This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] online security guide live safety center malware

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i've been having the same problem as couple other people on this forum. online security guide live safety center icons that you try to delete but keep poping up, yellow triangle with system alerts, security toolbar on toolbar when on the internet, along with many other annoying popups(system defender, save the information, etc…). here's my hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 8:52:01 PM, on 11/18/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Nitrodial V2\nitrodial.exe
C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/googlesidesearch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5400
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\gkzijkcl.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [f03468ad] rundll32.exe "C:\WINDOWS\System32\wridfnpn.dll",b
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: Nitrodial V2.lnk = C:\Program Files\Nitrodial V2\nitrodial.exe
O8 - Extra context menu item: Show All Original Images - res://C:\Program Files\Nitrodial V2\nitrodial.exe/250
O8 - Extra context menu item: Show Original Image - res://C:\Program Files\Nitrodial V2\nitrodial.exe/227
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: *.doginhispen.com
O15 - Trusted Zone: *.whataboutadog.com
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/VaioInfo.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {50BD5CDA-4BA8-4048-8FAA-763F222E41D8} - ms-its:mhtml:file://c:\\nores.mht!http://adxrnet.net/code/chm/xpre.chm::/xpreload.ocx
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1452/ftp…/couponsbar.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg…,16/mcgdmgr.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A261AE53-0F90-4901-AAD3-9A1001AAEFA8}: NameServer = 72.35.32.161 64.85.136.161
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\System32\rynpedms.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe


i've had this for almost two weeks now and am going insane. please help!
Hello retrorags and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem. You have a real hornets' nest here and this make take several posts to clean up so buckle your seat belt and here we go.


A. Please provide a list of uninstallable programs.

To Provide a List of Installed Programs
  • Run HijackThis.
  • Click Config>>Miscellaneous Tools>>Open Uninstall Manager>>Save List
  • Save list to Desktop
  • Copy the Notepad list and Paste it into this thread.
B. Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.



C. Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall


D. Reports/Logs to post:
  • (All important to save and post)
  • VundoFix.txt
  • ComboFix.txt
  • HijackThis log
  • Uninstall List
ComboFix 07-11-08.3 - Debra Ritzema 2007-11-19 1:56:00.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.41 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Debra Ritzema\Application Data\macromedia\Flash Player\#SharedObjects\BQCEU3GY\www.broadcaster.com
C:\Documents and Settings\Debra Ritzema\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Debra Ritzema\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\Debra Ritzema\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Debra Ritzema\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Debra Ritzema\Favorites\Online Security Guide.lnk
C:\Program Files\WinBudget
C:\Program Files\WinBudget\bin\carp**.1192492360.old
C:\Program Files\WinBudget\bin\carp**.1193177735.old
C:\Program Files\WinBudget\bin\carp**.1193824793.old
C:\Program Files\WinBudget\bin\matrix.dat
C:\Program Files\WinBudget\bin\matrix.dll
C:\Program Files\WinBudget\bin\matrix.dll.1193177733.old
C:\Program Files\WinBudget\bin\matrix.dll.1193824791.old
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files.\xpreload.ocx
C:\WINDOWS\system32\dobe~1
C:\WINDOWS\system32\mjuyarxp.dllbox
C:\WINDOWS\system32\onnmp.bak2
C:\WINDOWS\system32\onnmp.ini
C:\WINDOWS\system32\onnmp.ini2
C:\WINDOWS\system32\onnmp.tmp
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pmnno.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-10-19 to 2007-11-19 )))))))))))))))))))))))))))))))
.

2007-11-19 01:45 145,984 –a—— C:\WINDOWS\system32\mjuyarxp.dll
2007-11-19 01:44 145,984 –a—— C:\WINDOWS\system32\stmfrmrs.dll
2007-11-19 01:43 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-19 01:29 85,056 –a—— C:\WINDOWS\system32\nkdjykvn.dll
2007-11-19 01:26 83,008 –a—— C:\WINDOWS\system32\veqoxkrp.dll
2007-11-19 01:26 71,232 –a—— C:\WINDOWS\system32\ehxovead.exe
2007-11-19 01:01 83,008 –a—— C:\WINDOWS\system32\xoeyvuly.dll
2007-11-19 01:01 71,232 –a—— C:\WINDOWS\system32\fnbjdhmj.exe
2007-11-18 20:34 79,424 –a—— C:\WINDOWS\system32\pehwxjry.dll
2007-11-18 20:28 71,232 –a—— C:\WINDOWS\system32\dovlmret.exe
2007-11-18 18:13 85,056 –a—— C:\WINDOWS\system32\aeyjswsv.dll
2007-11-16 21:15 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-16 21:13 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-11-16 20:06 71,232 –a—— C:\WINDOWS\system32\ejppfoer.exe
2007-11-16 19:31 608,481 –a—— C:\Program Files\aaw2007.exe
2007-11-16 14:19 81,984 –a—— C:\WINDOWS\system32\rtqdookb.dll
2007-11-15 12:46 d——– C:\Documents and Settings\Debra Ritzema\Application Data\Grisoft
2007-11-15 12:45 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-15 12:37 12,413,440 –a—— C:\Program Files\avgas-setup-7.5.1.43.exe
2007-11-15 01:15 71,232 –a—— C:\WINDOWS\system32\vaffyujp.exe
2007-11-15 00:28 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-11-15 00:28 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-13 18:08 71,232 –a—— C:\WINDOWS\system32\bgwobmcs.exe
2007-11-12 23:52 2,992 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-12 20:31 d——– C:\Program Files\Clean Sweep
2007-11-12 20:18 d——– C:\Program Files\QuickClean
2007-11-12 20:18 249,856 ——— C:\WINDOWS\Setup1.exe
2007-11-12 20:18 73,216 –a—— C:\WINDOWS\ST6UNST.EXE
2007-11-12 17:16 89,664 –a—— C:\WINDOWS\system32\ofvgmrjf.dll
2007-11-12 17:07 71,232 –a—— C:\WINDOWS\system32\uiahbggw.exe
2007-11-11 17:10 88,128 –a—— C:\WINDOWS\system32\uecvpycu.dll
2007-11-11 17:07 71,232 –a—— C:\WINDOWS\system32\sbchkjpp.exe
2007-11-10 18:53 81,472 –a—— C:\WINDOWS\system32\adqhsmlo.dll
2007-11-08 19:11 71,232 –a—— C:\WINDOWS\system32\syuyjjbu.exe
2007-11-08 18:11 79,936 –a—— C:\WINDOWS\system32\dpaojoag.dll
2007-11-08 18:09 71,232 –a—— C:\WINDOWS\system32\eqaepvek.exe
2007-11-07 16:53 79,936 –a—— C:\WINDOWS\system32\lfvkkxeh.dll
2007-11-07 16:47 71,232 –a—— C:\WINDOWS\system32\mxutiebp.exe
2007-11-07 16:44 79,936 –a—— C:\WINDOWS\system32\rrygtgvo.dll
2007-11-07 16:44 71,232 –a—— C:\WINDOWS\system32\bkqgflho.exe
2007-11-07 14:12 27,200 –a—— C:\WINDOWS\system32\6x7MQ6oj.exe
2007-11-06 15:21 81,472 –a—— C:\WINDOWS\system32\glkxrocb.dll
2007-11-06 15:12 71,232 –a—— C:\WINDOWS\system32\cjlcqioc.exe
2007-11-06 14:52 218,112 –a—— C:\HijackThis.exe
2007-11-06 13:16 81,472 –a—— C:\WINDOWS\system32\usrlfobb.dll
2007-11-05 12:49 83,008 –a—— C:\WINDOWS\system32\qjbegvsi.dll
2007-11-04 20:42 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-04 20:29 12,413,440 –a—— C:\avgas-setup-7.5.1.43.exe
2007-10-31 12:11 d——– C:\WINDOWS\system32\Mz02r
2007-10-31 12:11 d——– C:\Temp
2007-10-31 12:11 34,816 –a—— C:\WINDOWS\system32\efcdabc.dll
2007-10-31 00:23 d——– C:\Documents and Settings\All Users\Application Data\Movavi Flash Converter 2
2007-10-31 00:20 33,824 –a—— C:\WINDOWS\system32\drivers\oreans32.sys
2007-10-31 00:19 d——– C:\Program Files\Movavi Flash Converter
2007-10-31 00:19 d——– C:\Program Files\Common Files\MOVAVI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 02:15 ——— d—–w C:\Program Files\Lavasoft
2007-11-16 19:37 ——— d—–w C:\Documents and Settings\All Users\Application Data\AntiSpyInfo
2007-11-16 19:12 ——— d—–w C:\Program Files\PCFriendly
2007-11-15 20:21 ——— d—–w C:\Program Files\Microsoft Money
2007-11-15 20:18 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-15 20:18 ——— d—–w C:\Program Files\Quicken
2007-11-06 19:53 413 —-a-w C:\Program Files\Shortcut to HijackThis.exe.lnk
2007-11-06 19:53 413 —-a-w C:\Program Files\Shortcut (2) to HijackThis.exe.lnk
2007-11-06 18:43 ——— d—–w C:\Program Files\Soulseek-Test
2007-10-17 04:24 ——— d—–w C:\Documents and Settings\Debra Ritzema\Application Data\AdobeUM
2007-10-11 18:13 ——— d—–w C:\Program Files\Common Files\Adobe
2007-10-10 05:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-10-08 23:42 ——— d—–w C:\Program Files\Winamp
2007-10-08 23:42 ——— d—–w C:\Program Files\QuickTime
2007-10-08 23:42 ——— d—–w C:\Program Files\iTunes
2007-10-08 23:34 ——— d—–w C:\Program Files\MSN Messenger
2007-10-02 23:05 1,156,096 —-a-w C:\iview400_setup.exe
2005-10-17 00:49 857,915 -c–a-w C:\Program Files\vx2cleaner_inst.exe
2005-10-17 00:45 6,629,880 -c–a-w C:\Program Files\ewido-setup.exe
2005-10-09 20:27 318,775 -c–a-w C:\Program Files\CleanUp40.exe
2005-10-09 19:45 488,144 -c–a-w C:\Program Files\HJTsetup.exe
2005-08-29 04:39 14,064,602 -c–a-w C:\Program Files\convertmovie.exe
2005-08-24 02:05 9,754,618 -c–a-w C:\Program Files\AuroraMovieBurner.exe
2005-08-24 00:08 14,332,241 -c–a-w C:\Program Files\scvc5504.exe
2005-08-23 18:44 8,871,372 -c–a-w C:\Program Files\VCDEasy_v3.0.2_Setup.exe
2005-08-23 17:45 4,361,712 -c–a-w C:\Program Files\avi-vcd.exe
2005-08-23 04:59 12,754,672 -c–a-w C:\Program Files\MP10Setup.exe
2005-08-13 14:41 2,068,153 -c–a-w C:\Program Files\hfxpack0-extrafx.exe
2005-08-11 02:01 770,608 -c–a-w C:\Program Files\TO-41S330801AZ04US.EXE
2005-08-11 01:35 21,637,120 -c–a-w C:\Program Files\SO-Z80600803HM03US.EXE
2005-08-11 00:00 17,802,955 -c–a-w C:\Program Files\SO-Q61800803GQ.EXE
2005-08-10 22:31 5,614,281 -c–a-w C:\Program Files\SO-Z70800803FM.EXE
2004-09-24 02:57 22 —-a-w C:\Program Files\radead17.zip
2004-09-19 23:03 823,296 -c–a-w C:\Program Files\winmx353.exe
2004-09-10 04:14 50 -c–a-w C:\Documents and Settings\Debra Ritzema\Application Data\tvmcwrd.dll
2004-09-08 15:38 216,030 -c–a-w C:\Documents and Settings\Debra Ritzema\Application Data\tvmknwrd.dll
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 315,392 2003-03-01 04:00:00 C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

—-a-r 49,152 2003-05-22 13:03:16 C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe

—-a-w 278,528 2006-06-14 20:24:14 C:\Program Files\iTunes\bak\iTunesHelper.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\Program Files\iTunes\iTunesHelper.exe

-c–a-w 200,767 2002-07-17 18:00:00 C:\Program Files\Microsoft Money\System\bak\mnyexpr.exe

—-a-w 212,992 2004-11-12 01:50:15 C:\Program Files\Nero\data\Xtras\bak\mssysmgr.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\Program Files\Nero\data\Xtras\mssysmgr.exe

—-a-w 282,624 2006-07-26 15:49:25 C:\Program Files\QuickTime\bak\qttask.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\Program Files\QuickTime\qttask.exe

—-a-w 11,406 2002-07-14 19:50:14 C:\Program Files\support.com\client\lserver\bak\server.vbs

—-a-w 155,648 2002-06-18 07:01:00 C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\Program Files\VERITAS Software\Update Manager\sgtray.exe

—-a-w 33,792 2004-12-20 18:41:22 C:\Program Files\Winamp\bak\winampa.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\Program Files\Winamp\winampa.exe

—-a-w 28,672 2003-04-20 05:08:44 C:\WINDOWS\SONYSYS\VAIO Recovery\bak\PartSeal.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe

—-a-w 114,688 2003-03-11 18:11:56 C:\WINDOWS\system32\bak\hkcmd.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\WINDOWS\system32\hkcmd.exe

—-a-r 483,328 2003-05-22 12:55:38 C:\WINDOWS\system32\bak\hphmon05.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\WINDOWS\system32\hphmon05.exe

—-a-w 155,648 2003-03-11 18:24:08 C:\WINDOWS\system32\bak\igfxtray.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\WINDOWS\system32\igfxtray.exe

—-a-w 155,648 2001-07-09 14:50:42 C:\WINDOWS\system32\bak\NeroCheck.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\WINDOWS\system32\NeroCheck.exe

—-a-w 188,416 2003-05-07 05:56:22 C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb09.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-19 01:45 145984 –a—— C:\WINDOWS\system32\mjuyarxp.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b5a94c95-2814-4172-aabb-f5dfe78f0fe1}]
2007-11-19 01:26 83008 –a—— C:\WINDOWS\System32\veqoxkrp.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\mjuyarxp.dll [2007-11-19 01:45 145984]

[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\mjuyarxp.dll [2007-11-19 01:45 145984]

[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2007-10-08 18:39]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2007-10-08 18:39]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2007-10-08 18:39]
"ZTgServerSwitch"="c:\program files\support.com\client\lserver\server.vbs" []
"AGRSMMSG"="AGRSMMSG.exe" [2003-02-14 14:59 C:\WINDOWS\AGRSMMSG.exe]
"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [2007-10-08 18:39]
"VAIO Recovery"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2007-10-08 18:39]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe" [2007-10-08 18:39]
"HPHUPD05"="C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2007-10-08 18:39]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2007-10-08 18:39]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-08 18:39]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2007-10-08 18:39]
"nwiz"="nwiz.exe" [2003-03-03 21:44 C:\WINDOWS\system32\nwiz.exe]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-10-08 18:39]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-08 18:39]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 16:24 C:\WINDOWS\system32\Ati2mdxx.exe]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]
"f03468ad"="C:\WINDOWS\System32\nkdjykvn.dll" [2007-11-19 01:29]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54]
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe" [2007-10-08 18:39]

C:\Documents and Settings\Debra Ritzema\Start Menu\Programs\Startup\
Camio Viewer.lnk - C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe [2003-10-16 14:51:34]
PowerReg Scheduler V3.exe [2004-07-09 16:37:42]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06]
Event Reminder.lnk - C:\Program Files\Broderbund\PrintMaster\pmremind.exe [2006-02-11 15:28:37]
Nitrodial V2.lnk - C:\Program Files\Nitrodial V2\nitrodial.exe [2007-09-12 13:31:19]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mjuyarxp]
mjuyarxp.dll 2007-11-19 01:45 145984 C:\WINDOWS\system32\mjuyarxp.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\System32\pmnno.dll

R1 oreans32;oreans32;\??\C:\WINDOWS\system32\drivers\oreans32.sys
R2 ONSIO;ONSIO;\??\C:\WINDOWS\SYSTEM32\DRIVERS\ONSIO.SYS
S0 SMPLSCSI;SMPLSCSI;C:\WINDOWS\System32\drivers\SMPLSCSI.SYS
S3 SONYWBMS;Sony Memory Stick controller(WB);C:\WINDOWS\System32\DRIVERS\SonyWBMS.SYS

.
Contents of the 'Scheduled Tasks' folder
"2007-09-18 15:01:06 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#240#CN37523025H3.job"
"2007-11-19 00:00:10 C:\WINDOWS\Tasks\HP Usg Daily.job"
- C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\pexpress\hphped05.exe
"2003-10-09 19:34:25 C:\WINDOWS\Tasks\Registration reminder 1.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-19 02:04:00
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-19 2:09:20 - machine was rebooted
.
— E O F —


VundoFix V6.6.2

Checking Java version…

Scan started at 1:09:42 AM 11/19/2007

Listing files found while scanning….

C:\windows\system32\btdadmde.dll
C:\windows\system32\dwiewsne.dll
C:\windows\system32\efcdabc.dll
C:\WINDOWS\system32\gkzijkcl.dll
C:\windows\system32\gkzijkcl.dllbox
C:\windows\system32\lcxrdhyo.dllbox
C:\windows\system32\muvxcjwq.dll

Beginning removal…

Attempting to delete C:\windows\system32\btdadmde.dll
C:\windows\system32\btdadmde.dll Has been deleted!

Attempting to delete C:\windows\system32\dwiewsne.dll
C:\windows\system32\dwiewsne.dll Has been deleted!

Attempting to delete C:\windows\system32\efcdabc.dll
C:\windows\system32\efcdabc.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\gkzijkcl.dll
C:\WINDOWS\system32\gkzijkcl.dll Has been deleted!

Attempting to delete C:\windows\system32\gkzijkcl.dllbox
C:\windows\system32\gkzijkcl.dllbox Has been deleted!

Attempting to delete C:\windows\system32\lcxrdhyo.dllbox
C:\windows\system32\lcxrdhyo.dllbox Has been deleted!

Attempting to delete C:\windows\system32\muvxcjwq.dll
C:\windows\system32\muvxcjwq.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\windows\system32\efcdabc.dll
C:\windows\system32\efcdabc.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal…

Logfile of HijackThis v1.99.1
Scan saved at 2:15:48 AM, on 11/19/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Nitrodial V2\nitrodial.exe
C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\MSN Messenger\usnsvc.exe
c:\program files\internet explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/googlesidesearch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5400
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\Program Files\Nitrodial V2\PBHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\mjuyarxp.dll
O2 - BHO: {1ef0f87e-fd5f-bbaa-2714-418259c49a5b} - {b5a94c95-2814-4172-aabb-f5dfe78f0fe1} - C:\WINDOWS\System32\veqoxkrp.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\mjuyarxp.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [f03468ad] rundll32.exe "C:\WINDOWS\System32\nkdjykvn.dll",b
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: Nitrodial V2.lnk = C:\Program Files\Nitrodial V2\nitrodial.exe
O8 - Extra context menu item: Show All Original Images - res://C:\Program Files\Nitrodial V2\nitrodial.exe/250
O8 - Extra context menu item: Show Original Image - res://C:\Program Files\Nitrodial V2\nitrodial.exe/227
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: *.doginhispen.com
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/VaioInfo.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {50BD5CDA-4BA8-4048-8FAA-763F222E41D8} - ms-its:mhtml:file://c:\\nores.mht!http://adxrnet.net/code/chm/xpre.chm::/xpreload.ocx
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1452/ftp…/couponsbar.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg…,16/mcgdmgr.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A261AE53-0F90-4901-AAD3-9A1001AAEFA8}: NameServer = 72.35.32.161 64.85.136.161
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: mjuyarxp - C:\WINDOWS\SYSTEM32\mjuyarxp.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe

Abacast Version 1.32
Ad-Aware 2007
Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Download Manager 2.0 (Remove Only)
Adobe Reader 7.0
Agere Systems AC'97 Modem
ATI Control Panel
ATI Display Driver
AVG Anti-Spyware 7.5
Broderbund Media Manager
Clean Sweep 1.0
CleanUp!
Click to DVD 1.2
ClickStamp Online Suite
ConvertMovie 1.1
DivX
DivX Player
DVD Creation
DVgate Plus
DXG-518
ewido security suite
Experience VAIO
exPressit S.E. 2.2
getPlus®_ocx
Hijackthis 1.99.1
HijackThis 1.99.1
Home Office Page for Experience VAIO
hp instant support
HP Memories Disc
HP Software Update
Image Expert
ImageStation Tour
InetDctr
Intel® Extreme Graphics Driver
Intel® Integrated Performance Primitives RTI 4.0
Intel® PRO Network Adapters and Drivers
InterActual Player
iPod for Windows 2005-02-22
iTunes
Java 2 Runtime Environment, SE v1.4.0_03
Java Web Start
Kaspersky Online Scanner
Memory Stick Formatter
Microsoft Learning and Research Plus Support Files
Microsoft Picture It! Express 7.0
Microsoft Upgrade Offer
Microsoft Visual C++ 2005 Redistributable
Microsoft Web Publishing Wizard 1.52
Microsoft Works 7.0
Microtek ScanWizard for Windows NT V2.49
MoodLogic
Movavi Flash Converter
MSN Add-in for Windows Messenger
MSN Internet Software
MSN Toolbar
Music Visualizer Library 1.4.00
Nero PhotoShow Express
Nero Suite
Network Smart Capture
Nitrodial V2
NVIDIA Windows 2000/XP Display Drivers
OpenMG Limited Patch 3.2-03-02-21-08
OpenMG Limited Patch 3.2-03-02-25-01
OpenMG Secure Module 3.2
PC Clean
Photosmart 140,240,7200,7600,7700,7900 Series
PictureGear Studio 1.0
PowerDVD
PrintMaster
QuickTime
RealPlayer
Serif DrawPlus 3.0
Shipstream Manager
Shockwave
SmartFTP Client
SonicStage 1.5.50
Sony Certificate PCH
Sony on Yahoo! Essentials
Sony Video Shared Library
SoulSeek 157 test 8
Studio 8
Studio Content CD
Ulead iPhoto Express 1.1
Update for Windows XP (KB898461)
VAIO DeepSea Wallpaper
VAIO Help and Support
VAIO Media 2.5
VAIO Media Music Server 2.5
VAIO Media Photo Server 2.5
VAIO Media Platform 2.5
VAIO Media Redistribution 2.5
VAIO Media Setup 2.5
VAIO Registration
VAIO Support
VAIO Survey Standalone
VAIO System Information
VERITAS RecordNow
VERITAS RecordNow Update Manager
Viewpoint Media Player (Remove Only)
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Live Messenger
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB828741
Windows XP Hotfix - KB835732
Windows XP Hotfix - KB842773
Windows XP Hotfix - KB887472
This fpart of the fix needs to be done in 2 parts with the results from each posted. Once again, these reports are extremely important.

A. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\system32\mjuyarxp.dll
C:\WINDOWS\system32\stmfrmrs.dll
C:\WINDOWS\system32\nkdjykvn.dll
C:\WINDOWS\system32\veqoxkrp.dll
C:\WINDOWS\system32\ehxovead.exe
C:\WINDOWS\system32\xoeyvuly.dll
C:\WINDOWS\system32\fnbjdhmj.exe
C:\WINDOWS\system32\pehwxjry.dll
C:\WINDOWS\system32\dovlmret.exe
C:\WINDOWS\system32\aeyjswsv.dll
C:\WINDOWS\system32\ejppfoer.exe
C:\WINDOWS\system32\rtqdookb.dll
C:\WINDOWS\system32\vaffyujp.exe
C:\WINDOWS\system32\bgwobmcs.exe
C:\WINDOWS\system32\ofvgmrjf.dll
C:\WINDOWS\system32\uiahbggw.exe
C:\WINDOWS\system32\uecvpycu.dll
C:\WINDOWS\system32\sbchkjpp.exe
C:\WINDOWS\system32\adqhsmlo.dll
C:\WINDOWS\system32\syuyjjbu.exe
C:\WINDOWS\system32\dpaojoag.dll
C:\WINDOWS\system32\eqaepvek.exe
C:\WINDOWS\system32\lfvkkxeh.dll
C:\WINDOWS\system32\mxutiebp.exe
C:\WINDOWS\system32\rrygtgvo.dll
C:\WINDOWS\system32\bkqgflho.exe
C:\WINDOWS\system32\6x7MQ6oj.exe
C:\WINDOWS\system32\glkxrocb.dll
C:\WINDOWS\system32\cjlcqioc.exe
C:\WINDOWS\system32\usrlfobb.dll
C:\WINDOWS\system32\qjbegvsi.dll
C:\WINDOWS\system32\efcdabc.dll
C:\Program Files\convertmovie.exe
C:\Program Files\AuroraMovieBurner.exe
C:\Program Files\scvc5504.exe
C:\Documents and Settings\Debra Ritzema\Application Data\tvmcwrd.dll
C:\Documents and Settings\Debra Ritzema\Application Data\tvmknwrd.dll
C:\WINDOWS\System32\pmnno.dll
C:\Documents and Settings\Debra Ritzema\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe

Folder::
C:\WINDOWS\system32\Mz02r
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b5a94c95-2814-4172-aabb-f5dfe78f0fe1}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
[-HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"f03468ad"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mjuyarxp] 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer]
"SearchUrl"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" 
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{50BD5CDA-4BA8-4048-8FAA-763F222E41D8}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}]


3. Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields)


4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
6. When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

* After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

* Reconnect to the internet

* Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
===================================================

B. Please download FindAWF to your Desktop.
  • Double-click FindAWF.exe to start the tool.
  • Select option #1 - Scan for bak folders by typing 1 and press 'Enter'
  • When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt here.
**Do not run any other option unless directed to do so.**
ComboFix 07-11-08.3 - Debra Ritzema 2007-11-19 15:28:57.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.97 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Debra Ritzema\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\Documents and Settings\Debra Ritzema\Application Data\tvmcwrd.dll
C:\Documents and Settings\Debra Ritzema\Application Data\tvmknwrd.dll
C:\Documents and Settings\Debra Ritzema\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
C:\Program Files\AuroraMovieBurner.exe
C:\Program Files\convertmovie.exe
C:\Program Files\scvc5504.exe
C:\WINDOWS\system32\6x7MQ6oj.exe
C:\WINDOWS\system32\adqhsmlo.dll
C:\WINDOWS\system32\aeyjswsv.dll
C:\WINDOWS\system32\bgwobmcs.exe
C:\WINDOWS\system32\bkqgflho.exe
C:\WINDOWS\system32\cjlcqioc.exe
C:\WINDOWS\system32\dovlmret.exe
C:\WINDOWS\system32\dpaojoag.dll
C:\WINDOWS\system32\efcdabc.dll
C:\WINDOWS\system32\ehxovead.exe
C:\WINDOWS\system32\ejppfoer.exe
C:\WINDOWS\system32\eqaepvek.exe
C:\WINDOWS\system32\fnbjdhmj.exe
C:\WINDOWS\system32\glkxrocb.dll
C:\WINDOWS\system32\lfvkkxeh.dll
C:\WINDOWS\system32\mjuyarxp.dll
C:\WINDOWS\system32\mxutiebp.exe
C:\WINDOWS\system32\nkdjykvn.dll
C:\WINDOWS\system32\ofvgmrjf.dll
C:\WINDOWS\system32\pehwxjry.dll
C:\WINDOWS\System32\pmnno.dll
C:\WINDOWS\system32\qjbegvsi.dll
C:\WINDOWS\system32\rrygtgvo.dll
C:\WINDOWS\system32\rtqdookb.dll
C:\WINDOWS\system32\sbchkjpp.exe
C:\WINDOWS\system32\stmfrmrs.dll
C:\WINDOWS\system32\syuyjjbu.exe
C:\WINDOWS\system32\uecvpycu.dll
C:\WINDOWS\system32\uiahbggw.exe
C:\WINDOWS\system32\usrlfobb.dll
C:\WINDOWS\system32\vaffyujp.exe
C:\WINDOWS\system32\veqoxkrp.dll
C:\WINDOWS\system32\xoeyvuly.dll
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\AntiSpyInfo
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\.q_20_q.ini.old
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\_entreelist.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\_enviewlist.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\efcdabc.dll.q_8048800_q.ini
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\HPWuSchd.exe.q_2F18C000_q
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_0000000067937624F993D14C4705097B
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_0000000067937624F993D14C4705097B.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_05285706FC8CBE74C86B0E3C8BD42870
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_05285706FC8CBE74C86B0E3C8BD42870.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_0B79C053C7D38EE4AB9A00CB3B5D2472
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_0B79C053C7D38EE4AB9A00CB3B5D2472.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_0F007175D9BDA3B40BD3531AB45B39F9
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_0F007175D9BDA3B40BD3531AB45B39F9.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_12340
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_12345
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_1282F16FC496F57499BAA62FFEFD04DF
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_1282F16FC496F57499BAA62FFEFD04DF.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_15FFCA6BA84209245BB05EC0182FB579
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_15FFCA6BA84209245BB05EC0182FB579.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_19F4AD9090A22324BAC8B67C0490D63E
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_19F4AD9090A22324BAC8B67C0490D63E.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_20CC412817268CD48BDD779933542046
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_20CC412817268CD48BDD779933542046.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_2BF8B715EE620B34EAB170048806AA96
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_2BF8B715EE620B34EAB170048806AA96.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_32D24B202F012684DA4AD31FAE00122B
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_32D24B202F012684DA4AD31FAE00122B.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_4255D12C079AAF24CAA8958B7CDCAC13
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_4255D12C079AAF24CAA8958B7CDCAC13.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_48B19C1564B77EF498992882FC7AF598
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_48B19C1564B77EF498992882FC7AF598.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_5B5D11AFA0D78E34884C69F0791B49ED
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_5B5D11AFA0D78E34884C69F0791B49ED.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_5B7994EDDA558784797A9CAF48EF327C
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_5B7994EDDA558784797A9CAF48EF327C.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_602AD3DEC49116045BE5E87271B06E12
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_602AD3DEC49116045BE5E87271B06E12.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_68AB67CA7DA73301B7447A0000000000
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_68AB67CA7DA73301B7447A0000000000.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_71014BC3AC5F65C439C4DE205126156E
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_71014BC3AC5F65C439C4DE205126156E.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_8D60D467ED8DE1141A8C9D9E83F0A848
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_8D60D467ED8DE1141A8C9D9E83F0A848.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_8F962AF6BC837FD4AAD0633EEC874958
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_8F962AF6BC837FD4AAD0633EEC874958.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_92F43CED5BD4E9A4F9F83F28ECDF050B
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_92F43CED5BD4E9A4F9F83F28ECDF050B.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_9F267C11AE59A6848A7E86A3052C131C
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_9F267C11AE59A6848A7E86A3052C131C.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_A11A3BECAE30AD11FBDB0060B5DB0C5B
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_A11A3BECAE30AD11FBDB0060B5DB0C5B.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_A49D0C45764FCBA4D920E6854768864D
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_A49D0C45764FCBA4D920E6854768864D.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_b25099274a207264182f8181add555d0
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_b25099274a207264182f8181add555d0.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_C838BEBA7A1AD5C47B1EB83441061073
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_C838BEBA7A1AD5C47B1EB83441061073.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_C838BEBA7A1AD5C47B1EB83441062050
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_C838BEBA7A1AD5C47B1EB83441062050.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_C838BEBA7A1AD5C47B1EB83441068061
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_C838BEBA7A1AD5C47B1EB83441068061.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_C88D9F1068C328E448A001A123126FA7
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_C88D9F1068C328E448A001A123126FA7.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_D204673BAE85AE54DB05DD29E46BA707
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_D204673BAE85AE54DB05DD29E46BA707.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_D63A2550E7D05FF4F8BD6692BA7A7C97
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_D63A2550E7D05FF4F8BD6692BA7A7C97.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_D92AB513446206745BDFA50CA4258B5C
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_D92AB513446206745BDFA50CA4258B5C.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_EB63B96346D31464A9AE08D834F61E03
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_EB63B96346D31464A9AE08D834F61E03.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_ED83B86EDD7D3BF44A35F3309A74AEE8
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\ic_ED83B86EDD7D3BF44A35F3309A74AEE8.dll
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\lcxrdhyo.dll.q_8043045_q
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\lcxrdhyo.dll.q_8043045_q.ini
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\lcxrdhyo.dll.q_8043045_q.ini.old
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\Loader.exe.q_FFC3C01_q.ini
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\msntb.dll.q_27605004_q
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\msntb.dll.q_27605004_q.ini
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\NHelper.dll.q_1969F001_q.ini
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\pmnno.dll.q_804B464_q.ini
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\pmnno.dll.q_804B464_q.ini.old
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\scanregw.exe.q_93B0_q.ini
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\stmain.dll.q_1BC46002_q.ini.old
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\stmain.dll.q_1BC46002_q.old
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\systb.dll.q_2CF6004_q.ini.old
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\wjview.exe.q_8049F12_q
C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\wjview.exe.q_8049F12_q.ini
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Debra Ritzema\Application Data\tvmcwrd.dll
C:\Documents and Settings\Debra Ritzema\Application Data\tvmknwrd.dll
C:\Documents and Settings\Debra Ritzema\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Debra Ritzema\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Debra Ritzema\Favorites\Online Security Guide.lnk
C:\Documents and Settings\Debra Ritzema\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
C:\Program Files\AuroraMovieBurner.exe
C:\Program Files\convertmovie.exe
C:\Program Files\scvc5504.exe
C:\WINDOWS\system32\6x7MQ6oj.exe
C:\WINDOWS\system32\adqhsmlo.dll
C:\WINDOWS\system32\aeyjswsv.dll
C:\WINDOWS\system32\bgwobmcs.exe
C:\WINDOWS\system32\bkqgflho.exe
C:\WINDOWS\system32\cjlcqioc.exe
C:\WINDOWS\system32\dovlmret.exe
C:\WINDOWS\system32\dpaojoag.dll
C:\WINDOWS\system32\efcdabc.dll
C:\WINDOWS\system32\ehxovead.exe
C:\WINDOWS\system32\ejppfoer.exe
C:\WINDOWS\system32\eqaepvek.exe
C:\WINDOWS\system32\fnbjdhmj.exe
C:\WINDOWS\system32\glkxrocb.dll
C:\WINDOWS\system32\lfvkkxeh.dll
C:\WINDOWS\system32\mjuyarxp.dll
C:\WINDOWS\system32\mjuyarxp.dllbox
C:\WINDOWS\system32\mxutiebp.exe
C:\WINDOWS\system32\Mz02r
C:\WINDOWS\system32\nkdjykvn.dll
C:\WINDOWS\system32\ofvgmrjf.dll
C:\WINDOWS\system32\pehwxjry.dll
C:\WINDOWS\system32\qjbegvsi.dll
C:\WINDOWS\system32\rrygtgvo.dll
C:\WINDOWS\system32\rtqdookb.dll
C:\WINDOWS\system32\sbchkjpp.exe
C:\WINDOWS\system32\stmfrmrs.dll
C:\WINDOWS\system32\syuyjjbu.exe
C:\WINDOWS\system32\uecvpycu.dll
C:\WINDOWS\system32\uiahbggw.exe
C:\WINDOWS\system32\usrlfobb.dll
C:\WINDOWS\system32\vaffyujp.exe
C:\WINDOWS\system32\veqoxkrp.dll
C:\WINDOWS\system32\xoeyvuly.dll

.
((((((((((((((((((((((((( Files Created from 2007-10-19 to 2007-11-19 )))))))))))))))))))))))))))))))
.

2007-11-19 01:45 145,984 ——— C:\WINDOWS\system32\mjuyarxp.dll
2007-11-19 01:43 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-16 21:15 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-16 21:13 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-11-16 19:31 608,481 –a—— C:\Program Files\aaw2007.exe
2007-11-15 12:46 d——– C:\Documents and Settings\Debra Ritzema\Application Data\Grisoft
2007-11-15 12:45 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-15 12:37 12,413,440 –a—— C:\Program Files\avgas-setup-7.5.1.43.exe
2007-11-15 00:28 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-11-15 00:28 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-12 23:52 2,992 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-12 20:31 d——– C:\Program Files\Clean Sweep
2007-11-12 20:18 d——– C:\Program Files\QuickClean
2007-11-12 20:18 249,856 ——— C:\WINDOWS\Setup1.exe
2007-11-12 20:18 73,216 –a—— C:\WINDOWS\ST6UNST.EXE
2007-11-06 14:52 218,112 –a—— C:\HijackThis.exe
2007-11-04 20:42 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-04 20:29 12,413,440 –a—— C:\avgas-setup-7.5.1.43.exe
2007-10-31 12:11 d——– C:\Temp
2007-10-31 00:23 d——– C:\Documents and Settings\All Users\Application Data\Movavi Flash Converter 2
2007-10-31 00:20 33,824 –a—— C:\WINDOWS\system32\drivers\oreans32.sys
2007-10-31 00:19 d——– C:\Program Files\Movavi Flash Converter
2007-10-31 00:19 d——– C:\Program Files\Common Files\MOVAVI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 02:15 ——— d—–w C:\Program Files\Lavasoft
2007-11-16 19:12 ——— d—–w C:\Program Files\PCFriendly
2007-11-15 20:21 ——— d—–w C:\Program Files\Microsoft Money
2007-11-15 20:18 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-15 20:18 ——— d—–w C:\Program Files\Quicken
2007-11-06 19:53 413 —-a-w C:\Program Files\Shortcut to HijackThis.exe.lnk
2007-11-06 19:53 413 —-a-w C:\Program Files\Shortcut (2) to HijackThis.exe.lnk
2007-11-06 18:43 ——— d—–w C:\Program Files\Soulseek-Test
2007-10-17 04:24 ——— d—–w C:\Documents and Settings\Debra Ritzema\Application Data\AdobeUM
2007-10-11 18:13 ——— d—–w C:\Program Files\Common Files\Adobe
2007-10-10 05:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-10-08 23:42 ——— d—–w C:\Program Files\Winamp
2007-10-08 23:42 ——— d—–w C:\Program Files\QuickTime
2007-10-08 23:42 ——— d—–w C:\Program Files\iTunes
2007-10-08 23:34 ——— d—–w C:\Program Files\MSN Messenger
2007-10-02 23:05 1,156,096 —-a-w C:\iview400_setup.exe
2005-10-17 00:49 857,915 -c–a-w C:\Program Files\vx2cleaner_inst.exe
2005-10-17 00:45 6,629,880 -c–a-w C:\Program Files\ewido-setup.exe
2005-10-09 20:27 318,775 -c–a-w C:\Program Files\CleanUp40.exe
2005-10-09 19:45 488,144 -c–a-w C:\Program Files\HJTsetup.exe
2005-08-23 18:44 8,871,372 -c–a-w C:\Program Files\VCDEasy_v3.0.2_Setup.exe
2005-08-23 17:45 4,361,712 -c–a-w C:\Program Files\avi-vcd.exe
2005-08-23 04:59 12,754,672 -c–a-w C:\Program Files\MP10Setup.exe
2005-08-13 14:41 2,068,153 -c–a-w C:\Program Files\hfxpack0-extrafx.exe
2005-08-11 02:01 770,608 -c–a-w C:\Program Files\TO-41S330801AZ04US.EXE
2005-08-11 01:35 21,637,120 -c–a-w C:\Program Files\SO-Z80600803HM03US.EXE
2005-08-11 00:00 17,802,955 -c–a-w C:\Program Files\SO-Q61800803GQ.EXE
2005-08-10 22:31 5,614,281 -c–a-w C:\Program Files\SO-Z70800803FM.EXE
2004-09-24 02:57 22 —-a-w C:\Program Files\radead17.zip
2004-09-19 23:03 823,296 -c–a-w C:\Program Files\winmx353.exe
.

((((((((((((((((((((((((((((( snapshot@2007-11-19_ 2.05.26.54 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-19 06:23:08 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-11-19 20:14:06 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-11-19 06:23:08 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-11-19 20:14:06 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-11-19 06:23:08 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-11-19 20:14:06 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-11-19 06:55:41 262,144 —-a-w C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT
+ 2007-11-19 20:28:39 262,144 —-a-w C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 315,392 2003-03-01 04:00:00 C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

—-a-r 49,152 2003-05-22 13:03:16 C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe

—-a-w 278,528 2006-06-14 20:24:14 C:\Program Files\iTunes\bak\iTunesHelper.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\Program Files\iTunes\iTunesHelper.exe

-c–a-w 200,767 2002-07-17 18:00:00 C:\Program Files\Microsoft Money\System\bak\mnyexpr.exe

—-a-w 212,992 2004-11-12 01:50:15 C:\Program Files\Nero\data\Xtras\bak\mssysmgr.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\Program Files\Nero\data\Xtras\mssysmgr.exe

—-a-w 282,624 2006-07-26 15:49:25 C:\Program Files\QuickTime\bak\qttask.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\Program Files\QuickTime\qttask.exe

—-a-w 11,406 2002-07-14 19:50:14 C:\Program Files\support.com\client\lserver\bak\server.vbs

—-a-w 155,648 2002-06-18 07:01:00 C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\Program Files\VERITAS Software\Update Manager\sgtray.exe

—-a-w 33,792 2004-12-20 18:41:22 C:\Program Files\Winamp\bak\winampa.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\Program Files\Winamp\winampa.exe

—-a-w 28,672 2003-04-20 05:08:44 C:\WINDOWS\SONYSYS\VAIO Recovery\bak\PartSeal.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe

—-a-w 114,688 2003-03-11 18:11:56 C:\WINDOWS\system32\bak\hkcmd.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\WINDOWS\system32\hkcmd.exe

—-a-r 483,328 2003-05-22 12:55:38 C:\WINDOWS\system32\bak\hphmon05.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\WINDOWS\system32\hphmon05.exe

—-a-w 155,648 2003-03-11 18:24:08 C:\WINDOWS\system32\bak\igfxtray.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\WINDOWS\system32\igfxtray.exe

—-a-w 155,648 2001-07-09 14:50:42 C:\WINDOWS\system32\bak\NeroCheck.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\WINDOWS\system32\NeroCheck.exe

—-a-w 188,416 2003-05-07 05:56:22 C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb09.exe
—-a-w 27,660 2007-10-08 23:39:20 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-19 15:33 145984 ——— C:\WINDOWS\system32\mjuyarxp.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\mjuyarxp.dll [2007-11-19 15:33 145984]

[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\mjuyarxp.dll [2007-11-19 15:33 145984]

[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2007-10-08 18:39]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2007-10-08 18:39]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2007-10-08 18:39]
"ZTgServerSwitch"="c:\program files\support.com\client\lserver\server.vbs" []
"AGRSMMSG"="AGRSMMSG.exe" [2003-02-14 14:59 C:\WINDOWS\AGRSMMSG.exe]
"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [2007-10-08 18:39]
"VAIO Recovery"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2007-10-08 18:39]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe" [2007-10-08 18:39]
"HPHUPD05"="C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2007-10-08 18:39]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2007-10-08 18:39]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-08 18:39]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2007-10-08 18:39]
"nwiz"="nwiz.exe" [2003-03-03 21:44 C:\WINDOWS\system32\nwiz.exe]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-10-08 18:39]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-08 18:39]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 16:24 C:\WINDOWS\system32\Ati2mdxx.exe]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54]
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe" [2007-10-08 18:39]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06]
Event Reminder.lnk - C:\Program Files\Broderbund\PrintMaster\pmremind.exe [2006-02-11 15:28:37]
Nitrodial V2.lnk - C:\Program Files\Nitrodial V2\nitrodial.exe [2007-09-12 13:31:19]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mjuyarxp]
mjuyarxp.dll 2007-11-19 15:33 145984 C:\WINDOWS\system32\mjuyarxp.dll

R1 oreans32;oreans32;\??\C:\WINDOWS\system32\drivers\oreans32.sys
R2 ONSIO;ONSIO;\??\C:\WINDOWS\SYSTEM32\DRIVERS\ONSIO.SYS
S0 SMPLSCSI;SMPLSCSI;C:\WINDOWS\System32\drivers\SMPLSCSI.SYS
S3 SONYWBMS;Sony Memory Stick controller(WB);C:\WINDOWS\System32\DRIVERS\SonyWBMS.SYS

.
Contents of the 'Scheduled Tasks' folder
"2007-09-18 15:01:06 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#240#CN37523025H3.job"
"2007-11-19 16:00:01 C:\WINDOWS\Tasks\HP Usg Daily.job"
- C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\pexpress\hphped05.exe
"2003-10-09 19:34:25 C:\WINDOWS\Tasks\Registration reminder 1.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-19 15:35:01
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-19 15:39:07 - machine was rebooted
C:\ComboFix2.txt … 2007-11-19 02:09
.
— E O F —

Logfile of HijackThis v1.99.1
Scan saved at 4:30:08 PM, on 11/19/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Nitrodial V2\nitrodial.exe
C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5400
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\Program Files\Nitrodial V2\PBHelper.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\mjuyarxp.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\mjuyarxp.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: Nitrodial V2.lnk = C:\Program Files\Nitrodial V2\nitrodial.exe
O8 - Extra context menu item: Show All Original Images - res://C:\Program Files\Nitrodial V2\nitrodial.exe/250
O8 - Extra context menu item: Show Original Image - res://C:\Program Files\Nitrodial V2\nitrodial.exe/227
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: *.doginhispen.com
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/VaioInfo.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg…,16/mcgdmgr.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A261AE53-0F90-4901-AAD3-9A1001AAEFA8}: NameServer = 72.35.32.161 64.85.136.161
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: mjuyarxp - C:\WINDOWS\SYSTEM32\mjuyarxp.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe

i'll send the FindAFW report in a minute….
Find AWF report by noahdfear ©2006 Version 1.40 The current date is: Mon 11/19/2007 The current time is: 16:42:00.51 bak folders found ~~~~~~~~~~~ Directory of C:\WINDOWS\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\ITUNES\BAK 06/14/2006 03:24 PM 278,528 iTunesHelper.exe 1 File(s) 278,528 bytes Directory of C:\PROGRA~1\MSNMES~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 07/26/2006 10:49 AM 282,624 qttask.exe 1 File(s) 282,624 bytes Directory of C:\PROGRA~1\WINAMP\BAK 12/20/2004 01:41 PM 33,792 winampa.exe 1 File(s) 33,792 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 03/11/2003 01:11 PM 114,688 hkcmd.exe 05/22/2003 07:55 AM 483,328 hphmon05.exe 03/11/2003 01:24 PM 155,648 igfxtray.exe 07/09/2001 09:50 AM 155,648 NeroCheck.exe 4 File(s) 909,312 bytes Directory of C:\PROGRA~1\ATITEC~1\ATICON~1\BAK 02/28/2003 11:00 PM 315,392 atiptaxx.exe 1 File(s) 315,392 bytes Directory of C:\PROGRA~1\HEWLET~1\{45B61~1\BAK 05/22/2003 08:03 AM 49,152 hphupd05.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\MICAC0~1\SYSTEM\BAK 07/17/2002 01:00 PM 200,767 mnyexpr.exe 1 File(s) 200,767 bytes Directory of C:\PROGRA~1\VERITA~1\UPDATE~1\BAK 06/18/2002 02:01 AM 155,648 sgtray.exe 1 File(s) 155,648 bytes Directory of C:\WINDOWS\SONYSYS\VAIORE~1\BAK 04/20/2003 12:08 AM 28,672 PartSeal.exe 1 File(s) 28,672 bytes Directory of C:\PROGRA~1\NERO\DATA\XTRAS\BAK 11/11/2004 08:50 PM 212,992 mssysmgr.exe 1 File(s) 212,992 bytes Directory of C:\PROGRA~1\SUPPORT.COM\CLIENT\LSERVER\BAK 07/14/2002 02:50 PM 11,406 server.vbs 1 File(s) 11,406 bytes Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK 05/07/2003 12:56 AM 188,416 hpztsb09.exe 1 File(s) 188,416 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 27660 Oct 8 2007 "C:\Program Files\iTunes\iTunesHelper.exe" 278528 Jun 14 2006 "C:\Program Files\iTunes\bak\iTunesHelper.exe" 27660 Oct 8 2007 "C:\Program Files\QuickTime\qttask.exe" 282624 Jul 26 2006 "C:\Program Files\QuickTime\bak\qttask.exe" 27660 Oct 8 2007 "C:\Program Files\Winamp\winampa.exe" 33792 Dec 20 2004 "C:\Program Files\Winamp\bak\winampa.exe" 27660 Oct 8 2007 "C:\WINDOWS\system32\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\Drivers\Video\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\bak\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\21\DriverFiles\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\25\DriverFiles\hkcmd.exe" 27660 Oct 8 2007 "C:\WINDOWS\system32\hphmon05.exe" 483328 May 22 2003 "C:\WINDOWS\system32\bak\hphmon05.exe" 27660 Oct 8 2007 "C:\WINDOWS\system32\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\Drivers\Video\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\bak\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\21\DriverFiles\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\25\DriverFiles\igfxtray.exe" 27660 Oct 8 2007 "C:\WINDOWS\system32\NeroCheck.exe" 155648 Jul 9 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe" 27660 Oct 8 2007 "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" 315392 Feb 28 2003 "C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe" 27660 Oct 8 2007 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" 49152 May 22 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe" 200767 Jul 17 2002 "C:\Program Files\Java\Microsoft Money\System\mnyexpr.exe" 200767 Jul 17 2002 "C:\Program Files\Microsoft Money\System\bak\mnyexpr.exe" 27660 Oct 8 2007 "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" 155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe" 27660 Oct 8 2007 "C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe" 28672 Apr 20 2003 "C:\WINDOWS\SONYSYS\VAIO Recovery\bak\PartSeal.exe" 27660 Oct 8 2007 "C:\Program Files\Nero\data\Xtras\mssysmgr.exe" 212992 Nov 11 2004 "C:\Program Files\Nero\data\Xtras\bak\mssysmgr.exe" 11406 Jul 14 2002 "C:\Program Files\support.com\client\lserver\bak\server.vbs" 27660 Oct 8 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" 188416 May 7 2003 "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb09.exe" end of report
Once again a 2-step process and the reports/logs are EXTREMELY important.

A. Double-click FindAWF.exe to start the tool.
  • Select option #2 - Restore files from bak folders by typing 2 and press 'Enter'
  • A text file will open up. Please copy/paste the following bolded text into the text file:

    • "C:\Program Files\iTunes\bak\iTunesHelper.exe"
      "C:\Program Files\QuickTime\bak\qttask.exe"
      "C:\Program Files\Winamp\bak\winampa.exe"
      "C:\WINDOWS\system32\bak\hkcmd.exe"
      "C:\WINDOWS\system32\bak\hphmon05.exe"
      "C:\WINDOWS\system32\bak\igfxtray.exe"
      "C:\WINDOWS\system32\bak\NeroCheck.exe"
      "C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe"
      "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe"
      "C:\Program Files\Microsoft Money\System\bak\mnyexpr.exe"
      "C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe"
      "C:\WINDOWS\SONYSYS\VAIO Recovery\bak\PartSeal.exe"
      "C:\Program Files\Nero\data\Xtras\bak\mssysmgr.exe"
      "C:\Program Files\support.com\client\lserver\bak\server.vbs"
      "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb09.exe"

  • Close the .txt file and click 'Yes' to save the changes.
  • When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt here.


B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\system32\mjuyarxp.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"=-
[-HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mjuyarxp]


3. Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields)


4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
6. When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

* After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

* Reconnect to the internet

* Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
Find AWF report by noahdfear ©2006 Version 1.40 Option 2 run successfully The current date is: Mon 11/19/2007 The current time is: 17:33:15.87 bak folders found ~~~~~~~~~~~ Directory of C:\WINDOWS\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\ITUNES\BAK 06/14/2006 03:24 PM 278,528 iTunesHelper.exe 1 File(s) 278,528 bytes Directory of C:\PROGRA~1\MSNMES~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 07/26/2006 10:49 AM 282,624 qttask.exe 1 File(s) 282,624 bytes Directory of C:\PROGRA~1\WINAMP\BAK 12/20/2004 01:41 PM 33,792 winampa.exe 1 File(s) 33,792 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 03/11/2003 01:11 PM 114,688 hkcmd.exe 05/22/2003 07:55 AM 483,328 hphmon05.exe 03/11/2003 01:24 PM 155,648 igfxtray.exe 07/09/2001 09:50 AM 155,648 NeroCheck.exe 4 File(s) 909,312 bytes Directory of C:\PROGRA~1\ATITEC~1\ATICON~1\BAK 02/28/2003 11:00 PM 315,392 atiptaxx.exe 1 File(s) 315,392 bytes Directory of C:\PROGRA~1\HEWLET~1\{45B61~1\BAK 05/22/2003 08:03 AM 49,152 hphupd05.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\MICAC0~1\SYSTEM\BAK 07/17/2002 01:00 PM 200,767 mnyexpr.exe 1 File(s) 200,767 bytes Directory of C:\PROGRA~1\VERITA~1\UPDATE~1\BAK 06/18/2002 02:01 AM 155,648 sgtray.exe 1 File(s) 155,648 bytes Directory of C:\WINDOWS\SONYSYS\VAIORE~1\BAK 04/20/2003 12:08 AM 28,672 PartSeal.exe 1 File(s) 28,672 bytes Directory of C:\PROGRA~1\NERO\DATA\XTRAS\BAK 11/11/2004 08:50 PM 212,992 mssysmgr.exe 1 File(s) 212,992 bytes Directory of C:\PROGRA~1\SUPPORT.COM\CLIENT\LSERVER\BAK 07/14/2002 02:50 PM 11,406 server.vbs 1 File(s) 11,406 bytes Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK 05/07/2003 12:56 AM 188,416 hpztsb09.exe 1 File(s) 188,416 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 278528 Jun 14 2006 "C:\Program Files\iTunes\iTunesHelper.exe" 278528 Jun 14 2006 "C:\Program Files\iTunes\bak\iTunesHelper.exe" 282624 Jul 26 2006 "C:\Program Files\QuickTime\qttask.exe" 282624 Jul 26 2006 "C:\Program Files\QuickTime\bak\qttask.exe" 33792 Dec 20 2004 "C:\Program Files\Winamp\winampa.exe" 33792 Dec 20 2004 "C:\Program Files\Winamp\bak\winampa.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\Drivers\Video\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\bak\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\21\DriverFiles\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\25\DriverFiles\hkcmd.exe" 483328 May 22 2003 "C:\WINDOWS\system32\hphmon05.exe" 483328 May 22 2003 "C:\WINDOWS\system32\bak\hphmon05.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\Drivers\Video\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\bak\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\21\DriverFiles\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\25\DriverFiles\igfxtray.exe" 155648 Jul 9 2001 "C:\WINDOWS\system32\NeroCheck.exe" 155648 Jul 9 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe" 315392 Feb 28 2003 "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" 315392 Feb 28 2003 "C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe" 49152 May 22 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" 49152 May 22 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe" 200767 Jul 17 2002 "C:\Program Files\Microsoft Money\System\mnyexpr.exe" 200767 Jul 17 2002 "C:\Program Files\Java\Microsoft Money\System\mnyexpr.exe" 200767 Jul 17 2002 "C:\Program Files\Microsoft Money\System\bak\mnyexpr.exe" 155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" 155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe" 28672 Apr 20 2003 "C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe" 28672 Apr 20 2003 "C:\WINDOWS\SONYSYS\VAIO Recovery\bak\PartSeal.exe" 212992 Nov 11 2004 "C:\Program Files\Nero\data\Xtras\mssysmgr.exe" 212992 Nov 11 2004 "C:\Program Files\Nero\data\Xtras\bak\mssysmgr.exe" 11406 Jul 14 2002 "C:\Program Files\support.com\client\lserver\server.vbs" 11406 Jul 14 2002 "C:\Program Files\support.com\client\lserver\bak\server.vbs" 188416 May 7 2003 "C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" 188416 May 7 2003 "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb09.exe" end of report
ComboFix 07-11-08.3 - Debra Ritzema 2007-11-19 17:41:51.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.91 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Debra Ritzema\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\mjuyarxp.dll
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Debra Ritzema\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Debra Ritzema\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Debra Ritzema\Favorites\Online Security Guide.lnk
C:\WINDOWS\system32\mjuyarxp.dll
C:\WINDOWS\system32\mjuyarxp.dllbox

.
((((((((((((((((((((((((( Files Created from 2007-10-19 to 2007-11-19 )))))))))))))))))))))))))))))))
.

2007-11-19 17:33 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2007-11-19 01:45 145,984 ——— C:\WINDOWS\system32\mjuyarxp.dll
2007-11-19 01:43 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-16 21:15 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-16 21:13 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-11-16 19:31 608,481 –a—— C:\Program Files\aaw2007.exe
2007-11-15 12:46 d——– C:\Documents and Settings\Debra Ritzema\Application Data\Grisoft
2007-11-15 12:45 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-15 12:37 12,413,440 –a—— C:\Program Files\avgas-setup-7.5.1.43.exe
2007-11-15 00:28 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-11-15 00:28 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-12 23:52 2,992 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-12 20:31 d——– C:\Program Files\Clean Sweep
2007-11-12 20:18 d——– C:\Program Files\QuickClean
2007-11-12 20:18 249,856 ——— C:\WINDOWS\Setup1.exe
2007-11-12 20:18 73,216 –a—— C:\WINDOWS\ST6UNST.EXE
2007-11-06 14:52 218,112 –a—— C:\HijackThis.exe
2007-11-04 20:42 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-04 20:29 12,413,440 –a—— C:\avgas-setup-7.5.1.43.exe
2007-10-31 12:11 d——– C:\Temp
2007-10-31 00:23 d——– C:\Documents and Settings\All Users\Application Data\Movavi Flash Converter 2
2007-10-31 00:20 33,824 –a—— C:\WINDOWS\system32\drivers\oreans32.sys
2007-10-31 00:19 d——– C:\Program Files\Movavi Flash Converter
2007-10-31 00:19 d——– C:\Program Files\Common Files\MOVAVI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-19 22:33 ——— d—–w C:\Program Files\Winamp
2007-11-19 22:33 ——— d—–w C:\Program Files\QuickTime
2007-11-19 22:33 ——— d—–w C:\Program Files\iTunes
2007-11-17 02:15 ——— d—–w C:\Program Files\Lavasoft
2007-11-16 19:12 ——— d—–w C:\Program Files\PCFriendly
2007-11-15 20:21 ——— d—–w C:\Program Files\Microsoft Money
2007-11-15 20:18 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-15 20:18 ——— d—–w C:\Program Files\Quicken
2007-11-06 19:53 413 —-a-w C:\Program Files\Shortcut to HijackThis.exe.lnk
2007-11-06 19:53 413 —-a-w C:\Program Files\Shortcut (2) to HijackThis.exe.lnk
2007-11-06 18:43 ——— d—–w C:\Program Files\Soulseek-Test
2007-10-17 04:24 ——— d—–w C:\Documents and Settings\Debra Ritzema\Application Data\AdobeUM
2007-10-11 18:13 ——— d—–w C:\Program Files\Common Files\Adobe
2007-10-10 05:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-10-08 23:34 ——— d—–w C:\Program Files\MSN Messenger
2007-10-02 23:05 1,156,096 —-a-w C:\iview400_setup.exe
2005-10-17 00:49 857,915 -c–a-w C:\Program Files\vx2cleaner_inst.exe
2005-10-17 00:45 6,629,880 -c–a-w C:\Program Files\ewido-setup.exe
2005-10-09 20:27 318,775 -c–a-w C:\Program Files\CleanUp40.exe
2005-10-09 19:45 488,144 -c–a-w C:\Program Files\HJTsetup.exe
2005-08-23 18:44 8,871,372 -c–a-w C:\Program Files\VCDEasy_v3.0.2_Setup.exe
2005-08-23 17:45 4,361,712 -c–a-w C:\Program Files\avi-vcd.exe
2005-08-23 04:59 12,754,672 -c–a-w C:\Program Files\MP10Setup.exe
2005-08-13 14:41 2,068,153 -c–a-w C:\Program Files\hfxpack0-extrafx.exe
2005-08-11 02:01 770,608 -c–a-w C:\Program Files\TO-41S330801AZ04US.EXE
2005-08-11 01:35 21,637,120 -c–a-w C:\Program Files\SO-Z80600803HM03US.EXE
2005-08-11 00:00 17,802,955 -c–a-w C:\Program Files\SO-Q61800803GQ.EXE
2005-08-10 22:31 5,614,281 -c–a-w C:\Program Files\SO-Z70800803FM.EXE
2004-09-24 02:57 22 —-a-w C:\Program Files\radead17.zip
2004-09-19 23:03 823,296 -c–a-w C:\Program Files\winmx353.exe
.

((((((((((((((((((((((((((((( snapshot@2007-11-19_ 2.05.26.54 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-10-08 23:39:20 27,660 —-a-w C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe
+ 2003-04-20 05:08:44 28,672 —-a-w C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe
- 2007-11-19 06:23:08 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-11-19 21:36:30 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-11-19 06:23:08 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-11-19 21:36:30 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-11-19 06:23:08 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-11-19 21:36:30 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-11-19 06:55:41 262,144 —-a-w C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT
+ 2007-11-19 22:41:34 262,144 —-a-w C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT
- 2007-10-08 23:39:20 27,660 —-a-w C:\WINDOWS\system32\hkcmd.exe
+ 2003-03-11 18:11:56 114,688 —-a-w C:\WINDOWS\system32\hkcmd.exe
- 2007-10-08 23:39:20 27,660 —-a-w C:\WINDOWS\system32\hphmon05.exe
+ 2003-05-22 12:55:38 483,328 —-a-w C:\WINDOWS\system32\hphmon05.exe
- 2007-10-08 23:39:20 27,660 —-a-w C:\WINDOWS\system32\igfxtray.exe
+ 2003-03-11 18:24:08 155,648 —-a-w C:\WINDOWS\system32\igfxtray.exe
- 2007-10-08 23:39:20 27,660 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
+ 2003-05-07 05:56:22 188,416 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 315,392 2003-03-01 04:00:00 C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
—-a-w 315,392 2003-03-01 04:00:00 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

—-a-r 49,152 2003-05-22 13:03:16 C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe
—-a-w 49,152 2003-05-22 13:03:16 C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe

—-a-w 278,528 2006-06-14 20:24:14 C:\Program Files\iTunes\bak\iTunesHelper.exe
—-a-w 278,528 2006-06-14 20:24:14 C:\Program Files\iTunes\iTunesHelper.exe

-c–a-w 200,767 2002-07-17 18:00:00 C:\Program Files\Microsoft Money\System\bak\mnyexpr.exe
—-a-w 200,767 2002-07-17 18:00:00 C:\Program Files\Microsoft Money\System\mnyexpr.exe

—-a-w 212,992 2004-11-12 01:50:15 C:\Program Files\Nero\data\Xtras\bak\mssysmgr.exe
—-a-w 212,992 2004-11-12 01:50:15 C:\Program Files\Nero\data\Xtras\mssysmgr.exe

—-a-w 282,624 2006-07-26 15:49:25 C:\Program Files\QuickTime\bak\qttask.exe
—-a-w 282,624 2006-07-26 15:49:25 C:\Program Files\QuickTime\qttask.exe

—-a-w 11,406 2002-07-14 19:50:14 C:\Program Files\support.com\client\lserver\bak\server.vbs
—-a-w 11,406 2002-07-14 19:50:14 C:\Program Files\support.com\client\lserver\server.vbs

—-a-w 155,648 2002-06-18 07:01:00 C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe
—-a-w 155,648 2002-06-18 07:01:00 C:\Program Files\VERITAS Software\Update Manager\sgtray.exe

—-a-w 33,792 2004-12-20 18:41:22 C:\Program Files\Winamp\bak\winampa.exe
—-a-w 33,792 2004-12-20 18:41:22 C:\Program Files\Winamp\winampa.exe

—-a-w 28,672 2003-04-20 05:08:44 C:\WINDOWS\SONYSYS\VAIO Recovery\bak\PartSeal.exe
—-a-w 28,672 2003-04-20 05:08:44 C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe

—-a-w 114,688 2003-03-11 18:11:56 C:\WINDOWS\system32\bak\hkcmd.exe
—-a-w 114,688 2003-03-11 18:11:56 C:\WINDOWS\system32\hkcmd.exe

—-a-r 483,328 2003-05-22 12:55:38 C:\WINDOWS\system32\bak\hphmon05.exe
—-a-w 483,328 2003-05-22 12:55:38 C:\WINDOWS\system32\hphmon05.exe

—-a-w 155,648 2003-03-11 18:24:08 C:\WINDOWS\system32\bak\igfxtray.exe
—-a-w 155,648 2003-03-11 18:24:08 C:\WINDOWS\system32\igfxtray.exe

—-a-w 155,648 2001-07-09 14:50:42 C:\WINDOWS\system32\bak\NeroCheck.exe
—-a-w 155,648 2001-07-09 14:50:42 C:\WINDOWS\system32\NeroCheck.exe

—-a-w 188,416 2003-05-07 05:56:22 C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb09.exe
—-a-w 188,416 2003-05-07 05:56:22 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-19 17:45 145984 ——— C:\WINDOWS\system32\mjuyarxp.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\mjuyarxp.dll [2007-11-19 17:45 145984]

[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-02-28 23:00]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-03-11 13:24]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-11 13:11]
"ZTgServerSwitch"="c:\program files\support.com\client\lserver\server.vbs" [2002-07-14 14:50]
"AGRSMMSG"="AGRSMMSG.exe" [2003-02-14 14:59 C:\WINDOWS\AGRSMMSG.exe]
"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [2002-06-18 02:01]
"VAIO Recovery"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 00:08]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-05-07 00:56]
"HPHUPD05"="C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-05-22 08:03]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-05-22 07:55]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2004-12-20 13:41]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50]
"nwiz"="nwiz.exe" [2003-03-03 21:44 C:\WINDOWS\system32\nwiz.exe]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-06-14 15:24]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-26 10:49]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 16:24 C:\WINDOWS\system32\Ati2mdxx.exe]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54]
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe" [2004-11-11 20:50]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06]
Event Reminder.lnk - C:\Program Files\Broderbund\PrintMaster\pmremind.exe [2006-02-11 15:28:37]
Nitrodial V2.lnk - C:\Program Files\Nitrodial V2\nitrodial.exe [2007-09-12 13:31:19]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mjuyarxp]
mjuyarxp.dll 2007-11-19 17:45 145984 C:\WINDOWS\system32\mjuyarxp.dll

R1 oreans32;oreans32;\??\C:\WINDOWS\system32\drivers\oreans32.sys
R2 ONSIO;ONSIO;\??\C:\WINDOWS\SYSTEM32\DRIVERS\ONSIO.SYS
S0 SMPLSCSI;SMPLSCSI;C:\WINDOWS\System32\drivers\SMPLSCSI.SYS
S3 SONYWBMS;Sony Memory Stick controller(WB);C:\WINDOWS\System32\DRIVERS\SonyWBMS.SYS

.
Contents of the 'Scheduled Tasks' folder
"2007-09-18 15:01:06 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#240#CN37523025H3.job"
"2007-11-19 16:00:01 C:\WINDOWS\Tasks\HP Usg Daily.job"
- C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\pexpress\hphped05.exe
"2003-10-09 19:34:25 C:\WINDOWS\Tasks\Registration reminder 1.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-19 17:47:45
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-19 17:51:49 - machine was rebooted
C:\ComboFix2.txt … 2007-11-19 15:39
C:\ComboFix3.txt … 2007-11-19 02:09
.
— E O F —

Logfile of HijackThis v1.99.1
Scan saved at 5:58:39 PM, on 11/19/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\WScript.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\Program Files\Nitrodial V2\nitrodial.exe
C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5400
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\Program Files\Nitrodial V2\PBHelper.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\mjuyarxp.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\mjuyarxp.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: Nitrodial V2.lnk = C:\Program Files\Nitrodial V2\nitrodial.exe
O8 - Extra context menu item: Show All Original Images - res://C:\Program Files\Nitrodial V2\nitrodial.exe/250
O8 - Extra context menu item: Show Original Image - res://C:\Program Files\Nitrodial V2\nitrodial.exe/227
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: *.doginhispen.com
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/VaioInfo.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg…,16/mcgdmgr.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A261AE53-0F90-4901-AAD3-9A1001AAEFA8}: NameServer = 72.35.32.161 64.85.136.161
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: mjuyarxp - C:\WINDOWS\SYSTEM32\mjuyarxp.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
See what I mean by a "kettle of fish"?

I need to eliminate a possibility here:

Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Double-click smitfraudfix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm


Regards,

Trevuren
i did a smitfraud about a week ago but here's a fresh one: SmitFraudFix v2.253 Scan done at 18:23:53.87, Mon 11/19/2007 Run from C:\Documents and Settings\Debra Ritzema\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\System32\WScript.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe C:\WINDOWS\System32\hphmon05.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Nitrodial V2\nitrodial.exe C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\HPZipm12.exe c:\progra~1\Support.com\client\bin\tgcmd.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Debra Ritzema »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Debra Ritzema\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\DEBRAR~1\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: WAN (PPP/SLIP) Interface DNS Server Search Order: 72.35.32.161 DNS Server Search Order: 64.85.136.161 HKLM\SYSTEM\CCS\Services\Tcpip\..\{A261AE53-0F90-4901-AAD3-9A1001AAEFA8}: NameServer=72.35.32.161 64.85.136.161 HKLM\SYSTEM\CS1\Services\Tcpip\..\{A261AE53-0F90-4901-AAD3-9A1001AAEFA8}: NameServer=72.35.32.161 64.85.136.161 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End i'm including a kaspersky report i did a couple of days ago…it may be helpful..i don't know: KASPERSKY ONLINE SCANNER REPORT Thursday, November 15, 2007 3:20:17 AM Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 15/11/2007 Kaspersky Anti-Virus database records: 459745 Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true Scan Target My Computer A:\ C:\ D:\ E:\ F:\ Scan Statistics Total number of scanned objects 62299 Number of viruses found 16 Number of infected objects 66 Number of suspicious objects 1 Duration of the scan process 01:12:30 Infected Object Name Virus Name Last Action C:\Documents and Settings\All Users\Application Data\AntiSpyInfo\lcxrdhyo.dll.q_8043045_q Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped C:\Documents and Settings\All Users\Application Data\Sony Corporation\SonicStage\Packages\MtData.ldb Object is locked skipped C:\Documents and Settings\All Users\Application Data\Sony Corporation\SonicStage\Packages\MtData.mdb Object is locked skipped C:\Documents and Settings\Debra Ritzema\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Debra Ritzema\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Debra Ritzema\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Debra Ritzema\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Debra Ritzema\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Debra Ritzema\Local Settings\Temporary Internet Files\Content.IE5\IP9FVEU8\hctp[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\Documents and Settings\Debra Ritzema\Local Settings\Temporary Internet Files\Content.IE5\L7M5TZI2\pochki20071106[1] Infected: Trojan.Win32.Obfuscated.kp skipped C:\Documents and Settings\Debra Ritzema\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Debra Ritzema\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\hijackthis.log Suspicious: Exploit.HTML.Mht skipped C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe Infected: Trojan.Win32.Agent.bxj skipped C:\Program Files\dvdrnb.exe/data0002/NHInstall.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped C:\Program Files\dvdrnb.exe/data0002/v2.0.2.cab/NHUninstaller.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped C:\Program Files\dvdrnb.exe/data0002/v2.0.2.cab/NHUpdater.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped C:\Program Files\dvdrnb.exe/data0002/v2.0.2.cab/NHelper.dll Infected: not-a-virus:AdWare.Win32.NavExcel skipped C:\Program Files\dvdrnb.exe/data0002/v2.0.2.cab Infected: not-a-virus:AdWare.Win32.NavExcel skipped C:\Program Files\dvdrnb.exe/data0002 Infected: not-a-virus:AdWare.Win32.NavExcel skipped C:\Program Files\dvdrnb.exe/data0003/data0139 Infected: not-a-virus:AdWare.Win32.HelpExpress skipped C:\Program Files\dvdrnb.exe/data0003 Infected: not-a-virus:AdWare.Win32.HelpExpress skipped C:\Program Files\dvdrnb.exe Inno: infected - 8 skipped C:\Program Files\dvdrnb40.exe/data0002/NHInstall.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped C:\Program Files\dvdrnb40.exe/data0002/v2.0.2.cab/NHUninstaller.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped C:\Program Files\dvdrnb40.exe/data0002/v2.0.2.cab/NHUpdater.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped C:\Program Files\dvdrnb40.exe/data0002/v2.0.2.cab/NHelper.dll Infected: not-a-virus:AdWare.Win32.NavExcel skipped C:\Program Files\dvdrnb40.exe/data0002/v2.0.2.cab Infected: not-a-virus:AdWare.Win32.NavExcel skipped C:\Program Files\dvdrnb40.exe/data0002 Infected: not-a-virus:AdWare.Win32.NavExcel skipped C:\Program Files\dvdrnb40.exe/data0003/data0139 Infected: not-a-virus:AdWare.Win32.HelpExpress skipped C:\Program Files\dvdrnb40.exe/data0003 Infected: not-a-virus:AdWare.Win32.HelpExpress skipped C:\Program Files\dvdrnb40.exe Inno: infected - 8 skipped C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe Infected: Trojan.Win32.Agent.bxj skipped C:\Program Files\iTunes\iTunesHelper.exe Infected: Trojan.Win32.Agent.bxj skipped C:\Program Files\Lycos\IEagent\CSTMINST.DLL Infected: not-a-virus:AdWare.Win32.ClearSearch.o skipped C:\Program Files\Lycos\IEagent\CSTVINST.DLL Infected: not-a-virus:AdWare.Win32.ClearSearch.a skipped C:\Program Files\Microsoft Money\System\mnyexpr.exe Infected: Trojan.Win32.Agent.bxj skipped C:\Program Files\Nero\data\Xtras\mssysmgr.exe Infected: Trojan.Win32.Agent.bxj skipped C:\Program Files\QuickTime\qttask.exe Infected: Trojan.Win32.Agent.bxj skipped C:\Program Files\VERITAS Software\Update Manager\sgtray.exe Infected: Trojan.Win32.Agent.bxj skipped C:\Program Files\Winamp\winampa.exe Infected: Trojan.Win32.Agent.bxj skipped C:\SmitfraudFix\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\SmitfraudFix.zip ZIP: infected - 1 skipped C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1320\A0051259.vbs Infected: Trojan.Win32.Agent.bxj skipped C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1320\A0051290.vbs Infected: Trojan.Win32.Agent.bxj skipped C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1320\A0051298.exe Infected: Trojan.Win32.Agent.bxj skipped C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1320\A0051300.exe Infected: Trojan.Win32.Agent.bxj skipped C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1344\A0053795.exe Infected: Trojan.Win32.Agent.bck skipped C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1344\A0053867.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1349\A0056177.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1350\A0057247.exe Infected: not-a-virus:AdTool.Win32.WhenU.a skipped C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1351\A0058336.vbs Infected: Trojan.Win32.Agent.bxj skipped C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1351\change.log Object is locked skipped C:\WINDOWS\czjakvuslh.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.am skipped C:\WINDOWS\Debug\oakley.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\ModemLog_Agere Systems AC'97 Modem.txt Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe Infected: Trojan.Win32.Agent.bxj skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\bgwobmcs.exe Infected: Trojan.Win32.Obfuscated.kp skipped C:\WINDOWS\system32\bkqgflho.exe Infected: Trojan.Win32.Obfuscated.kp skipped C:\WINDOWS\system32\btdadmde.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped C:\WINDOWS\system32\cjlcqioc.exe Infected: Trojan.Win32.Obfuscated.kp skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\WINDOWS\system32\drivers\etc\hosts Infected: Trojan.Win32.Qhost.u skipped C:\WINDOWS\system32\efcdabc.dll Infected: Trojan-Downloader.Win32.Agent.epy skipped C:\WINDOWS\system32\eqaepvek.exe Infected: Trojan.Win32.Obfuscated.kp skipped C:\WINDOWS\system32\gkzijkcl.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\hkcmd.exe Infected: Trojan.Win32.Agent.bxj skipped C:\WINDOWS\system32\hphmon05.exe Infected: Trojan.Win32.Agent.bxj skipped C:\WINDOWS\system32\igfxtray.exe Infected: Trojan.Win32.Agent.bxj skipped C:\WINDOWS\system32\muvxcjwq.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped C:\WINDOWS\system32\mxutiebp.exe Infected: Trojan.Win32.Obfuscated.kp skipped C:\WINDOWS\system32\NeroCheck.exe Infected: Trojan.Win32.Agent.bxj skipped C:\WINDOWS\system32\rvheumkx.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\WINDOWS\system32\sbchkjpp.exe Infected: Trojan.Win32.Obfuscated.kp skipped C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe Infected: Trojan.Win32.Agent.bxj skipped C:\WINDOWS\system32\syuyjjbu.exe Infected: Trojan.Win32.Obfuscated.kp skipped C:\WINDOWS\system32\uiahbggw.exe Infected: Trojan.Win32.Obfuscated.kp skipped C:\WINDOWS\system32\vaffyujp.exe Infected: Trojan.Win32.Obfuscated.kp skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wvtqmmrv.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\WINDOWS\Temp\JETDE88.tmp Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
I just wanted to make sure that there were no Smitfraud components that had reinfected the machine and the Kaspersky log is too old to be of much good now. Thanks for the effort though. We will be having you run another one at the very end.

  • Download UnDLL by ESET from here
  • Unzip/extact it to a folder on the desktop
  • Double click on UNDLL.EXE to start UnDLL
  • Click on Select infected DLL
  • Locate and select this file:
    C:\WINDOWS\SYSTEM32\mjuyarxp.dll
  • Click Open
  • UnDLL will now attempt to delete the DLL file
  • If asked to restart your PC, click No
  • Run HijackThis
    Click on do a system scan only
    Place a checkmark next to these lines(if still present)

    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\mjuyarxp.dll
    O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\mjuyarxp.dll
    O20 - Winlogon Notify: mjuyarxp - C:\WINDOWS\SYSTEM32\mjuyarxp.dll


    Then close all windows except HijackThis and click Fix Checked
  • Restart your PC manually
Now post a new HijackThis log
the BHO and winlogon files weren't there, but the toolbar one was. here's a new HJL:

Logfile of HijackThis v1.99.1
Scan saved at 12:21:34 AM, on 11/20/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\WScript.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Nitrodial V2\nitrodial.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\HPZipm12.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\Program Files\Nitrodial V2\PBHelper.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: Nitrodial V2.lnk = C:\Program Files\Nitrodial V2\nitrodial.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: *.doginhispen.com
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/VaioInfo.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg…,16/mcgdmgr.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A261AE53-0F90-4901-AAD3-9A1001AAEFA8}: NameServer = 72.35.32.161 64.85.136.161
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
Excellent. Now we just have to retry the last big infection that did not quite work last time.

You have a downloader trojan called Downloader.Agent.awf or Downloader.Agent.ayy. This trojan replaces legitimate files that are common on most computers with an infected file. It then moves the legitimate file to a "bak" or backup folder. Please follow the directions below to run FindAWF so we can identify the files that have been infected and the backups then restore them.

Download FindAWF.exe from here or here, and save it to your desktop.
  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to "Press any key to continue".
  • You will be presented with a Menu.

    1. Press 1 then Enter to scan for bak folders
    2. Press 2 then Enter to restore files from bak folders
    3. Press 3 then Enter to remove bak folders
    4. Press 4 then Enter to reset domain zones
    5. Press E then Enter to EXIT

  • Press 1, then press Enter
  • It may take a few minutes to complete so be patient.
  • When it is complete, it will open a text file in notepad called AWF.txt.
  • Please copy and paste the contents of the AWF.txt file in your next reply.
i just used the one(FindAWF.exe) you had me download before. is that ok? Find AWF report by noahdfear ©2006 Version 1.40 The current date is: Tue 11/20/2007 The current time is: 0:49:41.28 bak folders found ~~~~~~~~~~~ Directory of C:\WINDOWS\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\ITUNES\BAK 06/14/2006 03:24 PM 278,528 iTunesHelper.exe 1 File(s) 278,528 bytes Directory of C:\PROGRA~1\MSNMES~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 07/26/2006 10:49 AM 282,624 qttask.exe 1 File(s) 282,624 bytes Directory of C:\PROGRA~1\WINAMP\BAK 12/20/2004 01:41 PM 33,792 winampa.exe 1 File(s) 33,792 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 03/11/2003 01:11 PM 114,688 hkcmd.exe 05/22/2003 07:55 AM 483,328 hphmon05.exe 03/11/2003 01:24 PM 155,648 igfxtray.exe 07/09/2001 09:50 AM 155,648 NeroCheck.exe 4 File(s) 909,312 bytes Directory of C:\PROGRA~1\ATITEC~1\ATICON~1\BAK 02/28/2003 11:00 PM 315,392 atiptaxx.exe 1 File(s) 315,392 bytes Directory of C:\PROGRA~1\HEWLET~1\{45B61~1\BAK 05/22/2003 08:03 AM 49,152 hphupd05.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\MICAC0~1\SYSTEM\BAK 07/17/2002 01:00 PM 200,767 mnyexpr.exe 1 File(s) 200,767 bytes Directory of C:\PROGRA~1\VERITA~1\UPDATE~1\BAK 06/18/2002 02:01 AM 155,648 sgtray.exe 1 File(s) 155,648 bytes Directory of C:\WINDOWS\SONYSYS\VAIORE~1\BAK 04/20/2003 12:08 AM 28,672 PartSeal.exe 1 File(s) 28,672 bytes Directory of C:\PROGRA~1\NERO\DATA\XTRAS\BAK 11/11/2004 08:50 PM 212,992 mssysmgr.exe 1 File(s) 212,992 bytes Directory of C:\PROGRA~1\SUPPORT.COM\CLIENT\LSERVER\BAK 07/14/2002 02:50 PM 11,406 server.vbs 1 File(s) 11,406 bytes Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK 05/07/2003 12:56 AM 188,416 hpztsb09.exe 1 File(s) 188,416 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 278528 Jun 14 2006 "C:\Program Files\iTunes\iTunesHelper.exe" 278528 Jun 14 2006 "C:\Program Files\iTunes\bak\iTunesHelper.exe" 282624 Jul 26 2006 "C:\Program Files\QuickTime\qttask.exe" 282624 Jul 26 2006 "C:\Program Files\QuickTime\bak\qttask.exe" 33792 Dec 20 2004 "C:\Program Files\Winamp\winampa.exe" 33792 Dec 20 2004 "C:\Program Files\Winamp\bak\winampa.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\Drivers\Video\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\bak\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\21\DriverFiles\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\25\DriverFiles\hkcmd.exe" 483328 May 22 2003 "C:\WINDOWS\system32\hphmon05.exe" 483328 May 22 2003 "C:\WINDOWS\system32\bak\hphmon05.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\Drivers\Video\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\bak\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\21\DriverFiles\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\25\DriverFiles\igfxtray.exe" 155648 Jul 9 2001 "C:\WINDOWS\system32\NeroCheck.exe" 155648 Jul 9 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe" 315392 Feb 28 2003 "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" 315392 Feb 28 2003 "C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe" 49152 May 22 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" 49152 May 22 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe" 200767 Jul 17 2002 "C:\Program Files\Microsoft Money\System\mnyexpr.exe" 200767 Jul 17 2002 "C:\Program Files\Java\Microsoft Money\System\mnyexpr.exe" 200767 Jul 17 2002 "C:\Program Files\Microsoft Money\System\bak\mnyexpr.exe" 155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" 155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe" 28672 Apr 20 2003 "C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe" 28672 Apr 20 2003 "C:\WINDOWS\SONYSYS\VAIO Recovery\bak\PartSeal.exe" 212992 Nov 11 2004 "C:\Program Files\Nero\data\Xtras\mssysmgr.exe" 212992 Nov 11 2004 "C:\Program Files\Nero\data\Xtras\bak\mssysmgr.exe" 11406 Jul 14 2002 "C:\Program Files\support.com\client\lserver\server.vbs" 11406 Jul 14 2002 "C:\Program Files\support.com\client\lserver\bak\server.vbs" 188416 May 7 2003 "C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" 188416 May 7 2003 "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb09.exe" end of report

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI