2007-11-15 18:02 ——— d—–w C:\Documents and Settings\Tam P\Application Data\AVG7
2007-11-15 10:57 ——— d—–w C:\Documents and Settings\Tam P\Application Data\LimeWire
2007-11-13 08:21 ——— d—–w C:\Program Files\Yahoo!
2007-11-13 07:28 ——— d—–w C:\Program Files\MioNet
2007-11-03 17:11 ——— d—–w C:\Program Files\SpywareBlaster
2007-11-01 22:33 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-10-26 21:28 ——— d—–w C:\Program Files\Java
2007-10-26 03:36 8,454,656 ——w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-23 18:10 ——— d—–w C:\Program Files\AIM6
2007-10-23 18:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-10-23 18:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-10-22 16:21 12,386 —-a-w C:\Documents and Settings\Tam P\Application Data\wklnhst.dat
2007-10-22 16:06 71,768 —-a-w C:\Documents and Settings\Tam P\Application Data\GDIPFONTCACHEV1.DAT
2007-10-22 02:33 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-18 02:23 ——— d—–w C:\Program Files\iPod
2007-10-13 23:08 ——— d—–w C:\Program Files\K-Lite Codec Pack
2007-10-13 23:07 ——— d—–w C:\Program Files\Common Files\Real
2007-10-09 01:44 ——— d—–w C:\Documents and Settings\Tam P\Application Data\ArcSoft
2007-10-09 01:36 ——— d—–w C:\Program Files\Common Files\ArcSoft
2007-10-09 01:35 ——— d—–w C:\Program Files\Philips
2007-09-27 21:08 ——— d—–w C:\Program Files\Skype
2007-09-27 21:08 ——— d—–w C:\Program Files\Common Files\Skype
2007-09-27 21:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2007-09-27 17:08 ——— d—–w C:\Program Files\WC3Banlist
2007-09-25 22:48 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Research In Motion
2007-09-25 20:54 ——— d—–w C:\Program Files\Common Files\Research In Motion
2007-09-25 20:54 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Blackberry Desktop
2007-09-25 20:53 ——— d—–w C:\Program Files\Research In Motion
2007-09-25 14:35 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Yahoo!
2007-09-24 15:12 ——— d—–w C:\Program Files\MTV Networks
2007-09-24 15:09 ——— d—–w C:\Program Files\Windows Media Connect 2
2007-09-22 22:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Dell Photo Printer 720
2007-09-22 22:21 ——— d—–w C:\Program Files\Jasc Software Inc
2007-09-22 22:21 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Jasc Software Inc
2007-09-22 22:19 ——— d—–w C:\Program Files\Dell Photo Printer 720
2007-09-22 22:19 ——— d—–w C:\Program Files\Dell Computer
2007-09-22 22:17 ——— d—–w C:\Program Files\Dell 720
2007-09-18 15:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\TEMP
2007-09-17 05:51 ——— d—–w C:\Program Files\QuickTime
2007-09-17 05:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-09-17 05:49 ——— d—–w C:\Program Files\Common Files\Apple
2007-09-17 05:49 ——— d—–w C:\Program Files\Apple Software Update
2007-09-17 05:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-09-17 05:36 ——— d—–w C:\Documents and Settings\Tam P\Application Data\Apple Computer
2007-09-15 15:57 94,208 —-a-w C:\WINDOWS\ScUnin.exe
2007-09-13 17:13 4,608 —-a-w C:\WINDOWS\system32\w95inf32.dll
2007-08-22 13:12 96,256 ——w C:\WINDOWS\system32\dllcache\inseng.dll
2007-08-22 13:12 658,944 ——w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-22 13:12 615,424 ——w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-22 13:12 55,808 ——w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-22 13:12 532,480 ——w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-22 13:12 474,112 ——w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-08-22 13:12 449,024 ——w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-22 13:12 39,424 ——w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-08-22 13:12 357,888 ——w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-08-22 13:12 3,058,176 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-22 13:12 251,392 ——w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-08-22 13:12 205,312 ——w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-22 13:12 16,384 ——w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-22 13:12 151,040 ——w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-08-22 13:12 146,432 ——w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-22 13:12 1,494,528 ——w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-08-22 13:12 1,054,208 ——w C:\WINDOWS\system32\dllcache\danim.dll
2007-08-22 13:12 1,022,976 ——w C:\WINDOWS\system32\dllcache\browseui.dll
2007-08-21 10:30 18,432 —-a-w C:\WINDOWS\system32\dllcache\iedw.exe
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ——w C:\WINDOWS\system32\dllcache\inetcomm.dll
.

((((((((((((((((((((((((((((( snapshot@2007-11-15_15.27.10.39 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-15 18:08:30 17,145 —-a-w C:\WINDOWS\system32\nvModes.dat
+ 2007-11-17 00:46:32 17,145 —-a-w C:\WINDOWS\system32\nvModes.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-10-04 15:06 1135968 –a—— C:\Program Files\Winamp Toolbar\winamptb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 15:06 1135968]

[HKEY_CLASSES_ROOT\CLSID\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 15:06 1135968]

[HKEY_CLASSES_ROOT\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-10-26 11:01]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-24 09:57]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2004-06-09 14:37]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 02:01]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-14 01:23]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 15:35]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 12:43]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2004-09-15 02:01]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2004-10-07 20:44]
"C-Media Speaker Configuration"="C:\PROGRA~1\C-Media\WIN_ME\Setup.exe" [2001-11-14 08:26]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 06:00 C:\WINDOWS\system32\bthprops.cpl]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 09:59]
"nwiz"="nwiz.exe" [2004-10-26 11:01 C:\WINDOWS\system32\nwiz.exe]
"RegistryMechanic"="" []
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2007-08-31 20:24]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-09-29 15:22]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-29 10:09]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-09-13 12:31]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 09:59]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 13:00]
"Anti-AD Guard 2.1"="C:\Program Files\Anti-AD Guard 2.1\adguard.exe" [2007-08-22 11:10]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=C:\WINDOWS\pss\Desktop Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^dlbcserv.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dlbcserv.lnk
backup=C:\WINDOWS\pss\dlbcserv.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TrayMin315.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TrayMin315.exe.lnk
backup=C:\WINDOWS\pss\TrayMin315.exe.lnkCommon Startup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
"C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLTRYSVC"=2 (0x2)
"MioNet"=2 (0x2)
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)

S3 BOCDRIVE;BOClean Kernel Monitor.;\??\C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
S4 MioNet;MioNet Service;"C:\Program Files\MioNet\MioNetManager.exe" -s "C:\Program Files\MioNet\wrapper.conf"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{897934ef-3f6d-11db-9f7c-806d6172696f}]
\Shell\AutoRun\command - D:\autoplay.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-11-15 02:02:13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-16 19:51:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-16 19:52:11
C:\ComboFix2.txt … 2007-11-16 13:24
C:\ComboFix3.txt … 2007-11-15 18:09
.
— E O F —
sorry scotty, as for the kaspersky, i only have firefox, which it doesnt work under. i deleted IE because it was the main engine under attack, and now i have now way of using kaspersky. is there an alternate online scan that we can use scotty?. and once again thanks a bunch for your patience with me….im sucha newb. -Jon
I don't have the kaspersky online scan info, but here is the hijackthis log, in case you need it:

——————————————————————————————————————

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:14:41 PM, on 11/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Tam P\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?.home=ytie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?.home=ytie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?.home=ytie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC315NC Webcam
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [C-Media Speaker Configuration] C:\PROGRA~1\C-Media\WIN_ME\Setup.exe /SPEAKER
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Anti-AD Guard 2.1] "C:\Program Files\Anti-AD Guard 2.1\adguard.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

–
End of file - 9563 bytes
Hello

Sorry for the delay. Make sure AVG AntiSpyware is up to date before following the next instructions.


Follow the next instructions carefully, even if they dont look right to you. There is a bug in the program and we have to work around it.

Run a scan with AVG.
  • Click on Scanner
    • Click on the Settings tab, and set the following settings.
      • How to act
      • Click on Recommended actions, and set to Quarantine.
    • How to scan
      • Check all options.
    • Possibly unwanted software.
      • Check all options.
    • Reports
      • Check Do not automatically generate reports after every scan.
    • What to scan
      • Check Scan every file.
  • Click on the Scan tab.
    • Click on Complete System Scan and the scan will begin.
    • When the scan has finished
    • Make sure that Set all elements to: shows Quarantine, if not click on the link and choose Quarantine from the popup menu.
    • At the bottom of the window click on the Apply all Actions button.
Note: Don't save the report before you hit the Apply action button.

Close AVG Anti-Spyware.

AVG will save a report in the following location C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports

Post back with the report.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI