This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] best seller antivirus pop up

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

here the AVG. it changed the appearance of my destops task bar. its not XP like anymore, but all clear and white. how do i change it blue again? ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 3:43:07 PM 12/1/2007 + Scan result: C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined). C:\VundoFix Backups\srhnjlsa.exe.bad -> Downloader.Tiny.id : Cleaned with backup (quarantined). C:\Program Files\LimeWire\f.exe -> Not-A-Virus.PSWTool.Win32.FirePass.a : Cleaned with backup (quarantined). :mozilla.133:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Coremetrics : Cleaned. :mozilla.51:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Doubleclick : Cleaned. :mozilla.114:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Esomniture : Cleaned. :mozilla.115:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Esomniture : Cleaned. :mozilla.128:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Esomniture : Cleaned. :mozilla.135:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Esomniture : Cleaned. :mozilla.137:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Esomniture : Cleaned. :mozilla.138:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Esomniture : Cleaned. :mozilla.139:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Esomniture : Cleaned. :mozilla.88:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Esomniture : Cleaned. :mozilla.134:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Googleadservices : Cleaned. :mozilla.136:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Googleadservices : Cleaned. :mozilla.154:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Googleadservices : Cleaned. :mozilla.157:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Googleadservices : Cleaned. :mozilla.169:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Googleadservices : Cleaned. :mozilla.181:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Googleadservices : Cleaned. :mozilla.189:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Googleadservices : Cleaned. :mozilla.121:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned. :mozilla.122:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned. :mozilla.123:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned. :mozilla.192:C:\FOUND.018\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned. C:\WINDOWS\SYSTEM32\1024 -> Trojan.Small : Cleaned with backup (quarantined). ::Report end
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Saturday, December 01, 2007 8:06:30 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 2/12/2007
Kaspersky Anti-Virus database records: 470049
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\

Scan Statistics:
Total number of scanned objects: 76043
Number of viruses found: 12
Number of infected objects: 60
Number of suspicious objects: 0
Duration of the scan process: 01:53:12

Infected Object Name / Virus Name / Last Action
C:\WINDOWS\SYSTEM32\wbem\REPOSITORY\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\REPOSITORY\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\REPOSITORY\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\REPOSITORY\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\REPOSITORY\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\REPOSITORY\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\REPOSITORY\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\config\system.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\software.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\default.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\config\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\dytltnfx.dll_old Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\h323log.txt Object is locked skipped
C:\WINDOWS\All Users\Documents\AOL Downloads\America Online 9.0b\package_adp_SIAC.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\WINDOWS\All Users\Documents\AOL Downloads\America Online 9.0b\package_adp_SIAC.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped
C:\WINDOWS\All Users\Documents\AOL Downloads\America Online 9.0b\package_adp_SIAC.exe/stream/data0003 Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped
C:\WINDOWS\All Users\Documents\AOL Downloads\America Online 9.0b\package_adp_SIAC.exe/stream/data0005/stream/data0002 Infected: not-a-virus:AdWare.Win32.BargainBuddy.y skipped
C:\WINDOWS\All Users\Documents\AOL Downloads\America Online 9.0b\package_adp_SIAC.exe/stream/data0005/stream/data0005 Infected: not-a-virus:AdWare.Win32.BargainBuddy.aa skipped
C:\WINDOWS\All Users\Documents\AOL Downloads\America Online 9.0b\package_adp_SIAC.exe/stream/data0005/stream Infected: not-a-virus:AdWare.Win32.BargainBuddy.aa skipped
C:\WINDOWS\All Users\Documents\AOL Downloads\America Online 9.0b\package_adp_SIAC.exe/stream/data0005 Infected: not-a-virus:AdWare.Win32.BargainBuddy.aa skipped
C:\WINDOWS\All Users\Documents\AOL Downloads\America Online 9.0b\package_adp_SIAC.exe/stream Infected: not-a-virus:AdWare.Win32.BargainBuddy.aa skipped
C:\WINDOWS\All Users\Documents\AOL Downloads\America Online 9.0b\package_adp_SIAC.exe NSIS: infected - 8 skipped
C:\WINDOWS\SchedLog.Txt Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\Program Files\Mozilla Firefox\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\VundoFix Backups\cayuiwhn.dll.bad Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\VundoFix Backups\ddcyayv.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.ajq skipped
C:\VundoFix Backups\dytltnfx.dll.bad Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\adsywylv.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\akoswhgr.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\akterdfx.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\apmojfhi.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\brgociih.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\cpchljyf.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\ddcyayv.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.ajq skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\ecqpsefi.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\gbvqqbrk.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\irmlwbuj.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\micmkxbo.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\pnwrlcuj.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\repwyege.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\tdevftqi.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\vhwtffan.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\vqmssrwc.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\wcadtrwu.dll.vir Infected: Trojan.Win32.BHO.xe skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\ydcqeeur.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\yxbbyylx.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\Install\PC DJ Mixing Software\PCDJ.exe Infected: not-a-virus:AdWare.Win32.TimeSink.d skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee.com\VSO\OASLogs\OAS.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\Logs\TaskScheduler\McTskshd000.log Object is locked skipped
C:\Documents and Settings\Kyle Phan\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Kyle Phan\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Kyle Phan\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Kyle Phan\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Kyle Phan\Desktop\bestsellerantivirus remover\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Kyle Phan\Desktop\bestsellerantivirus remover\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Kyle Phan\Desktop\bestsellerantivirus remover\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Kyle Phan\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Kyle Phan\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Kyle Phan\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Kyle Phan\Application Data\Mozilla\Firefox\Profiles\bejyqwo5.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Kyle Phan\Application Data\Mozilla\Firefox\Profiles\bejyqwo5.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Kyle Phan\Application Data\Mozilla\Firefox\Profiles\bejyqwo5.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Kyle Phan\Application Data\Mozilla\Firefox\Profiles\bejyqwo5.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Kyle Phan\Application Data\Mozilla\Firefox\Profiles\bejyqwo5.default\history.dat Object is locked skipped
C:\Documents and Settings\Kyle Phan\Application Data\Mozilla\Firefox\Profiles\bejyqwo5.default\parent.lock Object is locked skipped
C:\Documents and Settings\Kyle Phan\Application Data\Mozilla\Firefox\Profiles\bejyqwo5.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Kyle Phan\Application Data\Mozilla\Firefox\Profiles\bejyqwo5.default\GoogleToolbarData\googlesafebrowsing.db Object is locked skipped
C:\Documents and Settings\Kyle Phan\Application Data\Mozilla\Firefox\Profiles\bejyqwo5.default\cert8.db Object is locked skipped
C:\Documents and Settings\Kyle Phan\Application Data\Mozilla\Firefox\Profiles\bejyqwo5.default\key3.db Object is locked skipped
C:\Documents and Settings\Kyle Phan\Application Data\Mozilla\Firefox\Profiles\bejyqwo5.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Kyle Phan\Application Data\Mozilla\Firefox\Profiles\bejyqwo5.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Kyle Phan\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Kyle Phan\ntuser.dat Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP1\A0001050.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP1\A0001051.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009208.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009209.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009210.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009211.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009212.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009214.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009216.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ajq skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009217.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009221.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009224.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009229.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009231.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009232.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009234.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009236.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009238.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009240.dll Infected: Trojan.Win32.BHO.xe skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009245.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP6\A0009246.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP12\A0014826.exe Infected: not-a-virus:PSWTool.Win32.FirePass.a skipped
C:\System Volume Information\_restore{9DB7D597-8919-460A-A50F-D58B73668C05}\RP12\change.log Object is locked skipped

Scan process completed.

















hijack this:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:09:01 PM, on 12/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\DRIVERS\dcfssvc.exe
C:\WINDOWS\system32\gearsec.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Washer\washer.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hp.my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://hp.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [dvjvpux] C:\WINDOWS\dvjvpux.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [MOSearch] C:\PROGRA~1\COMMON~1\System\MOSearch\Bin\mosearch.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Ohtco] C:\WINDOWS\system32\m?config.exe
O4 - HKCU\..\Run: [Washer] C:\Program Files\Washer\washer.exe /0
O4 - HKCU\..\Run: [Necl] "C:\Program Files\dolo\sunu.exe" -vt tzt
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'Default user')
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.pw.aol.com/molbin/shared/m…77/mcinsctl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: dcfssvc (Dcfssvc) - Eastman Kodak Company - C:\WINDOWS\system32\DRIVERS\dcfssvc.exe
O23 - Service: gearsec - GEAR Software - C:\WINDOWS\system32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe

–
End of file - 9538 bytes
Well unfortunately infections have either crept back in or you picked up some new ones….probably both :wacko: There was quite a bit of time that went by between posts so I have no way to know when or how it happened. Time is of the essence in getting these infections. If something is left and you go back online you're wide open. Back to combofix first. Remove your old version and download a fresh one please.

Download and Run ComboFix
  • Download this file from below:
    Here
  • Disable your Anti-virus and any real-time Anti-spyware monitors that are running.
  • Then double click Combofix.exe & follow the prompts.
  • When finished, it will produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
Note 2: Remember to re-enable your Anti-virus and Anti-spyware.

NOTE: If you have issues connecting to your network or internet after running combofix you can either simply reboot, or do the following:
* Going to Control Panel > Network Connections.
* Right click on their Network icons & select "Repair"
or
Alternately, if the Network icon appears in the notification area in the lower right corner of Desktop, right-click it, and then click Repair from the shortcut menu.
ComboFix 07-12-02.5 - Kyle Phan 2007-12-02 10:28:00.14 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.195 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix(2).exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\WINDOWS\FONTS\'

.
((((((((((((((((((((((((( Files Created from 2007-11-02 to 2007-12-02 )))))))))))))))))))))))))))))))
.

2007-11-30 16:59 . 2007-11-30 16:59 d–hs—- C:\FOUND.026
2007-11-27 19:43 . 2007-11-27 19:43 d——– C:\Documents and Settings\Kyle Phan\Application Data\Grisoft
2007-11-27 19:42 . 2007-11-27 19:42 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-27 19:42 . 2007-05-30 05:10 10,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-11-27 00:54 . 2007-11-27 00:54 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-11-27 00:54 . 2007-11-27 00:54 1,409 –a—— C:\WINDOWS\QTFont.for
2007-11-25 17:28 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\SYSTEM32\javacpl.cpl
2007-11-25 17:27 . 2007-11-25 17:27 d——– C:\Program Files\Java
2007-11-25 17:26 . 2007-11-25 17:26 d——– C:\Program Files\Common Files\Java
2007-11-25 14:31 . 2007-11-25 14:31 d——– C:\WINDOWS\SxsCaPendDel
2007-11-23 23:42 . 2007-11-23 23:42 d–hs—- C:\FOUND.025
2007-11-21 15:04 . 2007-11-21 15:04 d–hs—- C:\FOUND.024
2007-11-21 12:23 . 2003-06-05 20:13 53,248 –a—— C:\WINDOWS\SYSTEM32\Process.exe
2007-11-21 11:30 . 2007-11-21 11:30 2,518 –a—— C:\WINDOWS\SYSTEM32\tmp.reg
2007-11-21 11:29 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\SYSTEM32\VCCLSID.exe
2007-11-21 11:29 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\SYSTEM32\SrchSTS.exe
2007-11-21 11:29 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\SYSTEM32\dumphive.exe
2007-11-21 11:29 . 2007-10-03 23:36 25,600 –a—— C:\WINDOWS\SYSTEM32\WS2Fix.exe
2007-11-20 23:46 . 2007-11-20 23:47 24,576 –a—— C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
2007-11-20 22:32 . 2007-11-20 22:32 d——– C:\VundoFix Backups
2007-11-16 22:14 . 2007-11-16 22:14 d——– C:\Program Files\Trend Micro
2007-11-16 22:06 . 2007-11-17 13:37 678,040 —hs—- C:\WINDOWS\SYSTEM32\ulyngwja.ini
2007-11-14 22:00 . 2007-11-15 15:40 671,146 —hs—- C:\WINDOWS\SYSTEM32\qcpfdsjf.ini
2007-11-14 21:55 . 2007-11-14 21:55 d——– C:\WINDOWS\BDOSCAN8
2007-11-14 20:52 . 2007-11-14 20:52 d——– C:\Program Files\Spyware Doctor
2007-11-14 20:52 . 2007-11-14 20:52 d——– C:\Documents and Settings\Kyle Phan\Application Data\PC Tools
2007-11-14 20:52 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\SYSTEM32\msvcr80.dll
2007-11-14 20:52 . 2007-10-18 00:16 79,688 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\iksyssec.sys
2007-11-14 20:52 . 2007-10-18 00:15 62,280 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\iksysflt.sys
2007-11-14 20:52 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\ikfilesec.sys
2007-11-14 20:52 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\kcom.sys
2007-11-13 22:21 . 2007-11-13 22:21 d–hs—- C:\FOUND.023
2007-11-13 19:52 . 2007-11-13 19:52 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-13 19:51 . 2007-11-13 19:51 d——– C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-11-13 17:39 . 2007-11-13 17:39 145,984 ——— C:\WINDOWS\SYSTEM32\dytltnfx.dll_old
2007-11-11 13:19 . 2007-11-11 13:19 d–hs—- C:\FOUND.022
2007-11-11 11:02 . 2007-11-11 11:02 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-07 22:54 . 2007-11-07 22:54 d–hs—- C:\FOUND.021

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\dllcache\shell32.dll
2007-10-25 17:26 53,248 —-a-w C:\WINDOWS\bdoscandel.exe
2007-10-19 02:38 ——— d—–w C:\Program Files\Replay Media Catcher
2007-10-08 21:57 ——— d—–w C:\Program Files\NCH Software
2007-08-23 04:21 105,688 —-a-w C:\Documents and Settings\Kyle Phan\Application Data\GDIPFONTCACHEV1.DAT
2005-12-14 00:37 117 —-a-w C:\Documents and Settings\Kyle Phan\Application Data\fusioncache.dat
2002-10-04 22:09 204,800 —-a-w C:\WINDOWS\inf\FXPlugin.dll
2000-06-16 19:26 271 –sh–w C:\Program Files\desktop.ini
2000-06-16 19:26 23,357 —h–w C:\Program Files\folder.htt
2004-03-08 02:03 8 –sh–w C:\WINDOWS\DRM\pdrm.dat
.

((((((((((((((((((((((((((((( snapshot@2007-11-21_12.51.24.81 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-08 23:59:02 136,704 —-a-w C:\WINDOWS\catchme.exe
+ 2007-11-27 10:58:12 140,288 —-a-w C:\WINDOWS\catchme.exe
+ 2007-03-13 17:57:12 163,328 —-a-w C:\WINDOWS\erdnt\subs\F3M\ERDNT.EXE
+ 2007-11-25 21:32:26 295,606 —-a-r C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A81000000003}\SC_Reader.exe
- 2007-03-14 07:31:24 135,168 —-a-w C:\WINDOWS\SYSTEM32\java.exe
+ 2007-09-25 05:30:28 135,168 —-a-w C:\WINDOWS\SYSTEM32\java.exe
- 2007-03-14 07:31:28 135,168 —-a-w C:\WINDOWS\SYSTEM32\javaw.exe
+ 2007-09-25 05:30:30 135,168 —-a-w C:\WINDOWS\SYSTEM32\javaw.exe
- 2007-03-14 09:04:46 139,264 —-a-w C:\WINDOWS\SYSTEM32\javaws.exe
+ 2007-09-25 06:31:42 139,264 —-a-w C:\WINDOWS\SYSTEM32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"Ohtco"="C:\WINDOWS\system32\m?config.exe" []
"Washer"="C:\Program Files\Washer\washer.exe" [2002-12-12 17:00]
"Necl"="C:\Program Files\dolo\sunu.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-17 23:59]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 05:17]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2006-01-11 12:05]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 18:18]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2005-08-10 12:49]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-01-11 19:58]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-08 20:19]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" []
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]
"dvjvpux"="C:\WINDOWS\dvjvpux.exe" []
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
"McRegWiz"="c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe" [2003-09-02 15:41]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"MOSearch"="C:\PROGRA~1\COMMON~1\System\MOSearch\Bin\mosearch.exe" [2001-01-19 15:28]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\Money Express.exe" [1999-08-04 00:00]
"ctfmon.exe"="ctfmon.exe" [2004-08-04 02:56 C:\WINDOWS\SYSTEM32\ctfmon.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online Tray Icon.lnk]
backup=C:\WINDOWS\pss\America Online Tray Icon.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
backup=C:\WINDOWS\pss\AOL Companion.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AWMON]
2005-05-25 12:12 517632 –a—— C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 02:56 15360 –a—— C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
rundll32.exe C:\PROGRA~1\AIM\\DeadAIM.ocm,ExportedCheckODLs

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
2005-09-22 18:29 303104 –a—— c:\PROGRA~1\mcafee.com\agent\mcagent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
2006-01-11 12:05 212992 –a—— C:\PROGRA~1\mcafee.com\agent\McUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
1999-08-04 00:00 122940 –a—— C:\Program Files\Microsoft Money\System\Money Express.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2003-07-13 02:49 155648 –a—— C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
2006-05-08 05:17 81920 –a—— C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemTray]
SysTray.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
2005-08-10 12:49 163840 –a—— c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe /checktask

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Washer]
C:\Program Files\Washer\washer.exe /0

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\You've Got Pictures Screensaver]
2004-05-07 16:54 99456 –a—— C:\Program Files\Common Files\AOL\Screensaver\ygpsstra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zanu]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"HPScanPatch"=C:\WINDOWS\SYSTEM32\HPScanFix.exe
"MMTray"=
"hpsysdrv"=C:\WINDOWS\SYSTEM32\hpsysdrv.exe
"Delay"=C:\WINDOWS\delayrun.exe

R2 gearsec;gearsec;C:\WINDOWS\system32\gearsec.exe
R2 SVKP;SVKP;\??\C:\WINDOWS\system32\SVKP.sys
R3 crtaud;Conexant Riptide WDM Audio Driver;C:\WINDOWS\system32\drivers\crtaud.sys
R3 rpfun;Conexant Riptide Dummy Driver;C:\WINDOWS\system32\drivers\rpfun.sys
R3 rthwcls;Conexant Riptide Bus / Firmware Downloader;C:\WINDOWS\system32\drivers\rthwcls.sys
S3 APLMp50;APLMp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\APLMp50.sys
S3 PanasonicKX-TG5576USBD;Panasonic KX-TG55 USB;C:\WINDOWS\system32\Drivers\pccusbd.sys

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ad64f60-5914-11dc-b331-0010b591c4c7}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2007-12-02 02:00:02 C:\WINDOWS\Tasks\Tune-up Application Start.job"
"2007-12-02 17:37:02 C:\WINDOWS\Tasks\PCHealth Scheduler for Data Collection.job"
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-02 10:35:23
Windows 5.1.2600 Service Pack 2 FAT NTAPI

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-02 10:38:42
.
— E O F —
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\SYSTEM32\ulyngwja.ini
C:\WINDOWS\SYSTEM32\qcpfdsjf.ini
C:\WINDOWS\SYSTEM32\dytltnfx.dll_old
C:\WINDOWS\system32\m?config.exe

C:\WINDOWS\dvjvpux.exe
Folder::
C:\Program Files\dolo

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ohtco"=-
"Necl"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dvjvpux"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zanu]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
ComboFix 07-12-02.5 - Kyle Phan 2007-12-02 20:07:10.15 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.184 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix(2).exe
Command switches used :: C:\Documents and Settings\Kyle Phan\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\dvjvpux.exe
C:\WINDOWS\SYSTEM32\dytltnfx.dll_old
C:\WINDOWS\SYSTEM32\qcpfdsjf.ini
C:\WINDOWS\SYSTEM32\ulyngwja.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\SYSTEM32\dytltnfx.dll_old
C:\WINDOWS\SYSTEM32\qcpfdsjf.ini
C:\WINDOWS\SYSTEM32\ulyngwja.ini

.
((((((((((((((((((((((((( Files Created from 2007-11-03 to 2007-12-03 )))))))))))))))))))))))))))))))
.

2007-11-30 16:59 . 2007-11-30 16:59 d–hs—- C:\FOUND.026
2007-11-27 19:43 . 2007-11-27 19:43 d——– C:\Documents and Settings\Kyle Phan\Application Data\Grisoft
2007-11-27 19:42 . 2007-11-27 19:42 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-27 19:42 . 2007-05-30 05:10 10,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-11-27 00:54 . 2007-11-27 00:54 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-11-27 00:54 . 2007-11-27 00:54 1,409 –a—— C:\WINDOWS\QTFont.for
2007-11-25 17:28 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\SYSTEM32\javacpl.cpl
2007-11-25 17:27 . 2007-11-25 17:27 d——– C:\Program Files\Java
2007-11-25 17:26 . 2007-11-25 17:26 d——– C:\Program Files\Common Files\Java
2007-11-25 14:31 . 2007-11-25 14:31 d——– C:\WINDOWS\SxsCaPendDel
2007-11-23 23:42 . 2007-11-23 23:42 d–hs—- C:\FOUND.025
2007-11-21 15:04 . 2007-11-21 15:04 d–hs—- C:\FOUND.024
2007-11-21 12:23 . 2003-06-05 20:13 53,248 –a—— C:\WINDOWS\SYSTEM32\Process.exe
2007-11-21 11:30 . 2007-11-21 11:30 2,518 –a—— C:\WINDOWS\SYSTEM32\tmp.reg
2007-11-21 11:29 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\SYSTEM32\VCCLSID.exe
2007-11-21 11:29 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\SYSTEM32\SrchSTS.exe
2007-11-21 11:29 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\SYSTEM32\dumphive.exe
2007-11-20 23:46 . 2007-11-20 23:47 24,576 –a—— C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
2007-11-20 22:32 . 2007-11-20 22:32 d——– C:\VundoFix Backups
2007-11-16 22:14 . 2007-11-16 22:14 d——– C:\Program Files\Trend Micro
2007-11-14 21:55 . 2007-11-14 21:55 d——– C:\WINDOWS\BDOSCAN8
2007-11-14 20:52 . 2007-11-14 20:52 d——– C:\Program Files\Spyware Doctor
2007-11-14 20:52 . 2007-11-14 20:52 d——– C:\Documents and Settings\Kyle Phan\Application Data\PC Tools
2007-11-14 20:52 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\SYSTEM32\msvcr80.dll
2007-11-14 20:52 . 2007-10-18 00:16 79,688 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\iksyssec.sys
2007-11-14 20:52 . 2007-10-18 00:15 62,280 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\iksysflt.sys
2007-11-14 20:52 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\ikfilesec.sys
2007-11-14 20:52 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\kcom.sys
2007-11-13 22:21 . 2007-11-13 22:21 d–hs—- C:\FOUND.023
2007-11-13 19:52 . 2007-11-13 19:52 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-13 19:51 . 2007-11-13 19:51 d——– C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-11-11 13:19 . 2007-11-11 13:19 d–hs—- C:\FOUND.022
2007-11-11 11:02 . 2007-11-11 11:02 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-07 22:54 . 2007-11-07 22:54 d–hs—- C:\FOUND.021

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\dllcache\shell32.dll
2007-10-25 17:26 53,248 —-a-w C:\WINDOWS\bdoscandel.exe
2007-10-19 02:38 ——— d—–w C:\Program Files\Replay Media Catcher
2007-10-08 21:57 ——— d—–w C:\Program Files\NCH Software
2007-08-23 04:21 105,688 —-a-w C:\Documents and Settings\Kyle Phan\Application Data\GDIPFONTCACHEV1.DAT
2005-12-14 00:37 117 —-a-w C:\Documents and Settings\Kyle Phan\Application Data\fusioncache.dat
2002-10-04 22:09 204,800 —-a-w C:\WINDOWS\inf\FXPlugin.dll
2000-06-16 19:26 271 –sh–w C:\Program Files\desktop.ini
2000-06-16 19:26 23,357 —h–w C:\Program Files\folder.htt
2004-03-08 02:03 8 –sh–w C:\WINDOWS\DRM\pdrm.dat
.

((((((((((((((((((((((((((((( snapshot@2007-11-21_12.51.24.81 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-08 23:59:02 136,704 —-a-w C:\WINDOWS\catchme.exe
+ 2007-11-27 10:58:12 140,288 —-a-w C:\WINDOWS\catchme.exe
+ 2007-03-13 17:57:12 163,328 —-a-w C:\WINDOWS\erdnt\subs\F3M\ERDNT.EXE
+ 2007-11-25 21:32:26 295,606 —-a-r C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A81000000003}\SC_Reader.exe
- 2007-03-14 07:31:24 135,168 —-a-w C:\WINDOWS\SYSTEM32\java.exe
+ 2007-09-25 05:30:28 135,168 —-a-w C:\WINDOWS\SYSTEM32\java.exe
- 2007-03-14 07:31:28 135,168 —-a-w C:\WINDOWS\SYSTEM32\javaw.exe
+ 2007-09-25 05:30:30 135,168 —-a-w C:\WINDOWS\SYSTEM32\javaw.exe
- 2007-03-14 09:04:46 139,264 —-a-w C:\WINDOWS\SYSTEM32\javaws.exe
+ 2007-09-25 06:31:42 139,264 —-a-w C:\WINDOWS\SYSTEM32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"Washer"="C:\Program Files\Washer\washer.exe" [2002-12-12 17:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-17 23:59]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 05:17]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2006-01-11 12:05]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 18:18]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2005-08-10 12:49]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-01-11 19:58]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-08 20:19]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" []
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"MOSearch"="C:\PROGRA~1\COMMON~1\System\MOSearch\Bin\mosearch.exe" [2001-01-19 15:28]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\Money Express.exe" [1999-08-04 00:00]
"ctfmon.exe"="ctfmon.exe" [2004-08-04 02:56 C:\WINDOWS\SYSTEM32\ctfmon.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online Tray Icon.lnk]
backup=C:\WINDOWS\pss\America Online Tray Icon.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
backup=C:\WINDOWS\pss\AOL Companion.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AWMON]
2005-05-25 12:12 517632 –a—— C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 02:56 15360 –a—— C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
rundll32.exe C:\PROGRA~1\AIM\\DeadAIM.ocm,ExportedCheckODLs

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
2005-09-22 18:29 303104 –a—— c:\PROGRA~1\mcafee.com\agent\mcagent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
2006-01-11 12:05 212992 –a—— C:\PROGRA~1\mcafee.com\agent\McUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
1999-08-04 00:00 122940 –a—— C:\Program Files\Microsoft Money\System\Money Express.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2003-07-13 02:49 155648 –a—— C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
2006-05-08 05:17 81920 –a—— C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemTray]
SysTray.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
2005-08-10 12:49 163840 –a—— c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe /checktask

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Washer]
C:\Program Files\Washer\washer.exe /0

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\You've Got Pictures Screensaver]
2004-05-07 16:54 99456 –a—— C:\Program Files\Common Files\AOL\Screensaver\ygpsstra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"HPScanPatch"=C:\WINDOWS\SYSTEM32\HPScanFix.exe
"MMTray"=
"hpsysdrv"=C:\WINDOWS\SYSTEM32\hpsysdrv.exe
"Delay"=C:\WINDOWS\delayrun.exe

R2 gearsec;gearsec;C:\WINDOWS\system32\gearsec.exe
R2 SVKP;SVKP;\??\C:\WINDOWS\system32\SVKP.sys
R3 crtaud;Conexant Riptide WDM Audio Driver;C:\WINDOWS\system32\drivers\crtaud.sys
R3 rpfun;Conexant Riptide Dummy Driver;C:\WINDOWS\system32\drivers\rpfun.sys
R3 rthwcls;Conexant Riptide Bus / Firmware Downloader;C:\WINDOWS\system32\drivers\rthwcls.sys
S3 APLMp50;APLMp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\APLMp50.sys
S3 PanasonicKX-TG5576USBD;Panasonic KX-TG55 USB;C:\WINDOWS\system32\Drivers\pccusbd.sys

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ad64f60-5914-11dc-b331-0010b591c4c7}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2007-12-02 02:00:02 C:\WINDOWS\Tasks\Tune-up Application Start.job"
"2007-12-03 03:27:42 C:\WINDOWS\Tasks\PCHealth Scheduler for Data Collection.job"
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-02 20:31:31
Windows 5.1.2600 Service Pack 2 FAT NTAPI

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-02 20:37:15 - machine was rebooted
C:\ComboFix2.txt … 2007-12-02 10:38
.
— E O F —
i forgot to put the hijack this to the last reply…

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:47:28 PM, on 12/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\DRIVERS\dcfssvc.exe
C:\WINDOWS\system32\gearsec.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Washer\washer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hp.my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://hp.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKLM\..\RunServices: [MOSearch] C:\PROGRA~1\COMMON~1\System\MOSearch\Bin\mosearch.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Washer] C:\Program Files\Washer\washer.exe /0
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" (User 'Default user')
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.pw.aol.com/molbin/shared/m…77/mcinsctl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: dcfssvc (Dcfssvc) - Eastman Kodak Company - C:\WINDOWS\system32\DRIVERS\dcfssvc.exe
O23 - Service: gearsec - GEAR Software - C:\WINDOWS\system32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe

–
End of file - 9424 bytes
Do you or have you used a program called SVK-Protector Decrypter? Or do you know what this driver may be part of? SVKP.sys It may be part of some kind of DRM or something…if you're not sure why don't we upload it for analysis.

Please go to http://virusscan.jotti.org, click on Browse, and upload the following file for analysis:

C:\WINDOWS\system32\SVKP.sys

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.

If Jotti is too busy you can try these.

http://www.kaspersky.com/scanforvirus.html
http://www.virustotal.com/en/indexf.html

————————————————

How is it running now?
Scan taken on 03 Dec 2007 22:52:00 (GMT) A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found RemoteAdmin.AVE BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Ikarus Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Rising Antivirus Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing i think its running the same as before.

i think its running the same as before.

Can you be a little more specific please. Thanks…

Lets run an F-Secure online scan for Viruses, Spyware and RootKits:
  • Go to http://support.f-secure.com/enu/home/ols.shtml
  • Scroll to the bottom of the page and click the Start scanning button. A window will pop up.
  • Allow the Active X control to be installed on your computer, then click the Accept button
  • Click Full System Scan and allow the components to download and the scan to complete.
  • If malware is found, check Submit samples to F-Secure then select Automatic cleaning
  • When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post
If Automatic cleaning with Submit samples hangs, click Cancel, then New Scan
  • When the cleaning option is presented, Uncheck Submit samples to F-Secure
  • Click Automatic cleaning
  • When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post
Notes:
  • This scan will only work with Internet Explorer
  • You must have administrator rights to run this scan
  • This scan can take several hours, so please be patient
oh well, ever since i installed the avg antimalware, it seemed to run slower than it suppose to be. it takes awhile to load things. Scanning Report Wednesday, December 05, 2007 15:28:36 - 19:18:27 Computer name: HPPAV Scanning type: Scan system for viruses, rootkits, spyware Target: C:\ Result: 5 malware found Tracking Cookie (spyware) * System (Disinfected) * System (Disinfected) * System W32/Malware.XZZ (virus) * C:\SYSTEM VOLUME INFORMATION\_RESTORE{9DB7D597-8919-460A-A50F-D58B73668C05}\RP16\A0019064.EXE Win32.Trojandownloader.Zlob (spyware) * System (Disinfected) Statistics Scanned: * Files: 40842 * System: 5871 * Not scanned: 4 Actions: * Disinfected: 3 * Renamed: 0 * Deleted: 0 * None: 2 * Submitted: 0 Files not scanned: * C:\PAGEFILE.SYS * C:\HIBERFIL.SYS * C:\WINDOWS\SOFTWAREDISTRIBUTION\EVENTCACHE\{6CA55BDA-7E9A-4D91-880D-5A74DC5DFC05}.BIN * C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Options Scanning engines: * F-Secure AVP: 7.0.171, 2007-12-05 * F-Secure Blacklight: 1.0.64 * F-Secure Draco: 1.0.35, 2007-11-28 * F-Secure Libra: 2.4.2, 2007-11-28 * F-Secure Orion: 1.2.37, 2007-12-05 * F-Secure Pegasus: 1.19.0, 2007-11-03 Scanning options: * Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB BAT LNK ANI AVB CEO CMD LSP MAP MHT MIF PDF PHP POT WMF NWS TAR TGZ WSF ZL? {* ZIP JAR ARJ LZH TAR TGZ GZ CAB RAR BZ2 HQX * Use Advanced heuristics Copyright © 1998-2006 Product support |Send virus sample to F-Secure F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.
Well for AVG, you can just uninstall it using Add or Remove Programs or turn off real time scanning which should free up system resources, and just use it for one time scans. That is what I do.

To do that…
  • On the main screen under Your Computer's security.
  • Click on Change state next to Resident shield. It should now change to inactive.
  • Click on Change state next to Automatic updates. It should now change to inactive.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Next time you reboot it won't be running in the background.

Let me know how you make out.
wait before i turn off the guard, is the program really good in protecting my computer? if it is i think i'm just going to leave it active and deal with it be slow at some points.
oh ok, i guess i'll disable it. my last questions before we end the topic. should i continue my subscription to Mcafee? or should get some other program like Norton. (one of my friends told me i should switch to it, and i'm not sure if i should or not) and also what are some tips for me to stay up to date with computer protection stuff? like how you told me i should stay up to date with my java and all.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI