This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Need Some Help

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey guys, i know i started another thread in the "WHAT THE HECK SECTION" But i just found the SELF HELP thread. Here is my situation I'm trying everything with no luck.

I have a wierd problem. A few days ago, this problem started to happen on my computer. I have Verizon Fios Internet and a Router they provided. I have wireless internet and 2 other computers attached to it, mine being the main and im using ethernet. What the problem is that a few days ago, no websites are loading, I get the page cannot be found errors, the typical one when your internet is down, however when i hit refresh about 5-10times the site loads but not completely, and I have to keep hitting refresh for the pages to load, sometimes they just don't load. It's not a particular site, its EVERY SITE and I've also tried Firefox, samething. Now I KNOW ITS XP because on other computers (Laptop and another desktop) I'm not having this problem. I've checked the router and everything seems to be running smoothly, i've restarted router many times…I think it might be something to do with WINDOWS XP. ANy Input? I was told my WINSOCK might be corrupt to so i got http://www.snapfiles.com/get/winsockxpfix.html winsockfix and after reboot am getting the same thing. The pages will either load half way as in no IMAGES will show, only text, they will load completely, or not at all. I have to keep hitting refresh continuously until the site starts to one of the above mentioned. Once again this is only on this computer. I have HijAck this and I ran it to see alot of stuff running. I've used SPYBOT S&D 1.4 to delete any malware / spyware.

Here are my logs from both AVG and HIJACK THIS. It won't let me upload the files because once again it lags on upload, i had to refresh 20 times to post this, like click 20 TIMES on POST POST POST….



AVG=====================================================

+ Created at: 11:10:56 PM 11/19/2007

+ Scan result:



C:\WINDOWS\system32\mi1.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP166\A0019179.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP166\A0020179.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP175\A0021182.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP179\A0021994.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP191\A0022997.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP191\A0023994.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP194\A0024119.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP195\A0024151.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP199\A0024281.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP201\A0024331.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP208\A0025332.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP208\A0025338.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP211\A0025395.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP215\A0025450.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP244\A0025682.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP246\A0025721.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP253\A0025878.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP256\A0026919.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP263\A0027878.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP263\A0028877.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP265\A0029877.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP267\A0030877.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP269\A0031881.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP271\A0032877.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP271\A0033877.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP276\A0033999.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP276\A0034018.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP277\A0034050.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP280\A0034074.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\WINDOWS\system32\svchost.sys -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP276\A0033989.exe -> Backdoor.Rbot.aeu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP276\A0034006.exe -> Backdoor.Rbot.aeu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP280\A0034098.exe -> Backdoor.Rbot.aeu : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Mz16r\Mz16r2291.exe -> Downloader.VB.bkw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP166\A0019180.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP166\A0019181.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP166\A0020180.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP166\A0020181.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP175\A0021183.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP175\A0021184.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP179\A0021995.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP179\A0021996.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP191\A0022998.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP191\A0023995.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP191\A0023997.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP194\A0024120.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP194\A0024121.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP195\A0024152.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP195\A0024153.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP199\A0024282.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP199\A0024283.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP201\A0024332.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP201\A0024333.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP208\A0025333.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP208\A0025339.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP208\A0025340.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP211\A0025396.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP215\A0025451.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP215\A0025452.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP244\A0025683.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP244\A0025684.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP246\A0025722.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP246\A0025723.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP253\A0025879.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP253\A0025880.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP256\A0026920.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP256\A0026921.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP263\A0027879.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP263\A0027882.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP263\A0028878.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP263\A0028879.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP265\A0029878.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP265\A0029879.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP267\A0030878.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP267\A0030879.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP269\A0031882.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP269\A0031883.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP271\A0032878.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP271\A0032879.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP271\A0033878.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP271\A0033879.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP276\A0034000.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP276\A0034001.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP276\A0034019.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP276\A0034020.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP277\A0034051.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP280\A0034075.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP280\A0034077.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
C:\WINDOWS\system32\4W34TXYorx.ini -> Dropper.Delf.rc : Cleaned with backup (quarantined).
E:\Downloads\Win Rar + Crack.rar/Win Rar + Crack\Crack\Crack.exe -> Dropper.Delf.rc : Cleaned with backup (quarantined).
:mozilla.108:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.89:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.64:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.65:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.204:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.73:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.74:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.75:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.76:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.77:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.82:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.109:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.110:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.203:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.140:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.141:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.146:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.147:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.148:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.149:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.150:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.151:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.194:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.160:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.161:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.162:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.163:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.187:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.188:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.189:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.190:C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\a5nprmzz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{72F8BCC8-7AD2-4F03-BA6B-3C4F5169BEB7}\RP263\A0027891.dll -> Trojan.Maha.a : Cleaned with backup (quarantined).
C:\WINDOWS\sqlserver.dll -> Trojan.Maha.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Customer\Application Data\DVDPART\Fork cool loud.exe -> Trojan.Obfuscated.en : Cleaned with backup (quarantined).


::Report end






HIJACK THIS========================================


Logfile of HijackThis v1.99.1
Scan saved at 11:15:05 PM, on 11/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
F:\Program Files\Autodesk\mentalray\satellite\raysat_3dsmax8server.exe
C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
C:\WINDOWS\trkwksvc.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\PSIService.exe
F:\XSI_6.0\Application\bin\raysat3_5_6_3server.exe
C:\WINDOWS\system32\spm\spmd.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe
F:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ASUS\PC Probe II\Probe2.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
F:\Program Files\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe
C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe
C:\Program Files\HijackThis\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\
F3 - REG:win.ini: load=C:\WINDOWS\system32\scvhost.exe
F3 - REG:win.ini: run=C:\WINDOWS\system32\scvhost.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [Generic Host Process] C:\WINDOWS\system32\scvhost.exe
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [WinampAgent] F:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Launch PC Probe II] "C:\Program Files\ASUS\PC Probe II\Probe2.exe" 1
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVFX Engine] F:\Program Files\Creative Live! Cam\VideoFX\StartFX.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [Generic Host Process] C:\WINDOWS\system32\scvhost.exe
O4 - HKCU\..\Run: [µTorrent] "C:\Program Files\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [ares] "F:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [PlayNC Launcher] C:\program files\ncsoft\launcher\NCLauncher.exe /Minimized
O4 - HKCU\..\Run: [Creative Live! Cam Manager] "F:\Program Files\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: ASUS WiFi-AP Solo.lnk = ?
O4 - Global Startup: DualCoreCenter.lnk = C:\Program Files\MSI\DualCoreCenter\StartUpDualCoreCenter.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - F:\Program Files\Ares\chatServer.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - F:\Program Files\Autodesk\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: RaySat3_5_6_3 Server (RaySat3_5_6_3Server) - Unknown owner - F:\XSI_6.0\Application\bin\raysat3_5_6_3server.exe
O23 - Service: SPM License Server (spmd) - mental images GmbH - C:\WINDOWS\system32\spm\spmd.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

Any Ideas / Suggestions? Any one?

Come guys, no one has any clue??

We have others that have been waiting alot longer then you have.

The forum is run by volunteers who donate their time and expertise.


My best guess is this is what started causing your issues:
E:\Downloads\Win Rar + Crack.rar/Win Rar + Crack\Crack\Crack.exe

Come guys, no one has any clue??

We have others that have been waiting alot longer then you have.

The forum is run by volunteers who donate their time and expertise.


My best guess is this is what started causing your issues:
E:\Downloads\Win Rar + Crack.rar/Win Rar + Crack\Crack\Crack.exe


Oh, im sorry, I really appreciate the response. Hrmmm, I don't even seem to have that folder / file n e more. Do you think I should re-install windows?
With AVG Anti-Spyware, if you click on the Infections icon, then it will show you all the items in Quarrantine and you can remove them that way. Just click Select All then Remove Finally


I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
Hi, I followed your Directions, however when I ran ComboFix, it did its thing but when it came to preparing the LOG, it didnt do anything, i left it sit for 2 hour + and still nothing, so I assumed it stalled, the program only cuz the Desktop and everything was still fine and I could move my mouse. I didnt mouseclick at all while it was doing its thing, i didnt even touch the mouse.

I rebooted tried it again, same thing, stalling at Preparing LOG. I've tried it like 8 times, keeps on stalling at Preparing Log. Now my clock is wierd and it was suppose to fix it when its done, but its never finishing. Anyways, here is the log from HiJackThis, after running comboFix, i assume it did something because I'm guessing Preparing Log is the last process? I don't have a ComboFix Log to show, any other suggestion?


Logfile of HijackThis v1.99.1
Scan saved at 00:06, on 2007-11-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
F:\Program Files\Autodesk\mentalray\satellite\raysat_3dsmax8server.exe
C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
C:\WINDOWS\trkwksvc.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\PSIService.exe
F:\XSI_6.0\Application\bin\raysat3_5_6_3server.exe
C:\WINDOWS\system32\spm\spmd.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe
F:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ASUS\PC Probe II\Probe2.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\wuauclt.exe
F:\Program Files\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe
C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [WinampAgent] F:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Launch PC Probe II] "C:\Program Files\ASUS\PC Probe II\Probe2.exe" 1
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVFX Engine] F:\Program Files\Creative Live! Cam\VideoFX\StartFX.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [µTorrent] "C:\Program Files\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [ares] "F:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [PlayNC Launcher] C:\program files\ncsoft\launcher\NCLauncher.exe /Minimized
O4 - HKCU\..\Run: [Creative Live! Cam Manager] "F:\Program Files\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: ASUS WiFi-AP Solo.lnk = ?
O4 - Global Startup: DualCoreCenter.lnk = C:\Program Files\MSI\DualCoreCenter\StartUpDualCoreCenter.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - F:\Program Files\Autodesk\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: RaySat3_5_6_3 Server (RaySat3_5_6_3Server) - Unknown owner - F:\XSI_6.0\Application\bin\raysat3_5_6_3server.exe
O23 - Service: SPM License Server (spmd) - mental images GmbH - C:\WINDOWS\system32\spm\spmd.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: Uninterruptible Power Supply (UPS) - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
C:\WINDOWS\trkwksvc.exe

TrkWksvc.exe
Status X
Description Added by the W32.Toxbot.B WORM!

Look in C:\combofix see if combofix.txt is there. If so, post the txt file.



Lets run an F-Secure online scan it will scan for Viruses, Spyware and RootKits:
  • Click HERE
  • Scroll to the bottom of the page and click the Start scanning button. A window will pop up.
  • Allow the Active X control to be installed on your computer, then click the Accept button
  • Click Full System Scan and allow the components to download and the scan to complete.
  • If malware is found, check Submit samples to F-Secure then select Automatic cleaning
  • When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post
If Automatic cleaning with Submit samples hangs, click Cancel, then New Scan
  • When the cleaning option is presented, Uncheck Submit samples to F-Secure
  • Click Automatic cleaning
  • When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post

Note: This scan will only work with Internet Explorer.
You must be logged on a administrator rights to run this scan.
The scan may take a few hours.

Also let me know how the computer is running now.
Boss, i'm having some trouble. I can't use the F-secure because it requires the internet and the whole thing is it keeps on disconnecting, it was downloading slowly and then boom it lagged and it ended the download. Is there a way I can download the files on my Laptop then transfer it? do you know where it saves the Downloaded material? On the other note, i did find combofix.txt but this is all that it contains. Also did you want me to delete that file? C:\WINDOWS\trkwksvc.exe TrkWksvc.exe Status X Description Added by the W32.Toxbot.B WORM! CUz i see it in there. Heres the COmboFix.txt ComboFix 07-11-19.3 - Customer 2007-11-24 0:00:28.4 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1587 [GMT -5:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . —- Previous Run ——- . C:\WINDOWS\system32\pac.txt . ((((((((((((((((((((((((( Files Created from 2007-10-24 to 2007-11-24 ))))))))))))))))))))))))))))))) .
OMG! IT got to 15k out of 17k and then lagged , stalled and stopped due to connection error! Everytime i reboot the PC i get this 5-7 minutes in the beginning where the internet is fine, then it goes down so I keep restarting trying to get it to finish downloading….
ok ok, heres what happened, I got it to finish downloading and it finished scanning and found 6 Viruses and 1 Spyware and then when i clicked on Automatic Cleaning, it LAGGED and connection error……. If i reboot and do i again will I have to redownload!?
ok sorry for like a billion replies! Finally got it to work heres the lOG. Scanning Report Saturday, November 24, 2007 15:30:24 - 16:12:32 Computer name: CUSTOMER2007 Scanning type: Scan system for viruses, rootkits, spyware Target: C:\ E:\ F:\ ——————————————————————————– Result: 3 malware found Harnig.gen1 (virus) C:\DOCUMENTS AND SETTINGS\CUSTOMER\DESKTOP\APPLICATIONS\MUDBOX\CRACK\XF-MUDBOX-KG.EXE (Submitted) E:\DOWNLOADS\MUDBOX\CRACK\XF-MUDBOX-KG.EXE (Submitted) E:\DOWNLOADS\F.E.A.R\KEYGEN\KEYGEN FOR F.E.A.R.EXE (Submitted) ——————————————————————————– Statistics Scanned: Files: 51082 System: 4110 Not scanned: 3 Actions: Disinfected: 0 Renamed: 0 Deleted: 0 None: 3 Submitted: 3 Files not scanned: C:\PAGEFILE.SYS C:\WINDOWS\SYSTEM32\DRIVERS\SPTD.SYS C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT ——————————————————————————– Options Scanning engines: F-Secure Libra: 2.4.2, 2007-11-23 F-Secure AVP: 7.0.171, 2007-11-24 F-Secure Orion: 1.2.37, 2007-11-23 F-Secure Blacklight: 1.0.64 F-Secure Draco: 1.0.35, 2007-11-21 F-Secure Pegasus: 1.19.0, 2007-10-21 Scanning options: Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB BAT LNK ANI AVB CEO CMD LSP MAP MHT MIF PDF PHP POT WMF NWS TAR TGZ WSF ZL? {* ZIP JAR ARJ LZH TAR TGZ GZ CAB RAR BZ2 HQX Use Advanced heuristics ——————————————————————————– Copyright © 1998-2006 Product support |Send virus sample to F-Secure F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\DOCUMENTS AND SETTINGS\CUSTOMER\DESKTOP\APPLICATIONS\MUDBOX\CRACK\XF-MUDBOX-KG.EXE
E:\DOWNLOADS\MUDBOX\CRACK\XF-MUDBOX-KG.EXE
E:\DOWNLOADS\F.E.A.R\KEYGEN\KEYGEN FOR F.E.A.R.EXE

Folder::
E:\DOWNLOADS\F.E.A.R
C:\DOCUMENTS AND SETTINGS\CUSTOMER\DESKTOP\APPLICATIONS\MUDBOX
E:\DOWNLOADS\MUDBOX


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.
Hey Boss, ok so what happened was after the F-secure finished and deleted, My internet is BACK TO NORMAL! :D :D :D did you still wan't me to go ahead and do the combo thing?
Your a Genius! Heres the combofix log..



ComboFix 07-11-19.4 - Customer 2007-11-25 23:37:40.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1515 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix(2).exe
Command switches used :: C:\Documents and Settings\Customer\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\DOCUMENTS AND SETTINGS\CUSTOMER\DESKTOP\APPLICATIONS\MUDBOX\CRACK\XF-MUDBOX-KG.EXE
E:\DOWNLOADS\F.E.A.R\KEYGEN\KEYGEN FOR F.E.A.R.EXE
E:\DOWNLOADS\MUDBOX\CRACK\XF-MUDBOX-KG.EXE
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUMENTS AND SETTINGS\CUSTOMER\DESKTOP\APPLICATIONS\MUDBOX
C:\DOCUMENTS AND SETTINGS\CUSTOMER\DESKTOP\APPLICATIONS\MUDBOX\crack\install.txt
C:\DOCUMENTS AND SETTINGS\CUSTOMER\DESKTOP\APPLICATIONS\MUDBOX\CRACK\XF-MUDBOX-KG.EXE
C:\DOCUMENTS AND SETTINGS\CUSTOMER\DESKTOP\APPLICATIONS\MUDBOX\Mudbox1.0\Mudbox Hotkeys.txt
C:\DOCUMENTS AND SETTINGS\CUSTOMER\DESKTOP\APPLICATIONS\MUDBOX\Mudbox1.0\MudboxNetworkManager_clmd\clmd.exe
C:\DOCUMENTS AND SETTINGS\CUSTOMER\DESKTOP\APPLICATIONS\MUDBOX\Mudbox1.0\MudboxNetworkManager_clmd\clmd_start.bat
C:\DOCUMENTS AND SETTINGS\CUSTOMER\DESKTOP\APPLICATIONS\MUDBOX\Mudbox1.0\MudboxNetworkManager_clmd\config.dat
C:\DOCUMENTS AND SETTINGS\CUSTOMER\DESKTOP\APPLICATIONS\MUDBOX\Mudbox1.0\README.html
C:\DOCUMENTS AND SETTINGS\CUSTOMER\DESKTOP\APPLICATIONS\MUDBOX\Mudbox1.0\setup.exe
C:\DOCUMENTS AND SETTINGS\CUSTOMER\DESKTOP\APPLICATIONS\MUDBOX\x-force.nfo
E:\DOWNLOADS\F.E.A.R
E:\DOWNLOADS\F.E.A.R\Crack\FEAR.exe
E:\DOWNLOADS\F.E.A.R\FEAR DVD.mdf
E:\DOWNLOADS\F.E.A.R\FEAR DVD.mds
E:\DOWNLOADS\F.E.A.R\FEAR Install.nfo
E:\DOWNLOADS\F.E.A.R\KEYGEN\KEYGEN FOR F.E.A.R.EXE
E:\DOWNLOADS\MUDBOX
E:\DOWNLOADS\MUDBOX\crack\install.txt
E:\DOWNLOADS\MUDBOX\crack\xf-mudbox-kg.exe
E:\DOWNLOADS\MUDBOX\Mudbox1.0\Mudbox Hotkeys.txt
E:\DOWNLOADS\MUDBOX\Mudbox1.0\MudboxNetworkManager_clmd\clmd.exe
E:\DOWNLOADS\MUDBOX\Mudbox1.0\MudboxNetworkManager_clmd\clmd_start.bat
E:\DOWNLOADS\MUDBOX\Mudbox1.0\MudboxNetworkManager_clmd\config.dat
E:\DOWNLOADS\MUDBOX\Mudbox1.0\README.html
E:\DOWNLOADS\MUDBOX\Mudbox1.0\setup.exe
E:\DOWNLOADS\MUDBOX\x-force.nfo
I:\Autorun.inf
.
—- Previous Run ——-
.
C:\WINDOWS\system32\pac.txt

.
((((((((((((((((((((((((( Files Created from 2007-10-26 to 2007-11-26 )))))))))))))))))))))))))))))))
.

2007-11-25 20:21 d——– C:\REVIVED
2007-11-25 18:27 d——– C:\New Folder
2007-11-25 02:36 d——– C:\Documents and Settings\Customer\Application Data\Leadertech
2007-11-24 15:29 d——– C:\WINDOWS\LastGood
2007-11-19 21:35 d——– C:\Documents and Settings\Customer\Application Data\Grisoft
2007-11-19 21:35 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-19 21:35 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-09 23:00 d——– C:\Program Files\MobilEdit
2007-11-04 19:08 d——– C:\Program Files\Yuuguu
2007-11-04 18:52 d——– C:\WINDOWS\system32\URTTEMP
2007-11-04 18:51 d——– C:\Documents and Settings\All Users\Application Data\{CD64E9C4-4D54-4640-A70E-5452AC9F3290}
2007-11-04 00:51 702,464 –a—— C:\WINDOWS\ope4.exe
2007-11-04 00:47 d——– C:\WINDOWS\system32\Mz16r
2007-11-04 00:47 d——– C:\temp\mZOr
2007-11-04 00:47 702,464 –a—— C:\WINDOWS\ope3D7.exe
2007-11-04 00:47 702,464 –a—— C:\WINDOWS\cnssr.exe
2007-11-04 00:47 26,149 –a—— C:\WINDOWS\system32\wvuvvtu.dll
2007-11-04 00:37 72,192 –a—— C:\WINDOWS\system32\xxx.exe
2007-10-28 14:37 d——– C:\Documents and Settings\Customer\Application Data\Move Networks
2007-10-28 13:15 966,144 –a—— C:\WINDOWS\system32\NCTAudioInformation2.dll
2007-10-28 13:15 877,568 –a—— C:\WINDOWS\system32\NCTAudioFile2.dll
2007-10-28 13:15 467,968 –a—— C:\WINDOWS\system32\NCTAudioRecord2.dll
2007-10-28 13:15 467,456 –a—— C:\WINDOWS\system32\NCTAudioPlayer2.dll
2007-10-28 13:15 237,568 –a—— C:\WINDOWS\system32\lame_enc.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-24 20:28 ——— d—–w C:\Documents and Settings\Customer\Application Data\uTorrent
2007-11-24 20:27 ——— d—–w C:\Documents and Settings\Customer\Application Data\WTablet
2007-11-24 18:48 ——— d—–w C:\Documents and Settings\LocalService\Application Data\WTablet
2007-11-20 04:10 ——— d—–w C:\Documents and Settings\Customer\Application Data\DVDPART
2007-11-15 08:28 ——— d—–w C:\Program Files\LogMeIn
2007-11-12 23:13 ——— d—–w C:\Program Files\Common Files\Adobe
2007-11-04 05:51 352,410 —-a-w C:\WINDOWS\system32\ope5.exe
2007-11-04 05:48 ——— d—–w C:\Program Files\SNLBar
2007-11-04 05:47 352,410 —-a-w C:\WINDOWS\system32\ope3D8.exe
2007-11-03 18:27 ——— d—–w C:\Documents and Settings\Customer\Application Data\Bioshock
2007-10-25 18:12 ——— d—–w C:\Program Files\Google
2007-10-25 17:34 ——— d—–w C:\Program Files\Santiago Orgaz
2007-10-23 17:37 ——— d—–w C:\Program Files\Common Files\Autodesk Shared
2007-10-23 17:35 ——— d—–w C:\Program Files\Autodesk
2007-10-20 02:02 ——— d—–w C:\Documents and Settings\Customer\Application Data\TeamViewer
2007-10-19 21:37 ——— d—–w C:\Program Files\Creative
2007-10-19 21:36 ——— d—–w C:\Documents and Settings\Customer\Application Data\Creative
2007-10-19 21:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-08 00:37 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-10-03 05:06 114,688 —-a-w C:\WINDOWS\system32\wmatimer.dll
2007-10-03 04:58 ——— d—–w C:\Program Files\Mini-stream
2007-10-03 04:57 ——— d—–w C:\Program Files\RM Converter
2007-10-02 20:52 83,288 —-a-w C:\WINDOWS\system32\LMIRfsClientNP.dll
2007-10-02 20:52 21,496 —-a-w C:\WINDOWS\system32\LMIport.dll
2007-10-02 20:51 75,064 —-a-w C:\WINDOWS\system32\LMIinit.dll
2007-10-02 20:51 23,736 —-a-w C:\WINDOWS\system32\lmimirr.dll
2007-10-02 20:51 10,040 —-a-w C:\WINDOWS\system32\lmimirr2.dll
2007-09-28 04:26 107,888 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-09-28 04:26 ——— d–h–r C:\Documents and Settings\Customer\Application Data\SecuROM
2006-06-23 06:48 32,768 —-a-r C:\WINDOWS\inf\UpdateUSB.exe
2007-05-02 17:38 8 –sh–r C:\WINDOWS\system32\371D147DB5.sys
2007-05-02 17:38 1,056 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"µTorrent"="C:\Program Files\uTorrent\utorrent.exe" [2007-02-15 15:17]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-03-27 15:22]
"PlayNC Launcher"="C:\program files\ncsoft\launcher\NCLauncher.exe" [2007-10-31 15:38]
"Creative Live! Cam Manager"="F:\Program Files\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [2006-05-31 15:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-18 01:22]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-05-18 14:26]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidTool.exe" [2006-06-02 03:45]
"LiveMonitor"="C:\Program Files\MSI\Live Update 3\LMonitor.exe" [2007-01-17 17:01]
"WinampAgent"="F:\Program Files\Winamp\winampa.exe" [2007-02-13 13:29]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-01-22 17:22]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-12 07:00 C:\WINDOWS\system32\rundll32.exe]
"Launch PC Probe II"="C:\Program Files\ASUS\PC Probe II\Probe2.exe" [2002-01-04 23:53]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 16:40]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 08:41]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 02:23]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-08-18 20:58]
"AVFX Engine"="F:\Program Files\Creative Live! Cam\VideoFX\StartFX.exe" [2006-06-09 00:11]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2007-01-08 19:00 C:\WINDOWS\system32\advpack.dll]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ASUS WiFi-AP Solo.lnk - C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe [2007-04-11 09:37:57]
DualCoreCenter.lnk - C:\Program Files\MSI\DualCoreCenter\StartUpDualCoreCenter.exe [2007-04-11 10:43:10]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
"DisableStatusMessages"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoRecentDocsMenu"= 1 (0x1)
"NoRecentDocsHistory"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoRecentDocsMenu"= 1 (0x1)
"NoRecentDocsHistory"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

R2 LMIInfo;LogMeIn Kernel Information Provider;\??\C:\Program Files\LogMeIn\x86\RaInfo.sys
R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
R2 RaySat3_5_6_3Server;RaySat3_5_6_3 Server;F:\XSI_6.0\Application\bin\raysat3_5_6_3server.exe
R3 DigiCellDriver;DigiCellDriver;\??\C:\Program Files\MSI\DualCoreCenter\NTGLM7X.sys
R3 lmimirr;lmimirr;C:\WINDOWS\system32\DRIVERS\lmimirr.sys
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys
S2 NET Service;NET Service;"C:\WINDOWS\trkwksvc.exe"
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys
S3 SjyPkt;SjyPkt;\??\C:\WINDOWS\System32\Drivers\SjyPkt.sys
S3 V0220Dev;Live! Cam Video IM;C:\WINDOWS\system32\DRIVERS\V0220Dev.sys
S3 V0220Vfx;V0220VFX;C:\WINDOWS\system32\DRIVERS\V0220Vfx.sys
S3 XIRLINK;IBM PC Camera;C:\WINDOWS\system32\DRIVERS\C-itnt.sys
S4 WEBNTACCESS;WEBNTACCESS;\??\C:\WINDOWS\system32\NTACCESS.SYS

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService WebClient LmHosts upnphost SSDPSRV

*Newly Created Service* - F-SECURE_STANDALONE_MINIFILTER
*Newly Created Service* - WEBNTACCESS
.
Contents of the 'Scheduled Tasks' folder
"2007-11-21 11:24:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-25 23:41:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-25 23:42:12
.
— E O F —

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI