This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infections

103 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Done….Incoming logs…

ComboFix 07-11-19.4 - Leonard's 2007-12-04 8:08:53.5 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.69 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Leonard's\Desktop\CFSCRIPT.txt
* Created a new restore point

FILE
C:\pora.exe
C:\WINDOWS\SYSTEM32\ace16win.dll
C:\WINDOWS\system32\algs.exe
C:\WINDOWS\SYSTEM32\din.ip
C:\WINDOWS\SYSTEM32\dpqaqlqx.bin
C:\WINDOWS\system32\firewall.exe
C:\WINDOWS\system32\Isass.exe
C:\WINDOWS\SYSTEM32\jpewocmz.ini
C:\WINDOWS\SYSTEM32\mljklml.dll
C:\WINDOWS\SYSTEM32\qommmll.dll
C:\WINDOWS\SYSTEM32\stfv.bin
C:\WINDOWS\SYSTEM32\systemo2.exe
C:\WINDOWS\SYSTEM32\sznf.ascii
C:\WINDOWS\SYSTEM32\unpr.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\b3b6dfa3928d2fccb3f736a9
C:\b3b6dfa3928d2fccb3f736a9\mrt.exe._p
C:\b3b6dfa3928d2fccb3f736a9\mrtstub.exe
C:\pora.exe
C:\WINDOWS\SYSTEM32\ace16win.dll
C:\WINDOWS\SYSTEM32\acespy
C:\WINDOWS\SYSTEM32\acespy\__acelog.ndx
C:\WINDOWS\SYSTEM32\acespy\systune.exe
C:\WINDOWS\system32\algs.exe
C:\WINDOWS\SYSTEM32\din.ip
C:\WINDOWS\SYSTEM32\dpqaqlqx.bin
C:\WINDOWS\SYSTEM32\jpewocmz.ini
C:\WINDOWS\SYSTEM32\mljklml.dll
C:\WINDOWS\SYSTEM32\qommmll.dll
C:\WINDOWS\SYSTEM32\stfv.bin
C:\WINDOWS\SYSTEM32\systemo2.exe
C:\WINDOWS\SYSTEM32\sznf.ascii
C:\WINDOWS\SYSTEM32\unpr.sys

.
((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.

2007-11-26 16:58 d——– C:\Documents and Settings\Leonard's\DoctorWeb
2007-11-10 13:10 d——– C:\Program Files\uTorrent
2007-11-10 13:10 d——– C:\Documents and Settings\Leonard's\Application Data\uTorrent
2007-11-05 07:50 9,728 –a—— C:\WINDOWS\_MSRSTRT.EXE

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-03 15:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-03 15:28 68,830,616 —-a-w C:\Documents and Settings\Leonard's\jdk-6u3-windows-i586-p.exe
2007-11-03 15:19 382,352 —-a-w C:\Documents and Settings\Leonard's\jdk-6u3-windows-i586-p-iftw.exe
2007-11-02 18:03 ——— d—–w C:\Documents and Settings\Leonard's\Application Data\Grisoft
2007-11-02 17:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2007-10-14 20:23 ——— d–h–w C:\Program Files\Ss-Tools
2007-08-14 01:14 649,921 —-a-w C:\Documents and Settings\My Programs\data_eraser_setup.exe
2006-08-24 17:47 1,704,069 —-a-w C:\Documents and Settings\My Programs\PHOTOFILTRE SETUP.exe
2006-04-19 15:31 5,037,072 —-a-w C:\Documents and Settings\My Programs\spybotsd14.exe
2006-04-19 15:29 2,855,080 —-a-w C:\Documents and Settings\My Programs\aawsepersonal.exe
2006-03-01 14:14 5,640,784 —-a-w C:\Documents and Settings\My Programs\winamp52_full_emusic-7plus.exe
2006-02-28 14:28 2,167,119 —-a-w C:\Documents and Settings\My Programs\DBPOWER AMP-r11[1].5.exe
2006-02-28 13:48 1,665,325 —-a-w C:\Documents and Settings\My Programs\AUDIOGRABBER (setup).exe
2006-01-03 14:29 32,835 —-a-w C:\Documents and Settings\My Programs\HotKeyplus100.zip
2005-12-29 13:32 5,225,384 —-a-w C:\Documents and Settings\My Programs\Firefox Setup 1.5.exe
2005-12-23 22:19 189,764 —-a-w C:\Documents and Settings\My Programs\Mp3DC139.exe
2005-12-02 15:53 865,846 —-a-w C:\Documents and Settings\My Programs\srwa5-1.61.17.exe
2005-10-29 11:10 70,315 —-a-w C:\Documents and Settings\My Programs\Auto Close Winamp V.1.4 (5 star).exe
2005-10-17 01:49 816,782 —ha-w C:\Documents and Settings\My Programs\oggcodecs_0.69.8924 (for wmp).exe
2005-10-15 11:15 1,978,007 —ha-w C:\Documents and Settings\My Programs\mp3gain-win-full-1_2_5.exe
2005-09-29 20:29 1,207,074 —ha-w C:\Documents and Settings\My Programs\eac-0.95b3.exe
2005-09-25 20:34 4,878,136 —ha-w C:\Documents and Settings\My Programs\Firefox Setup 1.0.7.exe
2005-09-13 20:30 1,934,096 —ha-w C:\Documents and Settings\My Programs\DBPowerAmp-r11.exe
2005-08-18 17:48 79 —-a-w C:\Program Files\Show Desktop.scf
2005-07-09 14:59 1,585,777 —ha-w C:\Documents and Settings\My Programs\PhotoFiltre.exe
2002-11-26 05:10 40,012 —-a-w C:\Documents and Settings\My Programs\DBPower Amp Reset.exe
.

((((((((((((((((((((((((((((( snapshot@2007-11-27_11.56.46.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-13 16:57:12 174,080 —-a-w C:\WINDOWS\erdnt\subs\F3M\ERDNT.EXE
- 2007-11-27 12:47:12 16,384 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2007-12-04 12:49:58 16,384 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
- 2007-11-27 12:47:12 32,768 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2007-12-04 12:49:58 32,768 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
- 2007-11-27 12:47:12 32,768 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT
+ 2007-12-04 12:49:58 32,768 –sha-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPP Auto Loader"="C:\WINDOWS\tppaldr.exe" [2002-06-24 10:20]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-21 16:48]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-21 16:44]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-24 18:15]
"HotKeyz.exe"="" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]

C:\Documents and Settings\Leonard's\Start Menu\Programs\Startup\
Eagle Listener.lnk - C:\3apps\Catapult\3listen.exe [2005-08-18 11:54:07]
Eagle Scheduler.lnk - C:\3apps\Catapult\Sched.exe [2005-08-18 11:54:22]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
"NoToolbarsOnTaskbar"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!ewido]
C:\Program Files\ewido anti-spyware 4.0\ewido.exe /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfee Managed Services Tray]
2006-05-02 14:11 147456 –a—— C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MVS Splash]
2006-05-02 14:27 417792 –a—— C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuikShield]
qkshield.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"McShield"=3 (0x3)

R1 mfetdik;McAfee Inc.;C:\WINDOWS\system32\drivers\mfetdik.sys
R2 ASFAgent;ASF Agent;C:\Program Files\Intel\ASF Agent\ASFAgent.exe
R2 myAgtSvc;McAfee Total Protection Agent Service;C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe /ServiceStart
R2 NetAlrt;NetAlrt;\??\C:\WINDOWS\System32\drivers\NetAlrt.sys
R2 PlatAlrt;PlatAlrt;\??\C:\WINDOWS\System32\drivers\PlatAlrt.sys
R2 SWAGENT;SonicWALL Agent Service;C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
S0 UNPR;UNPR;C:\WINDOWS\system32\unpr.sys
S3 NMSCFG;NIC Management Service Configuration Driver;\??\C:\WINDOWS\system32\drivers\NMSCFG.SYS
S3 NMSSvc;Intel® NMS;C:\WINDOWS\System32\NMSSvc.exe
S3 TPP200;USB Storage Adapter V2 (TPP);C:\WINDOWS\system32\DRIVERS\TPP200.SYS

.
Contents of the 'Scheduled Tasks' folder
"2007-12-04 14:12:54 C:\WINDOWS\Tasks\HotKeyPlus.job"
- C:\Program Files\HotKeyplus100\HotKeyPlus.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-04 08:14:09
Windows 5.1.2600 Service Pack 2 FAT NTAPI

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-04 8:15:32 - machine was rebooted
C:\ComboFix2.txt … 2007-11-27 11:57
.
— E O F —

AND

Logfile of HijackThis v1.99.1
Scan saved at 8:16:42 AM, on 12/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\tppaldr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\3apps\Catapult\3listen.exe
C:\3apps\Catapult\Sched.exe
C:\3apps\CATAPULT\APPIPC.exe
C:\WINDOWS\system32\P32HELP.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\program files\plethora\hijackthis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9000
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HotKeyz.exe Startup] C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe Startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Eagle Listener.lnk = C:\3apps\Catapult\3listen.exe
O4 - Startup: Eagle Scheduler.lnk = C:\3apps\Catapult\Sched.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC039A07-7AFA-4AAC-95A9-D7FA4F6BA664}: NameServer = 68.1.208.30,68.1.208.25
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.0.0.358.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee Total Protection Agent Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: SonicWALL Agent Service (SWAGENT) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
Hi

Don't worry, we're getting there. We need to do another CFScript.


1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

Driver::
UNPR

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Thanks,

jpshortstuff
I really appreciate all the help…anyways…

ComboFix 07-11-19.4 - Leonard's 2007-12-04 13:14:41.6 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.80 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Leonard's\Desktop\CFSCRIPT.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.

2007-12-04 08:14 2,432 –a—— C:\WINDOWS\SYSTEM32\unpr.sys
2007-11-26 16:58 d——– C:\Documents and Settings\Leonard's\DoctorWeb
2007-11-10 13:10 d——– C:\Program Files\uTorrent
2007-11-10 13:10 d——– C:\Documents and Settings\Leonard's\Application Data\uTorrent
2007-11-05 07:50 9,728 –a—— C:\WINDOWS\_MSRSTRT.EXE

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-03 15:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-03 15:28 68,830,616 —-a-w C:\Documents and Settings\Leonard's\jdk-6u3-windows-i586-p.exe
2007-11-03 15:19 382,352 —-a-w C:\Documents and Settings\Leonard's\jdk-6u3-windows-i586-p-iftw.exe
2007-11-02 18:03 ——— d—–w C:\Documents and Settings\Leonard's\Application Data\Grisoft
2007-11-02 17:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2007-10-14 20:23 ——— d–h–w C:\Program Files\Ss-Tools
2007-08-14 01:14 649,921 —-a-w C:\Documents and Settings\My Programs\data_eraser_setup.exe
2006-08-24 17:47 1,704,069 —-a-w C:\Documents and Settings\My Programs\PHOTOFILTRE SETUP.exe
2006-04-19 15:31 5,037,072 —-a-w C:\Documents and Settings\My Programs\spybotsd14.exe
2006-04-19 15:29 2,855,080 —-a-w C:\Documents and Settings\My Programs\aawsepersonal.exe
2006-03-01 14:14 5,640,784 —-a-w C:\Documents and Settings\My Programs\winamp52_full_emusic-7plus.exe
2006-02-28 14:28 2,167,119 —-a-w C:\Documents and Settings\My Programs\DBPOWER AMP-r11[1].5.exe
2006-02-28 13:48 1,665,325 —-a-w C:\Documents and Settings\My Programs\AUDIOGRABBER (setup).exe
2006-01-03 14:29 32,835 —-a-w C:\Documents and Settings\My Programs\HotKeyplus100.zip
2005-12-29 13:32 5,225,384 —-a-w C:\Documents and Settings\My Programs\Firefox Setup 1.5.exe
2005-12-23 22:19 189,764 —-a-w C:\Documents and Settings\My Programs\Mp3DC139.exe
2005-12-02 15:53 865,846 —-a-w C:\Documents and Settings\My Programs\srwa5-1.61.17.exe
2005-10-29 11:10 70,315 —-a-w C:\Documents and Settings\My Programs\Auto Close Winamp V.1.4 (5 star).exe
2005-10-17 01:49 816,782 —ha-w C:\Documents and Settings\My Programs\oggcodecs_0.69.8924 (for wmp).exe
2005-10-15 11:15 1,978,007 —ha-w C:\Documents and Settings\My Programs\mp3gain-win-full-1_2_5.exe
2005-09-29 20:29 1,207,074 —ha-w C:\Documents and Settings\My Programs\eac-0.95b3.exe
2005-09-25 20:34 4,878,136 —ha-w C:\Documents and Settings\My Programs\Firefox Setup 1.0.7.exe
2005-09-13 20:30 1,934,096 —ha-w C:\Documents and Settings\My Programs\DBPowerAmp-r11.exe
2005-08-18 17:48 79 —-a-w C:\Program Files\Show Desktop.scf
2005-07-09 14:59 1,585,777 —ha-w C:\Documents and Settings\My Programs\PhotoFiltre.exe
2002-11-26 05:10 40,012 —-a-w C:\Documents and Settings\My Programs\DBPower Amp Reset.exe
.

((((((((((((((((((((((((((((( snapshot@2007-11-27_11.56.46.57 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-08 22:59:02 146,944 —-a-w C:\WINDOWS\catchme.exe
+ 2007-11-08 22:59:02 136,704 —-a-w C:\WINDOWS\catchme.exe
+ 2007-03-13 16:57:12 163,328 —-a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2007-06-17 06:11:58 58,368 —-a-w C:\WINDOWS\NirCmd.exe
+ 2007-06-17 06:11:58 51,200 —-a-w C:\WINDOWS\NirCmd.exe
- 2007-11-27 12:47:12 16,384 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2007-12-04 12:49:58 16,384 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
- 2007-11-27 12:47:12 32,768 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2007-12-04 12:49:58 32,768 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
- 2007-07-23 00:39:28 289,792 —-a-w C:\WINDOWS\SYSTEM32\swreg.exe
+ 2007-07-23 00:39:28 279,552 —-a-w C:\WINDOWS\SYSTEM32\swreg.exe
+ 2007-12-04 19:22:26 16,384 –sha-w C:\WINDOWS\TEMP\Cookies\index.dat
+ 2007-12-04 19:22:26 16,384 –sha-w C:\WINDOWS\TEMP\History\History.IE5\index.dat
+ 2007-12-04 19:22:26 32,768 –sha-w C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPP Auto Loader"="C:\WINDOWS\tppaldr.exe" [2002-06-24 10:20]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-21 16:48]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-21 16:44]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-24 18:15]
"HotKeyz.exe"="" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]

C:\Documents and Settings\Leonard's\Start Menu\Programs\Startup\
Eagle Listener.lnk - C:\3apps\Catapult\3listen.exe [2005-08-18 11:54:07]
Eagle Scheduler.lnk - C:\3apps\Catapult\Sched.exe [2005-08-18 11:54:22]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
"NoToolbarsOnTaskbar"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!ewido]
C:\Program Files\ewido anti-spyware 4.0\ewido.exe /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfee Managed Services Tray]
2006-05-02 14:11 147456 –a—— C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MVS Splash]
2006-05-02 14:27 417792 –a—— C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuikShield]
qkshield.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"McShield"=3 (0x3)

R1 mfetdik;McAfee Inc.;C:\WINDOWS\system32\drivers\mfetdik.sys
R2 ASFAgent;ASF Agent;C:\Program Files\Intel\ASF Agent\ASFAgent.exe
R2 myAgtSvc;McAfee Total Protection Agent Service;C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe /ServiceStart
R2 NetAlrt;NetAlrt;\??\C:\WINDOWS\System32\drivers\NetAlrt.sys
R2 PlatAlrt;PlatAlrt;\??\C:\WINDOWS\System32\drivers\PlatAlrt.sys
R2 SWAGENT;SonicWALL Agent Service;C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
S3 NMSCFG;NIC Management Service Configuration Driver;\??\C:\WINDOWS\system32\drivers\NMSCFG.SYS
S3 NMSSvc;Intel® NMS;C:\WINDOWS\System32\NMSSvc.exe
S3 TPP200;USB Storage Adapter V2 (TPP);C:\WINDOWS\system32\DRIVERS\TPP200.SYS

.
Contents of the 'Scheduled Tasks' folder
"2007-12-04 19:21:22 C:\WINDOWS\Tasks\HotKeyPlus.job"
- C:\Program Files\HotKeyplus100\HotKeyPlus.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-04 13:21:59
Windows 5.1.2600 Service Pack 2 FAT NTAPI

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-04 13:24:04 - machine was rebooted
C:\ComboFix3.txt … 2007-11-27 11:57
C:\ComboFix2.txt … 2007-12-04 08:15
.
— E O F —

AND

Logfile of HijackThis v1.99.1
Scan saved at 1:25:11 PM, on 12/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\tppaldr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\3apps\Catapult\3listen.exe
C:\3apps\Catapult\Sched.exe
C:\3apps\CATAPULT\APPIPC.exe
C:\WINDOWS\system32\P32HELP.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\3apps\Catapult\pos.exe
C:\program files\plethora\hijackthis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9000
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HotKeyz.exe Startup] C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe Startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Eagle Listener.lnk = C:\3apps\Catapult\3listen.exe
O4 - Startup: Eagle Scheduler.lnk = C:\3apps\Catapult\Sched.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC039A07-7AFA-4AAC-95A9-D7FA4F6BA664}: NameServer = 68.1.208.30,68.1.208.25
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.0.0.358.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee Total Protection Agent Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: SonicWALL Agent Service (SWAGENT) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
Hi


Please Right Click your Start button, and click Explore.
Next, locate and delete the following file(if present):

C:\WINDOWS\SYSTEM32\unpr.sys <



Please run this online scan:

Panda ActiveScan

  • Once you are on the Panda site, click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on Local Disks to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.

Post the contents of the Panda scan report, along with a new HijackThis Log

Thanks,

jpshortstuff
Incident Status Location

Adware:adware/adbars Not disinfected Windows Registry
Dialer:dialer.xd Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{54645654-2225-4455-44A1-9F4543D34546}
Adware:adware/activesearch Not disinfected Windows Registry
Adware:adware/404search Not disinfected Windows Registry
Adware:adware/adblaster Not disinfected Windows Registry
Adware:adware/adsincontext Not disinfected Windows Registry
Virus:Generic Trojan Disinfected C:\QOOBOX\Quarantine\C\WINDOWS\SYSTEM32\mljklml.dll.vir
Virus:Generic Trojan Disinfected C:\QOOBOX\Quarantine\C\WINDOWS\SYSTEM32\systemo2.exe.vir
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\fixwareout\FindT\NIRCMD.EXE
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Leonard's\Desktop\ComboFix.exe[nircmd.exe]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Leonard's\Desktop\ComboFix.exe[nircmd.cfexe]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.advertising.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.doubleclick.net/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.advertising.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[ad.yieldmanager.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.revenue.net/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[searchportal.information.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.casalemedia.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.fastclick.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.atdmt.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.adrevolver.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.zedo.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.trafficmp.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.mediaplex.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.apmebf.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.tribalfusion.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.bluestreak.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.statcounter.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.ads.pointroll.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.com.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.realmedia.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.247realmedia.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.atwola.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.adserver.easyad.info/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.belnk.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.go.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\COOKIES.TXT[.xiti.com/]
Virus:W95/Marburg Disinfected C:\Documents and Settings\My Programs\FAV PRG 2 (source)\Paintshop Pro\Anim300 Crack.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Program Files\Plethora\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Virus:Trj/Rebooter.J Disinfected C:\Program Files\Plethora\SmitfraudFix.zip[SmitfraudFix/Reboot.exe]
Potentially unwanted tool:Application/SuperFast Not disinfected C:\Program Files\Plethora\SmitfraudFix.zip[SmitfraudFix/restart.exe]

Wow…that looked a whole lot more….readable in my notepad.

Logfile of HijackThis v1.99.1
Scan saved at 8:19:06 AM, on 12/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\tppaldr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\3apps\Catapult\3listen.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\3apps\Catapult\Sched.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\3apps\CATAPULT\APPIPC.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\system32\P32HELP.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\3apps\Catapult\pos.exe
C:\WINDOWS\system32\Calc.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\program files\plethora\hijackthis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9000
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HotKeyz.exe Startup] C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe Startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Eagle Listener.lnk = C:\3apps\Catapult\3listen.exe
O4 - Startup: Eagle Scheduler.lnk = C:\3apps\Catapult\Sched.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC039A07-7AFA-4AAC-95A9-D7FA4F6BA664}: NameServer = 68.1.208.30,68.1.208.25
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.0.0.358.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee Total Protection Agent Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: SonicWALL Agent Service (SWAGENT) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
Hi

First of all, we have evidence of Cracked software showing up in your logs:
C:\Documents and Settings\My Programs\FAV PRG 2 (source)\Paintshop Pro\Anim300 Crack.exe

Cracked software is a huge source of malware these days, almost certainly where you contracted your many infections from. If you don't want to be back here a few weeks with the same problems, I strongly suggest you stop downloading cracks/keygens, and also uninstall any cracked software you currently have. We don't want to be treating the same people over and over again because of something like this.


Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open.

If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-click on avgas-signatures-full-current.exe to install the database).
Please set up the program as follows:
  • Click the Shield icon at the top and under Resident shield is… click active. This should now
    change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
  • Under How to act? - make sure that Quarantine is selected.
  • Under How to scan? - All checkboxes should be ticked.
  • Under Possibly unwanted software - All checkboxes should be ticked.
  • Under Reports - Select Do not automatically generate reports.
  • Under What to scan? - Select Scan every file.
Close all open windows.
Do not run a scan yet.

Reboot your computer into SafeMode
You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
Use your up arrow key to highlight SafeMode then hit enter.



IMPORTANT: Do not open any other windows or
programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  • Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
    • Make sure that Set all elements to: shows Quarantine
    • Important: Click on the Apply all Actions button (*** This must done before saving the report ***)
    • When the program has finished, it will display the message All actions have been applied.
    • Then click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
    • Right-click the AVG Tray Icon and select Exit. Confirm by clicking Yes.
    • Reboot in normal mode and copy the report back to this topic along with a new HijackThis log.


    Please also describe how your computer is running now.

    Thanks,

    jpshortstuff
Actually I'm quite glad you mentioned the part about cracked software. That would be my partner who likes to consider himself some sort of audio/video editing master and has all sorts of pirated editing software. That being said I don't think that'll be an issue anymore. :) And here's the log: ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 3:09:20 PM 12/7/2007 + Scan result: :mozilla.325:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.247realmedia : No action taken. :mozilla.161:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.162:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.163:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.327:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.252:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.253:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.219:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.220:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.221:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.222:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.223:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.224:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.225:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.226:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.123:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.124:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.125:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.126:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.127:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.35:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Atdmt : No action taken. :mozilla.293:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken. :mozilla.34:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Burstnet : No action taken. :mozilla.139:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.140:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.141:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.142:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.143:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.144:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.145:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.146:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.147:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.53:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken. C:\Documents and Settings\Leonard's\Cookies\leonard's@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken. :mozilla.259:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Euroclick : No action taken. :mozilla.260:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Euroclick : No action taken. :mozilla.261:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Euroclick : No action taken. :mozilla.262:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Euroclick : No action taken. :mozilla.155:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Fastclick : No action taken. :mozilla.156:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Fastclick : No action taken. :mozilla.157:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Fastclick : No action taken. :mozilla.331:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.334:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.286:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken. :mozilla.287:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken. :mozilla.138:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Information : No action taken. :mozilla.263:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken. :mozilla.264:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken. :mozilla.36:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.37:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.38:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.39:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.40:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.41:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.42:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.43:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.44:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.322:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Realmedia : No action taken. :mozilla.137:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Revenue : No action taken. :mozilla.239:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.240:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.241:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.329:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Sitestat : No action taken. :mozilla.330:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Sitestat : No action taken. :mozilla.301:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.29:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.30:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.31:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.32:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.33:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.254:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.255:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.256:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.257:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.258:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.289:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.46:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.47:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.48:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.57:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.58:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.243:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Zedo : No action taken. :mozilla.244:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Zedo : No action taken. :mozilla.245:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Zedo : No action taken. C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP20\A0012964.sys -> Trojan.KillAV.cn : No action taken. C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP21\A0014065.sys -> Trojan.KillAV.cn : No action taken. C:\WINDOWS\SYSTEM32\unpr.sys -> Trojan.KillAV.cn : No action taken. C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\unpr.sys.vir -> Trojan.KillAV.cn : No action taken. ::Report end The computer never really had much noticable about it to begin with. So it's hard to describe how it's behaving. The infections really only just alerted me to their presence…they don't seem to be doing anything…noticably bad.

Actually I'm quite glad you mentioned the part about cracked software. That would be my partner who likes to consider himself some sort of audio/video editing master and has all sorts of pirated editing software. That being said I don't think that'll be an issue anymore. :)

Good to hear :thumbup:

Can I see a new HijackThis log please?
Logfile of HijackThis v1.99.1
Scan saved at 10:20:23 AM, on 12/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\tppaldr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\3apps\Catapult\3listen.exe
C:\3apps\Catapult\Sched.exe
C:\3apps\CATAPULT\APPIPC.exe
C:\WINDOWS\system32\P32HELP.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\3apps\Catapult\pos.exe
C:\3apps\CATAPULT\3uparc.exe
C:\3apps\services\wruncbl.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\program files\plethora\hijackthis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9000
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HotKeyz.exe Startup] C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe Startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Eagle Listener.lnk = C:\3apps\Catapult\3listen.exe
O4 - Startup: Eagle Scheduler.lnk = C:\3apps\Catapult\Sched.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC039A07-7AFA-4AAC-95A9-D7FA4F6BA664}: NameServer = 68.1.208.30,68.1.208.25
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.0.0.358.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee Total Protection Agent Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: SonicWALL Agent Service (SWAGENT) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe

Here's the newest log. Thanks for all the patience on this one…it's much appreciated.
Hi, we need to run the AVG scan again.

Make sure you do this first bit, exactly as it says:

Please set up the program as follows:

  • Click the Shield icon at the top and under Resident shield is… click active. This should now
    change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act? - make sure that Quarantine is selected.
    • Under How to scan? - All checkboxes should be ticked.
    • Under Possibly unwanted software - All checkboxes should be ticked.
    • Under Reports - Select Do not automatically generate reports.
    • Under What to scan? - Select Scan every file.

Close all open windows.
Do not run a scan yet.

Reboot your computer into SafeMode
You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
Use your up arrow key to highlight SafeMode then hit enter.



IMPORTANT: Do not open any other windows or
programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  • Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
    • Make sure that Set all elements to: shows Quarantine
    • Important: Click on the Apply all Actions button (*** This must done before saving the report ***)
    • When the program has finished, it will display the message All actions have been applied.
    • Then click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
    • Right-click the AVG Tray Icon and select Exit. Confirm by clicking Yes.
    • Reboot in normal mode and copy the report back to this topic along with a new HijackThis log.

    Thanks,

    jpshortstuff
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 4:01:51 PM 12/10/2007

+ Scan result:



:mozilla.325:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.190:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.191:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.192:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.327:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.275:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.276:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.242:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.243:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.244:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.245:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.246:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.247:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.248:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.249:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.52:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.53:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.54:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.55:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.56:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.41:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.293:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.155:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.171:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.172:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.173:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.174:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.175:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.176:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.177:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.178:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.179:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.42:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Leonard's\Cookies\leonard's@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.23:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.24:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.25:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.26:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.27:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.28:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.113:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.114:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.115:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.116:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.117:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.331:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.334:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.286:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.287:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.170:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Information : Cleaned.
:mozilla.129:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.130:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.156:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.157:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.158:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.159:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.160:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.161:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.162:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.163:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.164:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.322:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.169:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.262:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.263:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.264:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.329:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.330:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.301:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.151:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.152:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.153:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.154:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.124:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.125:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.126:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.127:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.128:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.289:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.29:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.30:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.31:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.32:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.33:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.266:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.267:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.268:C:\Documents and Settings\Leonard's\Application Data\Mozilla\Firefox\Profiles\0ovn4khl.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\WINDOWS\SYSTEM32\unpr.sys -> Trojan.KillAV.cn : Cleaned with backup (quarantined).
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\unpr.sys.vir -> Trojan.KillAV.cn : Cleaned with backup (quarantined).


::Report end

AND

Logfile of HijackThis v1.99.1
Scan saved at 4:05:04 PM, on 12/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\tppaldr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\3apps\Catapult\3listen.exe
C:\3apps\Catapult\Sched.exe
C:\3apps\CATAPULT\APPIPC.exe
C:\WINDOWS\system32\P32HELP.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\3apps\Catapult\pos.exe
C:\WINDOWS\system32\wscntfy.exe
C:\program files\plethora\hijackthis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9000
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HotKeyz.exe Startup] C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe Startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Eagle Listener.lnk = C:\3apps\Catapult\3listen.exe
O4 - Startup: Eagle Scheduler.lnk = C:\3apps\Catapult\Sched.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC039A07-7AFA-4AAC-95A9-D7FA4F6BA664}: NameServer = 68.1.208.30,68.1.208.25
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.0.0.358.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee Total Protection Agent Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: SonicWALL Agent Service (SWAGENT) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe

I did notice that when Windows was loading the drivers for safe mode, one of the drivers loaded was unpr.sys which if I recall is something you had me attempt to get rid of.
Hi

Open AVG Anti-Spyware. Click on the Infections icon, where you should see a list of all the quarantined items. Click on Select All, and then Remove Finally. Close AVG.

Please reboot your computer, post a new HijackThis log and let me know how the computer is running.

Thanks,

jpshortstuff
Done…and the new log:

Logfile of HijackThis v1.99.1
Scan saved at 11:48:57 AM, on 12/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\tppaldr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\3apps\Catapult\3listen.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
C:\3apps\Catapult\Sched.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\3apps\CATAPULT\APPIPC.exe
C:\WINDOWS\system32\P32HELP.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\3apps\Catapult\pos.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\3apps\CATAPULT\3uparc.exe
C:\3apps\services\wruncbl.exe
C:\program files\plethora\hijackthis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9000
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HotKeyz.exe Startup] C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe Startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Eagle Listener.lnk = C:\3apps\Catapult\3listen.exe
O4 - Startup: Eagle Scheduler.lnk = C:\3apps\Catapult\Sched.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC039A07-7AFA-4AAC-95A9-D7FA4F6BA664}: NameServer = 68.1.208.30,68.1.208.25
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.0.0.358.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee Total Protection Agent Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: SonicWALL Agent Service (SWAGENT) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
Please right click your start button, and click Explore. Navigate to this folder:
C:\WINDOWS\SYSTEM32\
and see if this file exists:
unpr.sys

Please let me know, thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI