This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] best seller antivirus pop up

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi, i've been trying to get rid of this yellow pop up thingy that keep wanting me to install the best seller antiviru.
I've been trying for a couple days to get rid of it. i googled everything and came across your site. I hope you can hel me.

heres my hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:49:17 PM, on 11/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\DRIVERS\dcfssvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\gearsec.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Washer\washer.exe
C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brgociih.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hp.my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://hp.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R3 - URLSearchHook: (no name) - {BC0B0C61-91D3-952D-F0B5-912CF0690BB9} - (no file)
R3 - URLSearchHook: (no name) - {C29A683D-FBDD-F828-FC35-F9EA6CB074E6} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: (no name) - {80FA69EA-2207-8A57-DB23-5422B5E56BC9} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\dytltnfx.dll
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [dvjvpux] C:\WINDOWS\dvjvpux.exe
O4 - HKLM\..\RunServices: [MOSearch] C:\PROGRA~1\COMMON~1\System\MOSearch\Bin\mosearch.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Washer] C:\Program Files\Washer\washer.exe /0
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe"
O4 - HKCU\..\Run: [Necl] "C:\Program Files\dolo\sunu.exe" -vt tzt
O4 - HKCU\..\Run: [Ohtco] C:\WINDOWS\system32\m?config.exe
O4 - HKUS\S-1-5-19\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'Default user')
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.pw.aol.com/molbin/shared/m…77/mcinsctl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O20 - AppInit_DLLs: onlmcdmg.dll
O22 - SharedTaskScheduler: {874443fe-aa33-4ebf-a6ac-73208787e62d} - bestreak - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: dcfssvc (Dcfssvc) - Eastman Kodak Company - C:\WINDOWS\system32\DRIVERS\dcfssvc.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\brgociih.exe
O23 - Service: gearsec - GEAR Software - C:\WINDOWS\system32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

–
End of file - 9341 bytes
Hi and welcome to the forums. You have quite an infected machine there. Vundo and Smitfraud from what I can see.

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click Yes
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from Click the Scan for Vundo button when VundoFix appears at reboot.

——————————————————

Please download SmitfraudFix (by S!Ri) to your Desktop.

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

**If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.


Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm
wow i knew my computer was messed up, but really messed up from a person who knows what hes doing point of view. what is vundo, by the way?
well heres my logs.

VundoFix V6.6.2

Checking Java version…

Scan started at 10:32:26 PM 11/20/2007

Listing files found while scanning….



C:\windows\SYSTEM32\cayuiwhn.dll
C:\WINDOWS\system32\ddcyayv.dll
C:\windows\SYSTEM32\dytltnfx.dll
C:\windows\SYSTEM32\dytltnfx.dllbox
C:\windows\SYSTEM32\kmppo.bak1
C:\windows\SYSTEM32\kmppo.bak2
C:\windows\SYSTEM32\kmppo.ini
C:\windows\SYSTEM32\kmppo.ini2
C:\windows\SYSTEM32\kmppo.tmp
C:\windows\SYSTEM32\oppmk.dll
C:\windows\SYSTEM32\srhnjlsa.exe

Beginning removal…

Attempting to delete C:\windows\SYSTEM32\cayuiwhn.dll
C:\windows\SYSTEM32\cayuiwhn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ddcyayv.dll
C:\WINDOWS\system32\ddcyayv.dll Could not be deleted.

Attempting to delete C:\windows\SYSTEM32\dytltnfx.dll
C:\windows\SYSTEM32\dytltnfx.dll Has been deleted!

Attempting to delete C:\windows\SYSTEM32\dytltnfx.dllbox
C:\windows\SYSTEM32\dytltnfx.dllbox Has been deleted!

Attempting to delete C:\windows\SYSTEM32\kmppo.bak1
C:\windows\SYSTEM32\kmppo.bak1 Has been deleted!

Attempting to delete C:\windows\SYSTEM32\kmppo.bak2
C:\windows\SYSTEM32\kmppo.bak2 Has been deleted!

Attempting to delete C:\windows\SYSTEM32\kmppo.ini
C:\windows\SYSTEM32\kmppo.ini Has been deleted!

Attempting to delete C:\windows\SYSTEM32\kmppo.ini2
C:\windows\SYSTEM32\kmppo.ini2 Has been deleted!

Attempting to delete C:\windows\SYSTEM32\kmppo.tmp
C:\windows\SYSTEM32\kmppo.tmp Has been deleted!

Attempting to delete C:\windows\SYSTEM32\oppmk.dll
C:\windows\SYSTEM32\oppmk.dll Has been deleted!

Attempting to delete C:\windows\SYSTEM32\srhnjlsa.exe
C:\windows\SYSTEM32\srhnjlsa.exe Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:15:18 AM, on 11/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\DRIVERS\dcfssvc.exe
C:\WINDOWS\system32\gearsec.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\QuickTime\qttask.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Washer\washer.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brgociih.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hp.my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://hp.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R3 - URLSearchHook: (no name) - {BC0B0C61-91D3-952D-F0B5-912CF0690BB9} - (no file)
R3 - URLSearchHook: (no name) - {C29A683D-FBDD-F828-FC35-F9EA6CB074E6} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {12730779-9093-CB32-B7A1-C059D485F2BD} - blank (file missing)
O2 - BHO: (no name) - {4C6D130D-8EB1-8A43-C006-DA98CB10F2BD} - blank (file missing)
O2 - BHO: (no name) - {4F245171-9D9B-C331-B7A1-C059D485F2BA} - blank (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {B147E087-6294-49C9-AAC8-D27B7A307241} - C:\WINDOWS\system32\oppmk.dll (file missing)
O2 - BHO: (no name) - {DE38F2F2-6C1F-33BB-3BB9-61F3CD436FE4} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: (no name) - {80FA69EA-2207-8A57-DB23-5422B5E56BC9} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [dvjvpux] C:\WINDOWS\dvjvpux.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\RunServices: [MOSearch] C:\PROGRA~1\COMMON~1\System\MOSearch\Bin\mosearch.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Washer] C:\Program Files\Washer\washer.exe /0
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe"
O4 - HKCU\..\Run: [Necl] "C:\Program Files\dolo\sunu.exe" -vt tzt
O4 - HKCU\..\Run: [Ohtco] C:\WINDOWS\system32\m?config.exe
O4 - HKUS\S-1-5-19\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'Default user')
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.pw.aol.com/molbin/shared/m…77/mcinsctl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O20 - AppInit_DLLs: onlmcdmg.dll
O22 - SharedTaskScheduler: {874443fe-aa33-4ebf-a6ac-73208787e62d} - bestreak - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: dcfssvc (Dcfssvc) - Eastman Kodak Company - C:\WINDOWS\system32\DRIVERS\dcfssvc.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\brgociih.exe
O23 - Service: gearsec - GEAR Software - C:\WINDOWS\system32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe

–
End of file - 10398 bytes
Well that got quite a bit of it. The good news is I just heard we got one of our best tools back for use. I would have used it in the first place here but it wasn't available when you posted.

Download and Run ComboFix
  • Download this file from below:
    Here
  • Disconnect from the Internet, than disable your Anti-virus and any real-time Anti-spyware monitors that are running.
  • Then double click Combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
Note 2: Remember to re-enable your Anti-virus and Anti-spyware before reconnecting to the Internet.
also heres the other one you wanted: SmitFraudFix v2.253 Scan done at 11:29:57.29, Wed 11/21/2007 Run from C:\Program Files\Mozilla Firefox\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is FAT32 Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\DRIVERS\dcfssvc.exe C:\WINDOWS\system32\gearsec.exe C:\Program Files\Ahead\InCD\InCDsrv.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe c:\PROGRA~1\mcafee.com\vso\OasClnt.exe c:\program files\mcafee.com\vso\mcvsshld.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\QuickTime\qttask.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\Program Files\Spyware Doctor\SDTrayApp.exe C:\Program Files\Spyware Doctor\svcntaux.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Washer\washer.exe C:\Program Files\Spyware Doctor\swdsvc.exe C:\WINDOWS\system32\wdfmgr.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\brgociih.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\cmd.exe C:\WINDOWS\System32\wbem\wmiprvse.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\migicons.exe FOUND ! C:\WINDOWS\system32\1024\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kyle Phan »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kyle Phan\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\KYLEPH~1\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "bestreak"="{874443fe-aa33-4ebf-a6ac-73208787e62d}" »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="onlmcdmg.dll" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: HP EN1207D-TX PCI 10/100 Fast Ethernet Adapter DNS Server Search Order: 192.168.0.1 DNS Server Search Order: 205.171.3.65 HKLM\SYSTEM\CCS\Services\Tcpip\..\{B5B67EE9-283E-473D-AAAE-98A27A8A2619}: DhcpNameServer=192.168.0.1 [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{B5B67EE9-283E-473D-AAAE-98A27A8A2619}: DhcpNameServer=192.168.0.1 [removed] HKLM\SYSTEM\CS3\Services\Tcpip\..\{B5B67EE9-283E-473D-AAAE-98A27A8A2619}: DhcpNameServer=192.168.0.1 [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1 [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1 [removed] HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1 [removed] »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
yeah here you go, sorry it took forever. it kept freezing up on me.

ComboFix 07-11-19.3 - Kyle Phan 2007-11-21 20:42:32.8 - FAT32x86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-10-22 to 2007-11-22 )))))))))))))))))))))))))))))))
.

2007-11-21 15:04 d–hs—- C:\FOUND.024
2007-11-21 12:23 53,248 –a—— C:\WINDOWS\SYSTEM32\Process.exe
2007-11-21 11:30 2,518 –a—— C:\WINDOWS\SYSTEM32\tmp.reg
2007-11-21 11:30 0 –a—— C:\WINDOWS\SYSTEM32\tmp.txt
2007-11-21 11:29 288,417 –a—— C:\WINDOWS\SYSTEM32\SrchSTS.exe
2007-11-21 11:29 25,600 –a—— C:\WINDOWS\SYSTEM32\WS2Fix.exe
2007-11-20 23:46 24,576 –a—— C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
2007-11-20 22:33 80,960 –a—— C:\WINDOWS\SYSTEM32\xhsqjtxv.dll
2007-11-20 22:26 85,056 –a—— C:\WINDOWS\SYSTEM32\apmojfhi.dll
2007-11-20 22:26 71,232 –a—— C:\WINDOWS\SYSTEM32\cpchljyf.exe
2007-11-19 19:48 83,008 –a—— C:\WINDOWS\SYSTEM32\grovhuux.dll
2007-11-19 19:45 85,056 –a—— C:\WINDOWS\SYSTEM32\tdevftqi.dll
2007-11-19 19:42 71,232 –a—— C:\WINDOWS\SYSTEM32\ydcqeeur.exe
2007-11-19 16:17 685,712 —hs—- C:\WINDOWS\SYSTEM32\juclrwnp.ini
2007-11-19 16:17 85,056 –a—— C:\WINDOWS\SYSTEM32\pnwrlcuj.dll
2007-11-19 16:14 83,008 –a—— C:\WINDOWS\SYSTEM32\ffdaxrjt.dll
2007-11-19 16:08 71,232 –a—— C:\WINDOWS\SYSTEM32\gbvqqbrk.exe
2007-11-18 16:57 79,424 –a—— C:\WINDOWS\SYSTEM32\fbdjhxgh.dll
2007-11-18 16:52 677,920 —hs—- C:\WINDOWS\SYSTEM32\xfdretka.ini
2007-11-18 16:51 85,056 –a—— C:\WINDOWS\SYSTEM32\akterdfx.dll
2007-11-18 16:47 71,232 –a—— C:\WINDOWS\SYSTEM32\vhwtffan.exe
2007-11-18 11:35 79,424 –a—— C:\WINDOWS\SYSTEM32\vwhigtkm.dll
2007-11-18 11:32 677,920 —hs—- C:\WINDOWS\SYSTEM32\obxkmcim.ini
2007-11-18 11:32 85,056 –a—— C:\WINDOWS\SYSTEM32\micmkxbo.dll
2007-11-18 11:31 71,232 –a—— C:\WINDOWS\SYSTEM32\ecqpsefi.exe
2007-11-17 13:46 82,496 –a—— C:\WINDOWS\SYSTEM32\sjbagfbf.dll
2007-11-17 13:43 678,100 —hs—- C:\WINDOWS\SYSTEM32\jubwlmri.ini
2007-11-16 22:28 82,496 –a—— C:\WINDOWS\SYSTEM32\lwqfofan.dll
2007-11-16 22:24 71,232 –a—— C:\WINDOWS\SYSTEM32\vqmssrwc.exe
2007-11-16 22:14 d——– C:\Program Files\Trend Micro
2007-11-16 22:00 81,984 –a—— C:\WINDOWS\SYSTEM32\goibqcqw.dll
2007-11-16 21:56 71,232 –a—— C:\WINDOWS\SYSTEM32\akoswhgr.exe
2007-11-15 19:46 79,936 –a—— C:\WINDOWS\SYSTEM32\cfmkkfqh.dll
2007-11-15 19:43 677,920 —hs—- C:\WINDOWS\SYSTEM32\dcpmeddt.ini
2007-11-15 15:46 669,569 —hs—- C:\WINDOWS\SYSTEM32\xlyybbxy.ini
2007-11-14 22:02 79,424 –a—— C:\WINDOWS\SYSTEM32\mfrstpth.dll
2007-11-14 20:52 d——– C:\Program Files\Spyware Doctor
2007-11-14 20:52 d——– C:\Documents and Settings\Kyle Phan\Application Data\PC Tools
2007-11-14 20:52 626,688 –a—— C:\WINDOWS\SYSTEM32\msvcr80.dll
2007-11-14 20:52 79,688 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\iksyssec.sys
2007-11-14 20:52 62,280 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\iksysflt.sys
2007-11-14 20:52 41,288 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\ikfilesec.sys
2007-11-14 20:52 29,000 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\kcom.sys
2007-11-13 22:36 668,993 —hs—- C:\WINDOWS\SYSTEM32\egeywper.ini
2007-11-13 22:36 85,056 –a—— C:\WINDOWS\SYSTEM32\repwyege.dll
2007-11-13 22:30 81,472 –a—— C:\WINDOWS\SYSTEM32\wcadtrwu.dll
2007-11-13 19:52 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-13 19:51 d——– C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-11-13 17:41 669,023 —hs—- C:\WINDOWS\SYSTEM32\vlywysda.ini
2007-11-13 17:41 80,448 –a—— C:\WINDOWS\SYSTEM32\xqpvfcov.dll
2007-11-11 11:42 147,456 –a—— C:\WINDOWS\SYSTEM32\vbzip10.dll
2007-11-11 11:38 36,352 ——— C:\WINDOWS\SYSTEM32\ddcyayv.dll
2007-11-11 11:02 d——– C:\Documents and Settings\All Users\Application Data\TEMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 20:43 85,056 —-a-w C:\WINDOWS\SYSTEM32\irmlwbuj.dll
2007-11-17 20:38 71,232 —-a-w C:\WINDOWS\SYSTEM32\brgociih.exe
2007-11-15 22:47 85,056 —-a-w C:\WINDOWS\SYSTEM32\yxbbyylx.dll
2007-11-15 05:11 22 —-a-w C:\WINDOWS\FONTS\a.zip
2007-11-14 00:41 85,056 —-a-w C:\WINDOWS\SYSTEM32\adsywylv.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\dllcache\shell32.dll
2007-10-25 17:26 53,248 —-a-w C:\WINDOWS\bdoscandel.exe
2007-10-19 02:38 ——— d—–w C:\Program Files\Replay Media Catcher
2007-10-08 21:57 ——— d—–w C:\Program Files\NCH Software
2007-09-06 06:22 289,144 —-a-w C:\WINDOWS\SYSTEM32\VCCLSID.exe
2007-08-23 04:21 105,688 —-a-w C:\Documents and Settings\Kyle Phan\Application Data\GDIPFONTCACHEV1.DAT
2005-12-14 00:37 117 —-a-w C:\Documents and Settings\Kyle Phan\Application Data\fusioncache.dat
2002-10-04 22:09 204,800 —-a-w C:\WINDOWS\inf\FXPlugin.dll
2000-06-16 19:26 271 –sh–w C:\Program Files\desktop.ini
2000-06-16 19:26 23,357 —h–w C:\Program Files\folder.htt
2004-03-08 02:03 8 –sh–w C:\WINDOWS\DRM\pdrm.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{12730779-9093-CB32-B7A1-C059D485F2BD}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4C6D130D-8EB1-8A43-C006-DA98CB10F2BD}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4F245171-9D9B-C331-B7A1-C059D485F2BA}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B147E087-6294-49C9-AAC8-D27B7A307241}]
C:\WINDOWS\system32\oppmk.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DE38F2F2-6C1F-33BB-3BB9-61F3CD436FE4}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"Washer"="C:\Program Files\Washer\washer.exe" [2002-12-12 17:00]
"Necl"="C:\Program Files\dolo\sunu.exe" []
"Ohtco"="C:\WINDOWS\system32\m?config.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 05:17]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 12:05]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 18:18]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2005-08-10 12:49]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-01-11 19:58]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-08 20:19]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" []
"dvjvpux"="C:\WINDOWS\dvjvpux.exe" []
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]
"McRegWiz"="c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe" [2003-09-02 15:41]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"MOSearch"="C:\PROGRA~1\COMMON~1\System\MOSearch\Bin\mosearch.exe" [2001-01-19 15:28]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\Money Express.exe" [1999-08-04 00:00]
"ctfmon.exe"="ctfmon.exe" [2004-08-04 02:56 C:\WINDOWS\SYSTEM32\ctfmon.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=onlmcdmg.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online Tray Icon.lnk]
backup=C:\WINDOWS\pss\America Online Tray Icon.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
backup=C:\WINDOWS\pss\AOL Companion.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AWMON]
2005-05-25 12:12 517632 –a—— C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bndzuv]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Crrvve]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 02:56 15360 –a—— C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
rundll32.exe C:\PROGRA~1\AIM\\DeadAIM.ocm,ExportedCheckODLs

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dinst]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dzfyy]
2007-03-14 00:31 135168 –a—— C:\WINDOWS\system32\j?vaw.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
2005-09-22 18:29 303104 –a—— c:\PROGRA~1\mcafee.com\agent\mcagent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
2006-01-11 12:05 212992 –a—— C:\PROGRA~1\mcafee.com\agent\McUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
1999-08-04 00:00 122940 –a—— C:\Program Files\Microsoft Money\System\Money Express.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Necl]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2003-07-13 02:49 155648 –a—— C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ohtco]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\oq5tug96]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\regsync]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\richup]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
2006-05-08 05:17 81920 –a—— C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2004-12-06 21:31 36975 –a—— C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SurfSideKick 3]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemTray]
SysTray.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TizzleTalk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
2005-08-10 12:49 163840 –a—— c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe /checktask

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Washer]
C:\Program Files\Washer\washer.exe /0

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeirdOnTheWeb]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winupdates]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\You've Got Pictures Screensaver]
2004-05-07 16:54 99456 –a—— C:\Program Files\Common Files\AOL\Screensaver\ygpsstra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zanu]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"HPScanPatch"=C:\WINDOWS\SYSTEM32\HPScanFix.exe
"MMTray"=
"hpsysdrv"=C:\WINDOWS\SYSTEM32\hpsysdrv.exe
"Delay"=C:\WINDOWS\delayrun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2007-11-08 06:00:02 C:\WINDOWS\Tasks\Tune-up Application Start.job"
"2007-11-22 04:07:46 C:\WINDOWS\Tasks\PCHealth Scheduler for Data Collection.job"
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-21 20:48:23
Windows 5.1.2600 Service Pack 2 FAT NTAPI

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-21 21:15:26
Wow that is quite the collection of Malware you have there. Let's try to get it cleaned up.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\SYSTEM32\xhsqjtxv.dll
C:\WINDOWS\SYSTEM32\apmojfhi.dll
C:\WINDOWS\SYSTEM32\cpchljyf.exe
C:\WINDOWS\SYSTEM32\grovhuux.dll
C:\WINDOWS\SYSTEM32\tdevftqi.dll
C:\WINDOWS\SYSTEM32\ydcqeeur.exe
C:\WINDOWS\SYSTEM32\juclrwnp.ini
C:\WINDOWS\SYSTEM32\pnwrlcuj.dll
C:\WINDOWS\SYSTEM32\ffdaxrjt.dll
C:\WINDOWS\SYSTEM32\gbvqqbrk.exe
C:\WINDOWS\SYSTEM32\fbdjhxgh.dll
C:\WINDOWS\SYSTEM32\xfdretka.ini
C:\WINDOWS\SYSTEM32\akterdfx.dll
C:\WINDOWS\SYSTEM32\vhwtffan.exe
C:\WINDOWS\SYSTEM32\vwhigtkm.dll
C:\WINDOWS\SYSTEM32\obxkmcim.ini
C:\WINDOWS\SYSTEM32\micmkxbo.dll
C:\WINDOWS\SYSTEM32\ecqpsefi.exe
C:\WINDOWS\SYSTEM32\sjbagfbf.dll
C:\WINDOWS\SYSTEM32\jubwlmri.ini
C:\WINDOWS\SYSTEM32\lwqfofan.dll
C:\WINDOWS\SYSTEM32\vqmssrwc.exe
C:\WINDOWS\SYSTEM32\goibqcqw.dll
C:\WINDOWS\SYSTEM32\akoswhgr.exe
C:\WINDOWS\SYSTEM32\cfmkkfqh.dll
C:\WINDOWS\SYSTEM32\dcpmeddt.ini
C:\WINDOWS\SYSTEM32\xlyybbxy.ini
C:\WINDOWS\SYSTEM32\mfrstpth.dll
C:\WINDOWS\SYSTEM32\egeywper.ini
C:\WINDOWS\SYSTEM32\repwyege.dll
C:\WINDOWS\SYSTEM32\wcadtrwu.dll
C:\WINDOWS\SYSTEM32\vlywysda.ini
C:\WINDOWS\SYSTEM32\xqpvfcov.dll
C:\WINDOWS\SYSTEM32\vbzip10.dll
C:\WINDOWS\SYSTEM32\ddcyayv.dll
C:\WINDOWS\SYSTEM32\irmlwbuj.dll
C:\WINDOWS\SYSTEM32\brgociih.exe
C:\WINDOWS\SYSTEM32\yxbbyylx.dll
C:\WINDOWS\FONTS\a.zip
C:\WINDOWS\SYSTEM32\adsywylv.dll
C:\WINDOWS\system32\oppmk.dll
C:\WINDOWS\system32\m?config.exe
C:\WINDOWS\dvjvpux.exe
C:\WINDOWS\system32\onlmcdmg.dll
C:\WINDOWS\system32\j?vaw.exe

Folder::
C:\Program Files\dolo

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{12730779-9093-CB32-B7A1-C059D485F2BD}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4C6D130D-8EB1-8A43-C006-DA98CB10F2BD}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4F245171-9D9B-C331-B7A1-C059D485F2BA}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B147E087-6294-49C9-AAC8-D27B7A307241}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DE38F2F2-6C1F-33BB-3BB9-61F3CD436FE4}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Necl"=-
"Ohtco"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dvjvpux"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bndzuv]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Crrvve]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dinst]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dzfyy]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Necl]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ohtco]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\oq5tug96]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\regsync]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\richup]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SurfSideKick 3]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TizzleTalk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeirdOnTheWeb]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winupdates]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zanu]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
ComboFix 07-11-19.3 - Kyle Phan 2007-11-24 16:24:33.11 - FAT32x86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Kyle Phan\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\dvjvpux.exe
C:\WINDOWS\FONTS\a.zip
C:\WINDOWS\SYSTEM32\adsywylv.dll
C:\WINDOWS\SYSTEM32\akoswhgr.exe
C:\WINDOWS\SYSTEM32\akterdfx.dll
C:\WINDOWS\SYSTEM32\apmojfhi.dll
C:\WINDOWS\SYSTEM32\brgociih.exe
C:\WINDOWS\SYSTEM32\cfmkkfqh.dll
C:\WINDOWS\SYSTEM32\cpchljyf.exe
C:\WINDOWS\SYSTEM32\dcpmeddt.ini
C:\WINDOWS\SYSTEM32\ddcyayv.dll
C:\WINDOWS\SYSTEM32\ecqpsefi.exe
C:\WINDOWS\SYSTEM32\egeywper.ini
C:\WINDOWS\SYSTEM32\fbdjhxgh.dll
C:\WINDOWS\SYSTEM32\ffdaxrjt.dll
C:\WINDOWS\SYSTEM32\gbvqqbrk.exe
C:\WINDOWS\SYSTEM32\goibqcqw.dll
C:\WINDOWS\SYSTEM32\grovhuux.dll
C:\WINDOWS\SYSTEM32\irmlwbuj.dll
C:\WINDOWS\SYSTEM32\jubwlmri.ini
C:\WINDOWS\SYSTEM32\juclrwnp.ini
C:\WINDOWS\SYSTEM32\lwqfofan.dll
C:\WINDOWS\SYSTEM32\mfrstpth.dll
C:\WINDOWS\SYSTEM32\micmkxbo.dll
C:\WINDOWS\SYSTEM32\obxkmcim.ini
C:\WINDOWS\system32\onlmcdmg.dll
C:\WINDOWS\system32\oppmk.dll
C:\WINDOWS\SYSTEM32\pnwrlcuj.dll
C:\WINDOWS\SYSTEM32\repwyege.dll
C:\WINDOWS\SYSTEM32\sjbagfbf.dll
C:\WINDOWS\SYSTEM32\tdevftqi.dll
C:\WINDOWS\SYSTEM32\vbzip10.dll
C:\WINDOWS\SYSTEM32\vhwtffan.exe
C:\WINDOWS\SYSTEM32\vlywysda.ini
C:\WINDOWS\SYSTEM32\vqmssrwc.exe
C:\WINDOWS\SYSTEM32\vwhigtkm.dll
C:\WINDOWS\SYSTEM32\wcadtrwu.dll
C:\WINDOWS\SYSTEM32\xfdretka.ini
C:\WINDOWS\SYSTEM32\xhsqjtxv.dll
C:\WINDOWS\SYSTEM32\xlyybbxy.ini
C:\WINDOWS\SYSTEM32\xqpvfcov.dll
C:\WINDOWS\SYSTEM32\ydcqeeur.exe
C:\WINDOWS\SYSTEM32\yxbbyylx.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\Program Files\dolo
C:\WINDOWS\FONTS\a.zip
C:\WINDOWS\SYSTEM32\adsywylv.dll
C:\WINDOWS\SYSTEM32\akoswhgr.exe
C:\WINDOWS\SYSTEM32\akterdfx.dll
C:\WINDOWS\SYSTEM32\apmojfhi.dll
C:\WINDOWS\SYSTEM32\brgociih.exe
C:\WINDOWS\SYSTEM32\cfmkkfqh.dll
C:\WINDOWS\SYSTEM32\cpchljyf.exe
C:\WINDOWS\SYSTEM32\dcpmeddt.ini
C:\WINDOWS\SYSTEM32\ddcyayv.dll
C:\WINDOWS\SYSTEM32\ecqpsefi.exe
C:\WINDOWS\SYSTEM32\egeywper.ini
C:\WINDOWS\SYSTEM32\fbdjhxgh.dll
C:\WINDOWS\SYSTEM32\ffdaxrjt.dll
C:\WINDOWS\SYSTEM32\gbvqqbrk.exe
C:\WINDOWS\SYSTEM32\goibqcqw.dll
C:\WINDOWS\SYSTEM32\grovhuux.dll
C:\WINDOWS\SYSTEM32\irmlwbuj.dll
C:\WINDOWS\SYSTEM32\jubwlmri.ini
C:\WINDOWS\SYSTEM32\juclrwnp.ini
C:\WINDOWS\SYSTEM32\lwqfofan.dll
C:\WINDOWS\SYSTEM32\mfrstpth.dll
C:\WINDOWS\SYSTEM32\micmkxbo.dll
C:\WINDOWS\SYSTEM32\obxkmcim.ini
C:\WINDOWS\SYSTEM32\pnwrlcuj.dll
C:\WINDOWS\SYSTEM32\repwyege.dll
C:\WINDOWS\SYSTEM32\sjbagfbf.dll
C:\WINDOWS\SYSTEM32\tdevftqi.dll
C:\WINDOWS\SYSTEM32\vbzip10.dll
C:\WINDOWS\SYSTEM32\vhwtffan.exe
C:\WINDOWS\SYSTEM32\vlywysda.ini
C:\WINDOWS\SYSTEM32\vqmssrwc.exe
C:\WINDOWS\SYSTEM32\vwhigtkm.dll
C:\WINDOWS\SYSTEM32\wcadtrwu.dll
C:\WINDOWS\SYSTEM32\xfdretka.ini
C:\WINDOWS\SYSTEM32\xhsqjtxv.dll
C:\WINDOWS\SYSTEM32\xlyybbxy.ini
C:\WINDOWS\SYSTEM32\xqpvfcov.dll
C:\WINDOWS\SYSTEM32\ydcqeeur.exe
C:\WINDOWS\SYSTEM32\yxbbyylx.dll

.
((((((((((((((((((((((((( Files Created from 2007-10-24 to 2007-11-24 )))))))))))))))))))))))))))))))
.

2007-11-23 23:42 d–hs—- C:\FOUND.025
2007-11-21 15:04 d–hs—- C:\FOUND.024
2007-11-21 12:23 53,248 –a—— C:\WINDOWS\SYSTEM32\Process.exe
2007-11-21 11:30 0 –a—— C:\WINDOWS\SYSTEM32\tmp.txt
2007-11-20 23:46 24,576 –a—— C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
2007-11-20 22:32 d——– C:\VundoFix Backups
2007-11-16 22:14 d——– C:\Program Files\Trend Micro
2007-11-14 21:55 d——– C:\WINDOWS\BDOSCAN8
2007-11-14 20:52 d——– C:\Program Files\Spyware Doctor
2007-11-14 20:52 d——– C:\Documents and Settings\Kyle Phan\Application Data\PC Tools
2007-11-14 20:52 79,688 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\iksyssec.sys
2007-11-14 20:52 62,280 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\iksysflt.sys
2007-11-14 20:52 41,288 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\ikfilesec.sys
2007-11-14 20:52 29,000 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\kcom.sys
2007-11-13 22:21 d–hs—- C:\FOUND.023
2007-11-13 19:52 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-13 19:51 d——– C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-11-11 13:19 d–hs—- C:\FOUND.022
2007-11-11 11:02 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-07 22:54 d–hs—- C:\FOUND.021
2007-10-25 10:26 53,248 –a—— C:\WINDOWS\bdoscandel.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\dllcache\shell32.dll
2007-10-19 02:38 ——— d—–w C:\Program Files\Replay Media Catcher
2007-10-08 21:57 ——— d—–w C:\Program Files\NCH Software
2007-10-04 06:36 25,600 —-a-w C:\WINDOWS\SYSTEM32\WS2Fix.exe
2007-09-06 06:22 289,144 —-a-w C:\WINDOWS\SYSTEM32\VCCLSID.exe
2007-08-23 04:21 105,688 —-a-w C:\Documents and Settings\Kyle Phan\Application Data\GDIPFONTCACHEV1.DAT
2005-12-14 00:37 117 —-a-w C:\Documents and Settings\Kyle Phan\Application Data\fusioncache.dat
2002-10-04 22:09 204,800 —-a-w C:\WINDOWS\inf\FXPlugin.dll
2000-06-16 19:26 271 –sh–w C:\Program Files\desktop.ini
2000-06-16 19:26 23,357 —h–w C:\Program Files\folder.htt
2004-03-08 02:03 8 –sh–w C:\WINDOWS\DRM\pdrm.dat
.

((((((((((((((((((((((((((((( snapshot@2007-11-21_12.51.24.81 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-13 17:57:12 163,328 —-a-w C:\WINDOWS\erdnt\subs\F3M\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 05:17]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2006-01-11 12:05]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 18:18]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2005-08-10 12:49]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-01-11 19:58]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-08 20:19]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" []
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]
"McRegWiz"="c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe" [2003-09-02 15:41]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"MOSearch"="C:\PROGRA~1\COMMON~1\System\MOSearch\Bin\mosearch.exe" [2001-01-19 15:28]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\Money Express.exe" [1999-08-04 00:00]
"ctfmon.exe"="ctfmon.exe" [2004-08-04 02:56 C:\WINDOWS\SYSTEM32\ctfmon.exe]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online Tray Icon.lnk]
backup=C:\WINDOWS\pss\America Online Tray Icon.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
backup=C:\WINDOWS\pss\AOL Companion.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AWMON]
2005-05-25 12:12 517632 –a—— C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 02:56 15360 –a—— C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
rundll32.exe C:\PROGRA~1\AIM\\DeadAIM.ocm,ExportedCheckODLs

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
2005-09-22 18:29 303104 –a—— c:\PROGRA~1\mcafee.com\agent\mcagent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
2006-01-11 12:05 212992 –a—— C:\PROGRA~1\mcafee.com\agent\McUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
1999-08-04 00:00 122940 –a—— C:\Program Files\Microsoft Money\System\Money Express.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2003-07-13 02:49 155648 –a—— C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
2006-05-08 05:17 81920 –a—— C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2004-12-06 21:31 36975 –a—— C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemTray]
SysTray.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
2005-08-10 12:49 163840 –a—— c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe /checktask

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Washer]
C:\Program Files\Washer\washer.exe /0

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\You've Got Pictures Screensaver]
2004-05-07 16:54 99456 –a—— C:\Program Files\Common Files\AOL\Screensaver\ygpsstra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zanu]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"HPScanPatch"=C:\WINDOWS\SYSTEM32\HPScanFix.exe
"MMTray"=
"hpsysdrv"=C:\WINDOWS\SYSTEM32\hpsysdrv.exe
"Delay"=C:\WINDOWS\delayrun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2007-11-08 06:00:02 C:\WINDOWS\Tasks\Tune-up Application Start.job"
"2007-11-24 23:59:30 C:\WINDOWS\Tasks\PCHealth Scheduler for Data Collection.job"
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-24 16:59:25
Windows 5.1.2600 Service Pack 2 FAT NTAPI

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-24 17:12:50
C:\ComboFix2.txt … 2007-11-21 21:15
.
— E O F —









Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:15:07 PM, on 11/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\DRIVERS\dcfssvc.exe
C:\WINDOWS\system32\gearsec.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hp.my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://hp.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R3 - URLSearchHook: (no name) - {BC0B0C61-91D3-952D-F0B5-912CF0690BB9} - (no file)
R3 - URLSearchHook: (no name) - {C29A683D-FBDD-F828-FC35-F9EA6CB074E6} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: (no name) - {80FA69EA-2207-8A57-DB23-5422B5E56BC9} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKLM\..\RunServices: [MOSearch] C:\PROGRA~1\COMMON~1\System\MOSearch\Bin\mosearch.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'Default user')
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.pw.aol.com/molbin/shared/m…77/mcinsctl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O22 - SharedTaskScheduler: {874443fe-aa33-4ebf-a6ac-73208787e62d} - bestreak - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: dcfssvc (Dcfssvc) - Eastman Kodak Company - C:\WINDOWS\system32\DRIVERS\dcfssvc.exe
O23 - Service: gearsec - GEAR Software - C:\WINDOWS\system32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe

–
End of file - 9326 bytes
Run HijackThis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R3 - URLSearchHook: (no name) - {BC0B0C61-91D3-952D-F0B5-912CF0690BB9} - (no file)
R3 - URLSearchHook: (no name) - {C29A683D-FBDD-F828-FC35-F9EA6CB074E6} - (no file)
O3 - Toolbar: (no name) - {80FA69EA-2207-8A57-DB23-5422B5E56BC9} - (no file)
O22 - SharedTaskScheduler: {874443fe-aa33-4ebf-a6ac-73208787e62d} - bestreak - (no file)

Then close all windows except this one and press Fix checked.

——————————————————————————

Update Java Runtime:

You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, and also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6 Update 3.
  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Click on the link named Java Runtime Environment (JRE) 6 Update 3
  • Click on the radio button to Accept License Agreement
  • Click on Windows Offline Installation, Multi-language and save the downloaded file to your hard disk
  • Go to Start => Control Panel => Add or Remove Programs
  • Uninstall all old versions of Java (Java 2 Runtime Environment, JRE or JSE)
  • Reboot your computer
  • Delete the folder C:\Program Files\Java if present
  • Install the new version by running the newly-downloaded file, and follow the on-screen instructions.
  • Reboot your computer

——————————–

Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open.

If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-click on avgas-signatures-full-current.exe to install the database).
Please set up the program as follows:
  • Click the Shield icon at the top and under Resident shield is… click active. This should now
    change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
  • Under How to act? - make sure that Quarantine is selected.
  • Under How to scan? - All checkboxes should be ticked.
  • Under Possibly unwanted software - All checkboxes should be ticked.
  • Under Reports - Select Do not automatically generate reports.
  • Under What to scan? - Select Scan every file.
Close all open windows.



Please download ATF Cleaner here by Atribune. This program is for XP and Windows 2000 only.
It does not require any installation and uses minimal system resources. It is set up to clean IE, FireFox and Opera, and detects the browsers you have and grays out the other(s).
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Recommend UNCHECKING COOKIES if you rely on system remembered passwords.
  • Click the Empty Selected button.

    If you use Firefox browser
  • Click Firefox at the top and choose: Select All EXCEPT FIREFOX SAVED PASSWORDS
  • Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser
  • Click Opera at the top and choose: Select All EXCEPT COOKIES AND SAVED PASSWORDS
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your cookies and saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


We Now Need To Boot Into Safemode Now

Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine,
amount of memory, hard drives installed etc (BOOT SCREEEN).
At this point you should gently tap the F8 key repeatedly until you are presented with a Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode.


Run AVG


  • Click on Scanner on the toolbar.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
    • Make sure that Set all elements to: shows Quarantine
    • Important: Click on the Apply all Actions button This must done before saving the report
    • When the program has finished, it will display the message All actions have been applied.
    • Then click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
      [external image: Posted Image]
  • Right-click the AVG Tray Icon and select Exit.
  • Now copy the report back to this topic.


Restart into normal mode and post the AVG Log.

————————————————————–

Using Internet Explorer, click on Kaspersky Online Scanner * Click 'Accept' in the window that pops up.
* You will be prompted to install an ActiveX component from Kaspersky, Click on the information bar and select Install ActiveX Control if so. This may happen more than once. That is OK. You also may get a warning from your Windows Firewall. You can tell it to unblock.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save Report As…' button:
* Make sure it says Save as a text file - change it if not
* Save the file to your desktop.
Please post the Kaspersky report and a new HijackThis log.
hey i'm still doing all the thing you told me to. i'm just having problems with my safe mode. everytime i get there, it just freezes up.
Is it running OK in Normal Mode? If so go ahead and run AVG in Normal Mode anyway. At what point does it lock up in Safe Mode? Does it boot into Windows? Does it run for a little while?
yeah its ok in normal mode. so when i got in safe mode, it loads up and everything. but it won't let me go in the start menu. when i put the mouse in it, it says it still loading. i left it on for an hour and it still says its loading.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI