This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virus Help!

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there,

Any help that you could give would be much appreciated! I originally got the savetheinformation virus and being an idiot looked at other peoples problems and tried to fix it myself… unfortunatley this hasnt worked properly! I have managed to get rid of the blinking yellow symbol on the bottom right of my sccreen, however I still get pop ups regularly and my internet is slow and keeps crashing. My virus scanner keeps finding multiple virus now and although t says successfully removed, it actually doent get rid of them! Any help would be greatly appreciated, ill post my HiJack This log here:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:30:40, on 20/11/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\2z7q47r.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\runservice.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\3ivx\3ivx MPEG-4 5.0\3ivxRegister.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\HJT\scanner.exe.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qgb9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qgb9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: {d11b85f3-09e8-05eb-ec34-e1d8c5853b72} - {27b3585c-8d1e-43ce-be50-8e903f58b11d} - C:\WINDOWS\System32\ffaplfst.dll
O2 - BHO: SysApp - {4AE2A9A0-DC33-4C27-B521-5B6C68C1C53D} - C:\Program Files\ApplePie\ie-improver.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [2z7q47r] C:\WINDOWS\system32\2z7q47r.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [148a4c1c] rundll32.exe "C:\WINDOWS\System32\qwostuyb.dll",b
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [2z7q47r] C:\WINDOWS\system32\2z7q47r.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [eyeBeam SIP Client] "C:\Program Files\BT Broadband Talk Softphone\BTSoftphone.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - S-1-5-18 Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: OpenMG Jukebox Startup.lnk = C:\Program Files\Sony\OpenMG Jukebox\Omgtray.exe
O4 - Global Startup: StartupFaster
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: BT - {22787B8A-8D5C-45C1-9D4E-72AFE4079DC2} - http://www.bt.com (file missing) (HKCU)
O9 - Extra button: Homepage - {387D1F8D-3AEE-4135-83F8-7DEE02831182} - http://www.btopenworld.com/default (file missing) (HKCU)
O9 - Extra button: Help - {8B24DF65-DADB-48C6-82BC-FDE76718D060} - http://www.btopenworld.com/helpbb (file missing) (HKCU)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O21 - SSODL: VStorage - {548031A7-EF90-4B62-8100-AABD71CE61F4} - swmclip.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: Windows Installer MSIServerwinmgmt (MSIServerwinmgmt) - Unknown owner - C:\WINDOWS\System32\adsldpp.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Task Scheduler ScheduleShellHWDetection (ScheduleShellHWDetection) - Unknown owner - C:\WINDOWS\System32\adsldpl.exe (file missing)
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: YPCService - Unknown owner - C:\WINDOWS\system32\YPCSER~1.EXE (file missing)

–
End of file - 9158 bytes
Hello and welcome to the Forum

I don't see any anti-virus program running on your system. Do you have one?


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Next:

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: [external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
Hi LDTate, Firstly thanks a lot for looking at this for me, it is much appreciated! Regarding the virus scanner, I do have one on normally, howver I disabled it to speed up the scan for HiJack This… I couldnt find the icon you mentioned, however I think I managed to move the incurable by right clicking on them! I followed all the steps you mentioned, however my Dr Web log is so big that when I try to copy and paste it the IE just crash's. I was going to upload it as an attahment, however I'm not authorised to do so… What shall I do?
I can do that but it will result in many posts as I tried to post about 1/8th of it here and it said that the post was too long… it would be eaier to send the notepad file to you! If you want me to wade through like that I will do though!
Okey dokey! Everything mentioned above has been done, minus the log! Heres the latest HiJack This log….

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:14:08, on 21/11/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\runservice.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\3ivx\3ivx MPEG-4 5.0\3ivxRegister.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\HJT\scanner.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qgb9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qgb9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: {d11b85f3-09e8-05eb-ec34-e1d8c5853b72} - {27b3585c-8d1e-43ce-be50-8e903f58b11d} - C:\WINDOWS\System32\ffaplfst.dll
O2 - BHO: SysApp - {4AE2A9A0-DC33-4C27-B521-5B6C68C1C53D} - C:\Program Files\ApplePie\ie-improver.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [148a4c1c] rundll32.exe "C:\WINDOWS\System32\qwostuyb.dll",b
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [eyeBeam SIP Client] "C:\Program Files\BT Broadband Talk Softphone\BTSoftphone.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - S-1-5-18 Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: OpenMG Jukebox Startup.lnk = C:\Program Files\Sony\OpenMG Jukebox\Omgtray.exe
O4 - Global Startup: StartupFaster
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: BT - {22787B8A-8D5C-45C1-9D4E-72AFE4079DC2} - http://www.bt.com (file missing) (HKCU)
O9 - Extra button: Homepage - {387D1F8D-3AEE-4135-83F8-7DEE02831182} - http://www.btopenworld.com/default (file missing) (HKCU)
O9 - Extra button: Help - {8B24DF65-DADB-48C6-82BC-FDE76718D060} - http://www.btopenworld.com/helpbb (file missing) (HKCU)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: Windows Installer MSIServerwinmgmt (MSIServerwinmgmt) - Unknown owner - C:\WINDOWS\System32\adsldpp.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Task Scheduler ScheduleShellHWDetection (ScheduleShellHWDetection) - Unknown owner - C:\WINDOWS\System32\adsldpl.exe (file missing)
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: YPCService - Unknown owner - C:\WINDOWS\system32\YPCSER~1.EXE (file missing)

–
End of file - 8583 bytes
Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
ComboFix 07-11-19.3 - Owner 2007-11-23 14:25:45.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.193 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\cookies.ini

.
((((((((((((((((((((((((( Files Created from 2007-10-23 to 2007-11-23 )))))))))))))))))))))))))))))))
.

2007-11-22 18:00 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2007-11-21 14:45 d——– C:\Documents and Settings\Owner.JOSH\DoctorWeb
2007-11-12 19:56 d——– C:\The_Killers-Sawdust-2007-404
2007-11-07 00:42 d——– C:\Program Files\HJT
2007-11-07 00:30 d——– C:\VundoFix Backups
2007-11-06 13:33 81,472 –a—— C:\WINDOWS\system32\ffaplfst.dll
2007-11-06 13:27 1,723,989 —hs—- C:\WINDOWS\system32\byutsowq.ini
2007-11-06 13:27 87,104 –a—— C:\WINDOWS\system32\qwostuyb.dll
2007-11-04 20:58 d–h—– C:\Program Files\ApplePie
2007-10-30 14:15 d——– C:\The Wombats

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-22 18:03 ——— d—–w C:\Program Files\Winamp
2007-11-21 15:36 ——— d—–w C:\Program Files\BTopenworld
2007-11-18 00:41 ——— d—–w C:\Documents and Settings\Owner.JOSH\Application Data\BitTorrent
2007-11-17 01:27 ——— d—–w C:\Program Files\Spyware Doctor
2007-11-07 00:42 401,720 —-a-w C:\HiJackThis.exe
2007-10-18 00:29 ——— d—–w C:\Program Files\All Sound Recorder XP 210
2007-10-10 23:24 ——— d—–w C:\Program Files\BitTorrent
2007-09-29 21:06 124,416 —-a-w C:\WINDOWS\system32\rgzwpegk.dll
2007-07-10 23:18 92,064 —-a-w C:\Documents and Settings\Owner.JOSH\mqdmmdm.sys
2007-07-10 23:18 9,232 —-a-w C:\Documents and Settings\Owner.JOSH\mqdmmdfl.sys
2007-07-10 23:18 79,328 —-a-w C:\Documents and Settings\Owner.JOSH\mqdmserd.sys
2007-07-10 23:18 66,656 —-a-w C:\Documents and Settings\Owner.JOSH\mqdmbus.sys
2007-07-10 23:18 6,208 —-a-w C:\Documents and Settings\Owner.JOSH\mqdmcmnt.sys
2007-07-10 23:18 5,936 —-a-w C:\Documents and Settings\Owner.JOSH\mqdmwhnt.sys
2007-07-10 23:18 4,048 —-a-w C:\Documents and Settings\Owner.JOSH\mqdmcr.sys
2007-07-10 23:18 25,600 -c–a-w C:\Documents and Settings\Owner.JOSH\usbsermptxp.sys
2007-07-10 23:18 22,768 -c–a-w C:\Documents and Settings\Owner.JOSH\usbsermpt.sys
2003-12-07 17:12 1,617 -c–a-w C:\Program Files\INSTALL.LOG
2007-06-25 11:23 109 –sha-w C:\WINDOWS\system32\344607923.dat
2006-06-06 06:33 593 -csha-w C:\WINDOWS\system32\mmf(2)(2).sys
.

((((((((((((((((((((((((((((( snapshot@2007-11-07_ 1.11.45.03 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-10-29 18:56:19 136,192 —-a-w C:\WINDOWS\catchme.exe
+ 2007-11-08 16:59:01 136,704 —-a-w C:\WINDOWS\catchme.exe
- 2007-11-07 01:09:59 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-11-22 22:52:01 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-11-07 01:09:59 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-11-22 22:52:01 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-11-07 01:09:59 65,536 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-11-22 22:52:01 65,536 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-11-07 01:02:01 262,144 —-a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
+ 2007-11-23 14:25:42 262,144 —-a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
- 2006-05-16 20:23:54 46,080 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
+ 2007-03-07 23:51:00 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
- 2007-10-29 09:07:04 53,552 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-11-11 19:59:49 53,552 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2007-10-29 09:07:04 382,000 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-11-11 19:59:49 382,000 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2006-05-16 20:23:54 430,080 ——w C:\WINDOWS\system32\px.dll
+ 2007-03-07 23:51:00 547,576 ——w C:\WINDOWS\system32\px.dll
- 2006-05-16 20:23:54 57,344 -c—-w C:\WINDOWS\system32\pxcpya64.exe
+ 2007-03-07 23:51:00 64,760 -c—-w C:\WINDOWS\system32\pxcpya64.exe
- 2006-05-16 20:23:54 450,560 -c—-w C:\WINDOWS\system32\pxdrv.dll
+ 2007-03-07 23:51:00 510,712 -c—-w C:\WINDOWS\system32\pxdrv.dll
- 2006-05-16 20:23:54 61,440 -c—-w C:\WINDOWS\system32\pxhpinst.exe
+ 2007-03-07 23:51:00 72,440 -c—-w C:\WINDOWS\system32\pxhpinst.exe
- 2006-05-16 20:23:54 56,832 -c—-w C:\WINDOWS\system32\pxinsa64.exe
+ 2007-03-07 23:51:00 64,760 -c—-w C:\WINDOWS\system32\pxinsa64.exe
- 2006-05-16 20:23:54 176,128 ——w C:\WINDOWS\system32\pxmas.dll
+ 2007-03-07 23:51:00 187,128 ——w C:\WINDOWS\system32\pxmas.dll
- 2006-05-16 20:23:54 1,257,472 -c—-w C:\WINDOWS\system32\pxsfs.dll
+ 2007-03-07 23:51:00 1,628,920 -c—-w C:\WINDOWS\system32\pxsfs.dll
- 2006-05-16 20:23:56 339,968 ——w C:\WINDOWS\system32\pxwave.dll
+ 2007-03-07 23:51:00 379,640 ——w C:\WINDOWS\system32\pxwave.dll
- 2006-05-16 20:23:56 28,672 -c—-w C:\WINDOWS\system32\VXBLOCK.dll
+ 2007-03-07 23:51:00 39,672 -c—-w C:\WINDOWS\system32\VXBLOCK.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 61,440 2003-02-12 03:02:48 C:\hp\KBD\bak\KBD.EXE

—-a-w 43,008 2007-01-12 06:35:02 C:\Program Files\BitTorrent\bak\bittorrent.exe
—-a-w 43,008 2007-09-07 23:01:54 C:\Program Files\BitTorrent\bittorrent.exe

—-a-w 180,269 2006-05-06 15:56:22 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe

—-a-w 155,648 2003-02-13 15:01:00 C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe

—-a-w 229,952 2006-09-25 14:54:24 C:\Program Files\iTunes\bak\iTunesHelper.exe
—-a-w 229,952 2006-09-25 13:54:24 C:\Program Files\iTunes\iTunesHelper.exe

—-a-w 1,104,896 2006-03-31 15:58:32 C:\Program Files\Oxigen\bin\bak\OxiPanel.exe

—-a-w 460,288 2005-08-23 14:52:30 C:\Program Files\Oxigen\bin\bak\OxiTray.exe

—-a-w 282,624 2006-09-24 03:24:54 C:\Program Files\QuickTime\bak\qttask.exe

—-a-w 208,953 2003-01-22 09:13:00 C:\WINDOWS\ime\imjp8_1\bak\IMJPMIG.EXE
—-a-w 208,953 2003-01-22 09:13:00 C:\WINDOWS\ime\imjp8_1\imjpmig.exe

—-a-w 212,992 2002-09-14 04:42:26 C:\WINDOWS\SMINST\bak\RECGUARD.EXE

—-a-w 52,736 1998-05-07 23:04:38 C:\WINDOWS\system\bak\hpsysdrv.exe

—-a-w 114,688 2003-04-07 14:07:38 C:\WINDOWS\system32\bak\hkcmd.exe

—-a-w 81,920 2002-08-01 03:28:38 C:\WINDOWS\system32\bak\ps2.exe

—-a-w 59,392 2003-01-21 06:59:00 C:\WINDOWS\system32\IME\PINTLGNT\bak\ImScInst.exe
—-a-w 59,392 2003-01-21 06:59:00 C:\WINDOWS\system32\IME\PINTLGNT\imscinst.exe

—-a-w 455,168 2003-01-21 07:18:00 C:\WINDOWS\system32\IME\TINTLGNT\bak\TINTSETP.EXE
—-a-w 455,168 2003-01-21 07:18:00 C:\WINDOWS\system32\IME\TINTLGNT\tintsetp.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{27b3585c-8d1e-43ce-be50-8e903f58b11d}]
2007-11-06 13:33 81472 –a—— C:\WINDOWS\System32\ffaplfst.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4AE2A9A0-DC33-4C27-B521-5B6C68C1C53D}]
2007-11-04 20:58 95232 –a—— C:\Program Files\ApplePie\ie-improver.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIEW"="nview.dll" [2003-05-03 06:19 C:\WINDOWS\system32\nview.dll]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-09-07 23:01]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" []
"eyeBeam SIP Client"="C:\Program Files\BT Broadband Talk Softphone\BTSoftphone.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="C:\WINDOWS\system32\Macromed\SHOCKW~1\SWHELP~1.exe" [2007-05-02 11:31]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2003-01-22 09:13]
"MSPY2002"="C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe" [2003-01-21 06:59]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-01-21 07:18]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-01-21 07:18]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" []
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" []
"VTTimer"="VTTimer.exe" [2003-05-08 07:32 C:\WINDOWS\system32\VTTimer.exe]
"NvCplDaemon"="RUNDLL32.exe" [2003-01-20 17:42 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2003-05-03 06:19 C:\WINDOWS\system32\nwiz.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-04 03:35 C:\WINDOWS\ALCXMNTR.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 02:43]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-09-25 13:54]
"Motive SmartBridge"="C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe" []
"btbb_wcm_McciTrayApp"="C:\Program Files\btbb_wcm\McciTrayApp.exe" []
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" []
"148a4c1c"="C:\WINDOWS\System32\qwostuyb.dll" [2007-11-06 13:27]

C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
mod_sm.lnk - C:\hp\bin\cloaker.exe [1999-11-07 14:11:14]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
OpenMG Jukebox Startup.lnk - C:\Program Files\Sony\OpenMG Jukebox\Omgtray.exe [2006-03-19 22:04:53]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

R2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe
S2 MSIServerwinmgmt;Windows Installer MSIServerwinmgmt;C:\WINDOWS\System32\adsldpp.exe srv
S2 ScheduleShellHWDetection;Task Scheduler ScheduleShellHWDetection;C:\WINDOWS\System32\adsldpl.exe srv
S3 usbsermptxp;Motorola USB Modem Driver for MPT XP;C:\WINDOWS\System32\DRIVERS\usbsermptxp.sys

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
vicvggza

.
Contents of the 'Scheduled Tasks' folder
"2007-11-22 22:52:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-23 14:30:19
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-23 14:31:22
C:\ComboFix2.txt … 2007-11-19 17:26
C:\ComboFix3.txt … 2007-11-07 01:15
.
— E O F —

HiJack This log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:54:26, on 23/11/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\runservice.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\3ivx\3ivx MPEG-4 5.0\3ivxRegister.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HJT\scanner.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qgb9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qgb9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: {d11b85f3-09e8-05eb-ec34-e1d8c5853b72} - {27b3585c-8d1e-43ce-be50-8e903f58b11d} - C:\WINDOWS\System32\ffaplfst.dll
O2 - BHO: SysApp - {4AE2A9A0-DC33-4C27-B521-5B6C68C1C53D} - C:\Program Files\ApplePie\ie-improver.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [148a4c1c] rundll32.exe "C:\WINDOWS\System32\qwostuyb.dll",b
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [eyeBeam SIP Client] "C:\Program Files\BT Broadband Talk Softphone\BTSoftphone.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - S-1-5-18 Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: OpenMG Jukebox Startup.lnk = C:\Program Files\Sony\OpenMG Jukebox\Omgtray.exe
O4 - Global Startup: StartupFaster
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: BT - {22787B8A-8D5C-45C1-9D4E-72AFE4079DC2} - http://www.bt.com (file missing) (HKCU)
O9 - Extra button: Homepage - {387D1F8D-3AEE-4135-83F8-7DEE02831182} - http://www.btopenworld.com/default (file missing) (HKCU)
O9 - Extra button: Help - {8B24DF65-DADB-48C6-82BC-FDE76718D060} - http://www.btopenworld.com/helpbb (file missing) (HKCU)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: Windows Installer MSIServerwinmgmt (MSIServerwinmgmt) - Unknown owner - C:\WINDOWS\System32\adsldpp.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Task Scheduler ScheduleShellHWDetection (ScheduleShellHWDetection) - Unknown owner - C:\WINDOWS\System32\adsldpl.exe (file missing)
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: YPCService - Unknown owner - C:\WINDOWS\system32\YPCSER~1.EXE (file missing)

–
End of file - 8611 bytes
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\ffaplfst.dll
C:\WINDOWS\system32\byutsowq.ini
C:\WINDOWS\system32\qwostuyb.dll
C:\Program Files\ApplePie\ie-improver.dll
C:\WINDOWS\ALCXMNTR.EXE

Folder::
C:\VundoFix Backups
C:\Program Files\ApplePie

Netsvcs::
vicvggza

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{27b3585c-8d1e-43ce-be50-8e903f58b11d}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4AE2A9A0-DC33-4C27-B521-5B6C68C1C53D}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"=-
"148a4c1c"=-


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.
ComboFix 07-11-19.3 - Owner 2007-11-23 17:09:03.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.196 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner.JOSH\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\Program Files\ApplePie\ie-improver.dll
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\byutsowq.ini
C:\WINDOWS\system32\ffaplfst.dll
C:\WINDOWS\system32\qwostuyb.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\ApplePie
C:\Program Files\ApplePie\bho.dat
C:\Program Files\ApplePie\er.dat
C:\Program Files\ApplePie\ie-improver.dll
C:\Program Files\ApplePie\uninstall.exe
C:\VundoFix Backups
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\byutsowq.ini
C:\WINDOWS\system32\ffaplfst.dll
C:\WINDOWS\system32\qwostuyb.dll

.
((((((((((((((((((((((((( Files Created from 2007-10-23 to 2007-11-23 )))))))))))))))))))))))))))))))
.

2007-11-22 18:00 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2007-11-21 14:45 d——– C:\Documents and Settings\Owner.JOSH\DoctorWeb
2007-11-12 19:56 d——– C:\The_Killers-Sawdust-2007-404
2007-11-07 00:42 d——– C:\Program Files\HJT
2007-10-30 14:15 d——– C:\The Wombats

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-22 18:03 ——— d—–w C:\Program Files\Winamp
2007-11-21 15:36 ——— d—–w C:\Program Files\BTopenworld
2007-11-18 00:41 ——— d—–w C:\Documents and Settings\Owner.JOSH\Application Data\BitTorrent
2007-11-17 01:27 ——— d—–w C:\Program Files\Spyware Doctor
2007-11-07 00:42 401,720 —-a-w C:\HiJackThis.exe
2007-10-18 00:29 ——— d—–w C:\Program Files\All Sound Recorder XP 210
2007-10-10 23:24 ——— d—–w C:\Program Files\BitTorrent
2007-07-10 23:18 92,064 —-a-w C:\Documents and Settings\Owner.JOSH\mqdmmdm.sys
2007-07-10 23:18 9,232 —-a-w C:\Documents and Settings\Owner.JOSH\mqdmmdfl.sys
2007-07-10 23:18 79,328 —-a-w C:\Documents and Settings\Owner.JOSH\mqdmserd.sys
2007-07-10 23:18 66,656 —-a-w C:\Documents and Settings\Owner.JOSH\mqdmbus.sys
2007-07-10 23:18 6,208 —-a-w C:\Documents and Settings\Owner.JOSH\mqdmcmnt.sys
2007-07-10 23:18 5,936 —-a-w C:\Documents and Settings\Owner.JOSH\mqdmwhnt.sys
2007-07-10 23:18 4,048 —-a-w C:\Documents and Settings\Owner.JOSH\mqdmcr.sys
2007-07-10 23:18 25,600 -c–a-w C:\Documents and Settings\Owner.JOSH\usbsermptxp.sys
2007-07-10 23:18 22,768 -c–a-w C:\Documents and Settings\Owner.JOSH\usbsermpt.sys
2003-12-07 17:12 1,617 -c–a-w C:\Program Files\INSTALL.LOG
2007-06-25 11:23 109 –sha-w C:\WINDOWS\system32\344607923.dat
2006-06-06 06:33 593 -csha-w C:\WINDOWS\system32\mmf(2)(2).sys
.

((((((((((((((((((((((((((((( snapshot_2007-11-23_14.30.23.15 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-22 22:52:01 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-11-23 17:14:36 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-11-22 22:52:01 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-11-23 17:14:36 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-11-22 22:52:01 65,536 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-11-23 17:14:36 65,536 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 61,440 2003-02-12 03:02:48 C:\hp\KBD\bak\KBD.EXE

—-a-w 43,008 2007-01-12 06:35:02 C:\Program Files\BitTorrent\bak\bittorrent.exe
—-a-w 43,008 2007-09-07 23:01:54 C:\Program Files\BitTorrent\bittorrent.exe

—-a-w 180,269 2006-05-06 15:56:22 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe

—-a-w 155,648 2003-02-13 15:01:00 C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe

—-a-w 229,952 2006-09-25 14:54:24 C:\Program Files\iTunes\bak\iTunesHelper.exe
—-a-w 229,952 2006-09-25 13:54:24 C:\Program Files\iTunes\iTunesHelper.exe

—-a-w 1,104,896 2006-03-31 15:58:32 C:\Program Files\Oxigen\bin\bak\OxiPanel.exe

—-a-w 460,288 2005-08-23 14:52:30 C:\Program Files\Oxigen\bin\bak\OxiTray.exe

—-a-w 282,624 2006-09-24 03:24:54 C:\Program Files\QuickTime\bak\qttask.exe

—-a-w 208,953 2003-01-22 09:13:00 C:\WINDOWS\ime\imjp8_1\bak\IMJPMIG.EXE
—-a-w 208,953 2003-01-22 09:13:00 C:\WINDOWS\ime\imjp8_1\imjpmig.exe

—-a-w 212,992 2002-09-14 04:42:26 C:\WINDOWS\SMINST\bak\RECGUARD.EXE

—-a-w 52,736 1998-05-07 23:04:38 C:\WINDOWS\system\bak\hpsysdrv.exe

—-a-w 114,688 2003-04-07 14:07:38 C:\WINDOWS\system32\bak\hkcmd.exe

—-a-w 81,920 2002-08-01 03:28:38 C:\WINDOWS\system32\bak\ps2.exe

—-a-w 59,392 2003-01-21 06:59:00 C:\WINDOWS\system32\IME\PINTLGNT\bak\ImScInst.exe
—-a-w 59,392 2003-01-21 06:59:00 C:\WINDOWS\system32\IME\PINTLGNT\imscinst.exe

—-a-w 455,168 2003-01-21 07:18:00 C:\WINDOWS\system32\IME\TINTLGNT\bak\TINTSETP.EXE
—-a-w 455,168 2003-01-21 07:18:00 C:\WINDOWS\system32\IME\TINTLGNT\tintsetp.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIEW"="nview.dll" [2003-05-03 06:19 C:\WINDOWS\system32\nview.dll]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-09-07 23:01]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" []
"eyeBeam SIP Client"="C:\Program Files\BT Broadband Talk Softphone\BTSoftphone.exe" []

C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
mod_sm.lnk - C:\hp\bin\cloaker.exe [1999-11-07 14:11:14]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
OpenMG Jukebox Startup.lnk - C:\Program Files\Sony\OpenMG Jukebox\Omgtray.exe [2006-03-19 22:04:53]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

R2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe
S2 MSIServerwinmgmt;Windows Installer MSIServerwinmgmt;C:\WINDOWS\System32\adsldpp.exe srv
S2 ScheduleShellHWDetection;Task Scheduler ScheduleShellHWDetection;C:\WINDOWS\System32\adsldpl.exe srv
S3 usbsermptxp;Motorola USB Modem Driver for MPT XP;C:\WINDOWS\System32\DRIVERS\usbsermptxp.sys

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
vicvggza

.
Contents of the 'Scheduled Tasks' folder
"2007-11-22 22:52:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-23 17:33:35
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-23 17:38:09 - machine was rebooted
C:\ComboFix2.txt … 2007-11-23 14:31
C:\ComboFix3.txt … 2007-11-19 17:26
.
— E O F —


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:40:17, on 23/11/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\runservice.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\HJT\scanner.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qgb9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qgb9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [eyeBeam SIP Client] "C:\Program Files\BT Broadband Talk Softphone\BTSoftphone.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - S-1-5-18 Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: OpenMG Jukebox Startup.lnk = C:\Program Files\Sony\OpenMG Jukebox\Omgtray.exe
O4 - Global Startup: StartupFaster
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: BT - {22787B8A-8D5C-45C1-9D4E-72AFE4079DC2} - http://www.bt.com (file missing) (HKCU)
O9 - Extra button: Homepage - {387D1F8D-3AEE-4135-83F8-7DEE02831182} - http://www.btopenworld.com/default (file missing) (HKCU)
O9 - Extra button: Help - {8B24DF65-DADB-48C6-82BC-FDE76718D060} - http://www.btopenworld.com/helpbb (file missing) (HKCU)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: Windows Installer MSIServerwinmgmt (MSIServerwinmgmt) - Unknown owner - C:\WINDOWS\System32\adsldpp.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Task Scheduler ScheduleShellHWDetection (ScheduleShellHWDetection) - Unknown owner - C:\WINDOWS\System32\adsldpl.exe (file missing)
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: YPCService - Unknown owner - C:\WINDOWS\system32\YPCSER~1.EXE (file missing)

–
End of file - 6892 bytes
Please click HERE select Save. Save FindAWF to your desktop.

Double Click FindAWF.exe and let it run, it will create the file awf.txt on your desktop when finished.

Open awf.txt in notepad, select Edit> Select All> Edit> Copy> and Paste the contents.
Find AWF report by noahdfear ©2006 Version 1.40 The current date is: 23/11/2007 The current time is: 18:56:23.00 bak folders found ~~~~~~~~~~~ Directory of C:\HP\KBD\BAK 12/02/2003 03:02 61,440 KBD.EXE 1 File(s) 61,440 bytes Directory of C:\PROGRA~1\BITTOR~1\BAK 12/01/2007 06:35 43,008 bittorrent.exe 1 File(s) 43,008 bytes Directory of C:\PROGRA~1\ITUNES\BAK 25/09/2006 14:54 229,952 iTunesHelper.exe 1 File(s) 229,952 bytes Directory of C:\PROGRA~1\MSNMES~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 24/09/2006 03:24 282,624 qttask.exe 1 File(s) 282,624 bytes Directory of C:\WINDOWS\SMINST\BAK 14/09/2002 04:42 212,992 RECGUARD.EXE 1 File(s) 212,992 bytes Directory of C:\WINDOWS\SYSTEM\BAK 07/05/1998 23:04 52,736 hpsysdrv.exe 1 File(s) 52,736 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 07/04/2003 14:07 114,688 hkcmd.exe 01/08/2002 03:28 81,920 ps2.exe 2 File(s) 196,608 bytes Directory of C:\PROGRA~1\OXIGEN\BIN\BAK 31/03/2006 15:58 1,104,896 OxiPanel.exe 23/08/2005 14:52 460,288 OxiTray.exe 2 File(s) 1,565,184 bytes Directory of C:\WINDOWS\IME\IMJP8_1\BAK 22/01/2003 09:13 208,953 IMJPMIG.EXE 1 File(s) 208,953 bytes Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK 06/05/2006 15:56 180,269 realsched.exe 1 File(s) 180,269 bytes Directory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK 13/02/2003 15:01 155,648 sgtray.exe 1 File(s) 155,648 bytes Directory of C:\WINDOWS\SYSTEM32\IME\PINTLGNT\BAK 21/01/2003 06:59 59,392 ImScInst.exe 1 File(s) 59,392 bytes Directory of C:\WINDOWS\SYSTEM32\IME\TINTLGNT\BAK 21/01/2003 07:18 455,168 TINTSETP.EXE 1 File(s) 455,168 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 61440 12 Feb 2003 "C:\hp\KBD\bak\KBD.EXE" 43008 7 Sep 2007 "C:\Program Files\BitTorrent\bittorrent.exe" 43008 12 Jan 2007 "C:\Program Files\BitTorrent\bak\bittorrent.exe" 229952 25 Sep 2006 "C:\Program Files\iTunes\iTunesHelper.exe" 196608 22 Jun 2004 "C:\Program Files\iTunes Art Importer\iTunesArtImport.exe" 229952 25 Sep 2006 "C:\Program Files\iTunes\bak\iTunesHelper.exe" 102400 7 May 2007 "C:\WINDOWS\Installer\{5878FF02-3B8F-4309-B4E5-0D3DB6F2E8E6}\iTunesIco.exe" 108096 25 Sep 2006 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.0.1.8\iTunesSetupAdmin.exe" 282624 24 Sep 2006 "C:\Program Files\QuickTime\bak\qttask.exe" 212992 14 Sep 2002 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE" 52736 7 May 1998 "C:\WINDOWS\system\bak\hpsysdrv.exe" 114688 7 Apr 2003 "C:\WINDOWS\system32\bak\hkcmd.exe" 114688 7 Apr 2003 "C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\hkcmd.exe" 81920 1 Aug 2002 "C:\hp\drivers\keyboard\PS2.EXE" 81920 1 Aug 2002 "C:\WINDOWS\system32\bak\ps2.exe" 1104896 31 Mar 2006 "C:\Program Files\Oxigen\bin\bak\OxiPanel.exe" 460288 23 Aug 2005 "C:\Program Files\Oxigen\bin\bak\OxiTray.exe" 208953 22 Jan 2003 "C:\WINDOWS\ime\imjp8_1\imjpmig.exe" 208953 22 Jan 2003 "C:\WINDOWS\ime\imjp8_1\bak\IMJPMIG.EXE" 180269 6 May 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 155648 13 Feb 2003 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe" 59392 21 Jan 2003 "C:\WINDOWS\system32\IME\PINTLGNT\imscinst.exe" 59392 21 Jan 2003 "C:\WINDOWS\system32\IME\PINTLGNT\bak\ImScInst.exe" 455168 21 Jan 2003 "C:\WINDOWS\system32\IME\TINTLGNT\tintsetp.exe" 455168 21 Jan 2003 "C:\WINDOWS\system32\IME\TINTLGNT\bak\TINTSETP.EXE" end of report
Double-click FindAWF.exe to start the tool. Then, do the following
Select "option #2 - Restore files from bak folders" by typing 2 and press Enter .
A text file will open up. Please copy/paste the following text from the quote box (all except the word QUOTE) into the text file.

"C:\hp\KBD\bak\KBD.EXE"
"C:\Program Files\BitTorrent\bak\bittorrent.exe"
"C:\Program Files\iTunes\bak\iTunesHelper.exe"
"C:\Program Files\QuickTime\bak\qttask.exe"
"C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
"C:\WINDOWS\system\bak\hpsysdrv.exe"
"C:\WINDOWS\system32\bak\hkcmd.exe"
"C:\WINDOWS\system32\bak\ps2.exe"
"C:\Program Files\Oxigen\bin\bak\OxiPanel.exe"
"C:\Program Files\Oxigen\bin\bak\OxiTray.exe"
"C:\WINDOWS\ime\imjp8_1\bak\IMJPMIG.EXE"
"C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
"C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe"
"C:\WINDOWS\system32\IME\PINTLGNT\bak\ImScInst.exe"
"C:\WINDOWS\system32\IME\TINTLGNT\bak\TINTSETP.EXE"



Close the .txt file and click Yes to save the changes.
When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt in your next reply as an attachment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI