This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] security toolbar7.1 virus

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ok i am still trying to get the kaspersky scanner to work. i have combined the file into combofix. i have noticed however that the toolbar itself had gone down to just one toolbar and now it has almost completely disappeared. Only the "sec" of it is still visable.
i am sorry, i missed that message. I was trying to click on the scan now icon for kaspersky.it ill not bring it up,and now, it seems that i cannot get the keys to work. i try and try to type but it will notork. Also, I am not getting any error messages. It is just simply NOT working
ok, i am up to date on everything except for the kaspersky scan. i try and try to get it to work, clicking on the icon over and over but it doesnt ever bring it up. i have noticed that anything else that i click on works except for that. even my keys are working fine when i type. i am very careful as to not spill anything around the computer, so it is not sticking. i dont know what to think about this. do you have any clue as to why it is not working? also, how late are you available to work on this?
Hi :) I'm usually on line until 11 P.M. (GMT +1). Please leave the Kaspersky scan for now, I think there are more important things to deal with first. Post the logs you currently have (do you have the Virustotal/Jotti results?): the Combofix log and a new HijackThis log are the most important ones.
hi ,
i think is is the jotti results, and here are the combofix and hijack results. if somthing is not complete or was wrong, just let me know waht to do and i will send you the correct ones.
=============================================
Statistics
Last file scanned at least one scanner reported something about: pinch3.exe (MD5: fcd6e93cb706163dfdcd301a22c0d9d1, size: 54168 bytes), detected by:

Scanner Malware name
A-Squared X
AntiVir HEUR/Crypted
ArcaVir X
Avast Win32:LdPinch-CT
AVG Antivirus X
BitDefender MemScan:Trojan.PWS.LdPinch.BSJ
ClamAV X
CPsecure X
Dr.Web X
F-Prot Antivirus W32/Trojan.AFTI
F-Secure Anti-Virus Trojan-PSW.Win32.LdPinch.dsr
Fortinet X
Ikarus Suspect code-parts
Kaspersky Anti-Virus Trojan-PSW.Win32.LdPinch.dsr
NOD32 a variant of Win32/PSW.LdPinch.NCB
Norman Virus Control Sandbox: W32/Malware
Panda Antivirus X
Rising Antivirus X
Sophos Antivirus Mal/Basine-C
VirusBuster X
VBA32 MalwareScope.Trojan-PSW.Pinch.1
===========================================================================
ComboFix 07-11-19.3 - Tim 2007-11-24 17:58:45.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.127 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tim\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\a.exe
C:\b.exe
C:\Documents and Settings\Tim\x.dat
C:\Documents and Settings\Tim\z.dat
C:\n.bat
C:\svchost.exe
C:\WINDOWS\Fonts\acrsecB.fon
C:\WINDOWS\Fonts\Crack.exe
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\GPInstall.exe
C:\WINDOWS\smdat32a.sys
C:\WINDOWS\smdat32m.sys
C:\WINDOWS\system32\adssite-remove.exe
C:\WINDOWS\system32\gzmrotate.dll
C:\WINDOWS\system32\hggedcc.dll
C:\WINDOWS\system32\khfgfca.dll
C:\WINDOWS\system32\ljjgdaa.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nnnlljh.dll
C:\WINDOWS\system32\rightonadz-uninst.exe
C:\WINDOWS\system32\rldyt.dll
C:\WINDOWS\system32\tuvsrsr.dll
C:\WINDOWS\system32\tuvwuus.dll
C:\WINDOWS\system32\vbzip10.dll
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Tim\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Tim\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Tim\Favorites\Online Security Guide.lnk
C:\n.bat
C:\Program Files\Video Add-on
C:\Program Files\Video Add-on\icmntr.exe
C:\Program Files\Video Add-on\icthis.exe
C:\Program Files\Video Add-on\ictmdl.dll
C:\Program Files\Video Add-on\ictun.exe
C:\Program Files\Video Add-on\icun.exe
C:\Program Files\Video Add-on\isfmdl.dll
C:\Program Files\Video Add-on\isfmm.exe
C:\Program Files\Video Add-on\isfmntr.exe
C:\Program Files\Video Add-on\isfun.exe
C:\Program Files\Video Add-on\ot.ico
C:\Program Files\Video Add-on\ts.ico
C:\Program Files\Video Add-on\uninst.exe
C:\Program Files\web buying
C:\Program Files\web buying\v1.8.6\wbuninst.exe
C:\Program Files\web buying\v1.8.6\webbuying.exe
C:\temp\tn3
C:\WINDOWS\cookies.ini
C:\WINDOWS\Fonts\acrsecB.fon
C:\WINDOWS\Fonts\Crack.exe
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\GPInstall.exe
C:\WINDOWS\smdat32a.sys
C:\WINDOWS\smdat32m.sys
C:\WINDOWS\system32\adssite-remove.exe
C:\WINDOWS\system32\b1
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\g2
C:\WINDOWS\system32\gzmrotate.dll
C:\WINDOWS\system32\hggedcc.dll
C:\WINDOWS\system32\i2
C:\WINDOWS\system32\i2\mper83122.exe
C:\WINDOWS\system32\khfgfca.dll
C:\WINDOWS\system32\ljjgdaa.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\n8
C:\WINDOWS\system32\n8\ensts2dll.exe
C:\WINDOWS\system32\nnnlljh.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rightonadz-uninst.exe
C:\WINDOWS\system32\rldyt.dll
C:\WINDOWS\system32\rMa18yy
C:\WINDOWS\system32\rMa18yy\rMa18yy2328.exe
C:\WINDOWS\system32\rqstv.ini
C:\WINDOWS\system32\rqstv.ini2
C:\WINDOWS\system32\tuvsrsr.dll
C:\WINDOWS\system32\tuvwuus.dll
C:\WINDOWS\system32\vbzip10.dll
C:\WINDOWS\system32\vhycqtsk.dllbox
C:\WINDOWS\system32\vtsqr.dll
C:\WINDOWS\system32\whqnsmd.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CORE
——-\LEGACY_DOMAINSERVICE
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-10-24 to 2007-11-24 )))))))))))))))))))))))))))))))
.

2007-11-24 14:13 776,109 —hs—- C:\WINDOWS\system32\mllnpucy.ini
2007-11-24 14:10 145,984 –a—— C:\WINDOWS\system32\jwwujokc.dll
2007-11-24 14:10 71,232 –a—— C:\WINDOWS\system32\kpaapmhn.exe
2007-11-23 19:51 d——– C:\WINDOWS\ERUNT
2007-11-23 14:21 d——– C:\Program Files\Trend Micro
2007-11-23 14:05 d——– C:\Temp
2007-11-23 14:05 533,387 –a—— C:\Temp\u900Y714.exe
2007-11-22 18:22 d——– C:\Program Files\Common Files\Download Manager
2007-11-21 18:24 d——– C:\Documents and Settings\Tim\Application Data\Sonic
2007-11-21 12:40 d——– C:\Program Files\IrfanView
2007-11-20 14:49 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-11-20 14:49 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-11-20 14:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-11-20 14:49 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-11-20 14:48 d——– C:\Program Files\Alwil Software
2007-11-20 14:48 801,144 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-11-20 14:48 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-11-20 14:48 94,416 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-11-20 14:48 92,848 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-11-20 14:37 d——– C:\Program Files\Ares
2007-11-20 13:16 d——– C:\Program Files\Common Files\Nullsoft
2007-11-18 15:29 d——– C:\Documents and Settings\Tim\Application Data\Move Networks
2007-11-17 23:29 d——– C:\Program Files\InterActual
2007-11-17 23:27 d——– C:\Documents and Settings\LocalService\Application Data\Yahoo!
2007-11-17 22:52 d–hs—- C:\WINDOWS\VGlt
2007-11-17 13:52 d——– C:\Documents and Settings\Tim\Application Data\RegClean
2007-11-17 13:51 d——– C:\Program Files\RegClean
2007-11-17 13:34 d——– C:\Program Files\Windows Live Safety Center
2007-11-15 22:12 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-13 18:12 d——– C:\Program Files\Bullfrog
2007-11-13 18:12 156 –a—— C:\WINDOWS\tmpcpyis.bat
2007-11-13 18:12 122 –a—— C:\WINDOWS\tmpdelis.bat
2007-11-13 18:12 26 –a—— C:\WINDOWS\winstart.bat
2007-11-13 18:11 299,008 –a—— C:\WINDOWS\uninst.exe
2007-11-12 19:32 d——– C:\Documents and Settings\Tim\WINDOWS
2007-11-12 18:27 216,977 –a—— C:\CRACK MA.DAT
2007-11-12 18:06 d——– C:\Games
2007-11-12 00:19 d——– C:\WINDOWS\CinemaTycoonCC
2007-11-12 00:11 d——– C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL
2007-11-11 22:40 d——– C:\Documents and Settings\All Users\Application Data\Trymedia
2007-11-11 19:09 d——– C:\EbayTycoon
2007-11-11 17:28 483,328 –a—— C:\WINDOWS\system32\actskn45.ocx
2007-11-10 20:14 d——– C:\Program Files\PokerStars
2007-11-10 14:42 d——– C:\Program Files\Disney
2007-11-10 07:15 d——– C:\Program Files\MySpace
2007-11-10 07:15 d——– C:\Documents and Settings\Tim\Application Data\MySpace
2007-11-09 21:37 d——– C:\Program Files\Wizards of the Coast
2007-11-09 17:18 d——– C:\Program Files\Conquer 2.0
2007-11-09 00:47 d——– C:\Downloads

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-24 19:13 85,056 —-a-w C:\WINDOWS\system32\ycupnllm.dll
2007-11-24 19:10 81,472 —-a-w C:\WINDOWS\system32\uchjpuwm.dll
2007-11-24 19:10 145,984 —-a-w C:\WINDOWS\system32\vhycqtsk.dll
2007-11-23 01:21 ——— d—–w C:\Program Files\Yahoo!
2007-11-22 19:02 ——— d—–w C:\Program Files\Iomega
2007-11-20 20:32 ——— d—–w C:\Documents and Settings\Tim\Application Data\Lenovo
2007-11-20 18:49 ——— d—–w C:\Program Files\WordPerfect Office 12
2007-11-20 18:40 ——— d—–w C:\Program Files\Lenovo
2007-11-20 18:40 ——— d—–w C:\Program Files\Common Files\Lenovo
2007-11-20 18:38 23,552 —-a-w C:\WINDOWS\system32\drivers\psasrv.exe
2007-11-20 18:38 17,536 —-a-w C:\WINDOWS\system32\drivers\psadd.sys
2007-11-18 22:47 ——— d—–w C:\Program Files\Google
2007-11-18 20:03 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-18 05:00 5,427 —-a-w C:\WINDOWS\system32\EGATHDRV.SYS
2007-11-13 04:02 6,216 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-10-31 18:03 245,408 —-a-w C:\WINDOWS\system32\unicows.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-15 02:20 ——— d—–w C:\Documents and Settings\Tim\Application Data\Apple Computer
2007-10-07 02:36 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-07 02:36 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-07 02:36 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-07 02:36 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-07 02:36 ——— d—–w C:\Program Files\Symantec
2005-07-29 21:24 472 –sha-r C:\WINDOWS\VGlt\p35Q.vbs
.

((((((((((((((((((((((((((((( snapshot@2007-11-23_14.05.54.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-23 18:11:56 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2007-11-24 00:52:28 4,513,792 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2007-11-24 00:52:28 217,088 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2007-11-23 18:11:56 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2007-11-24 00:52:09 4,513,792 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2007-11-24 00:52:09 217,088 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2007-11-24 23:14:10 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_1b8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-24 14:10 145984 –a—— C:\WINDOWS\system32\vhycqtsk.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AAF138EF-7499-4C4F-97DD-4B7E3CDC780F}]
C:\Program Files\Internet Explorer\hokenoxaC:\WINDOWS\system32\i2\mper83122.exe.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{eefadd6a-432c-41cd-b6a3-dd837bf36eb5}]
2007-11-24 14:10 81472 –a—— C:\WINDOWS\system32\uchjpuwm.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\vhycqtsk.dll [2007-11-24 14:10 145984]

[HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\vhycqtsk.dll [2007-11-24 14:10 145984]

[HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 19:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-19 00:51]
"TPHOTKEY"="C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe" [2006-05-07 20:34]
"TPWAUDAP"="C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe" [2006-04-19 17:29]
"PMHandler"="C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe" [2006-08-22 02:54]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 02:56 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 04:04 C:\WINDOWS\SkyTel.exe]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2006-01-25 04:45]
"AGRSMMSG"="AGRSMMSG.exe" [2006-08-30 02:40 C:\WINDOWS\AGRSMMSG.exe]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-06-25 08:19]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-22 23:17]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-22 23:13]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-22 23:17]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-12-05 14:53]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2006-07-14 21:05]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-08-09 09:03]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 13:44]
"LPManager"="C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe" [2006-07-03 11:11]
"AMSG"="C:\Program Files\ThinkVantage\AMSG\Amsg.exe" [2005-11-22 06:36]
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-18 19:24]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2006-03-15 18:07]
"cssauth"="C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" [2006-07-14 21:13]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2006-01-10 21:01]
"ADUserMon"="C:\Program Files\Iomega\AutoDisk\ADUserMon.exe" [2002-09-24 16:39]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-27 19:03]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 06:06]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" []
"b40697c0"="C:\WINDOWS\system32\ycupnllm.dll" [2007-11-24 14:13]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 19:04]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 01:06:58]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-06-02 03:29:26]
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [1999-09-04 17:23:00]
officejet 6100.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe [2003-04-06 00:37:38]
Photags AutoDetect.lnk - C:\Program Files\PhoTags Express\Photags AutoDetect.exe [2007-07-04 17:51:24]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
ACNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
tphklock.dll 2006-01-11 01:05 13824 C:\WINDOWS\system32\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vhycqtsk]
vhycqtsk.dll 2007-11-24 14:10 145984 C:\WINDOWS\system32\vhycqtsk.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\vtsqr.dll
"Notification Packages"= scecli ACGina

R1 ANC;ANC;C:\WINDOWS\system32\drivers\ANC.SYS
R1 IBMTPCHK;IBMTPCHK;\??\C:\WINDOWS\system32\Drivers\IBMBLDID.sys
R1 PMHler;PMHler;C:\WINDOWS\system32\drivers\PMHler.sys
R2 smi2;smi2;\??\C:\Program Files\SMI2\smi2.sys
S3 TPPWRIF;TPPWRIF;\??\C:\WINDOWS\_tpb0000.tmp\TPPWRIF.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-11-11 14:40:09 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1173451077.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe:-I
"2007-11-24 08:30:00 C:\WINDOWS\Tasks\RegClean Scheduled Scan.job"
- C:\Program Files\RegClean\RegClean.ex
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-24 18:15:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WAM]
"ImagePath"="\??\C:\Program Files\Lenovo\Rescue and Recovery\WAM.sys"
.
Completion time: 2007-11-24 18:18:41 - machine was rebooted
C:\ComboFix2.txt … 2007-11-23 14:08
.Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:15:14 PM, on 11/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Lenovo\PM Driver\PMSveH.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Common Files\Lenovo\Logger\logmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe
C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
C:\Program Files\ThinkVantage\AMSG\Amsg.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\PhoTags Express\Photags AutoDetect.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.worldusa.com
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: (no name) - `@497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\vhycqtsk.dll
O2 - BHO: (no name) - {AAF138EF-7499-4C4F-97DD-4B7E3CDC780F} - C:\Program Files\Internet Explorer\hokenoxaC:\WINDOWS\system32\i2\mper83122.exe.dll (file missing)
O2 - BHO: {5be63fb7-38dd-3a6b-dc14-c234a6ddafee} - {eefadd6a-432c-41cd-b6a3-dd837bf36eb5} - C:\WINDOWS\system32\uchjpuwm.dll
O2 - BHO: (no name) - @B9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: (no name) - À@8ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\vhycqtsk.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TPWAUDAP] C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
O4 - HKLM\..\Run: [PMHandler] C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [b40697c0] rundll32.exe "C:\WINDOWS\system32\ycupnllm.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: officejet 6100.lnk = ?
O4 - Global Startup: Photags AutoDetect.lnk = C:\Program Files\PhoTags Express\Photags AutoDetect.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.topsoftwarefeed.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.topsoftwarefeed.com/redirect.php (file missing)
O9 - Extra button: System Update - {DA320635-F48C-4613-8325-D75A933C549E} - C:\Program Files\Lenovo\System Update\sulauncher.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/welcome/3000notebook
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex…wareControl.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O20 - Winlogon Notify: vhycqtsk - C:\WINDOWS\SYSTEM32\vhycqtsk.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PMSveH - Lenovo - C:\Program Files\Lenovo\PM Driver\PMSveH.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: System Update (SUService) - - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkVantage Registry Monitor Service - Unknown owner - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

–
End of file - 12155 bytes

— E O F —
================================================================================
=======
also i have realized that it was not only with the kaspersky scan, it is like that with most any links that i click on. And last night i told you that the toolbar was almost gone, well, this morning, it was completely back, just the one, not two. just other little tidbits i thought you might need to know ;)
Hi :)

Seems like you got reinfected, like I thought. Please do the following (delete the CFScript you currently have):

Open Notepad (Go to Start > Run, type Notepad and hit Enter), and copy/paste the text in the quotebox below into it:

File::

C:\WINDOWS\system32\mllnpucy.ini
C:\WINDOWS\system32\jwwujokc.dll
C:\WINDOWS\system32\kpaapmhn.exe
C:\Temp\u900Y714.exe
C:\CRACK MA.DAT
C:\WINDOWS\system32\ycupnllm.dll
C:\WINDOWS\system32\uchjpuwm.dll
C:\WINDOWS\system32\vhycqtsk.dll

Folder::

C:\WINDOWS\VGlt
C:\Program Files\Internet Explorer\hokenoxaC:

DirLook::

C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL

Registry::

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AAF138EF-7499-4C4F-97DD-4B7E3CDC780F}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{eefadd6a-432c-41cd-b6a3-dd837bf36eb5}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"=-
[-HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"=-
[-HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"b40697c0"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vhycqtsk]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
Click on File > Save as….

In the File Name box, copy/paste CFScript.txt (Note: Do not change the filename!)

Click Save.

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe.
It will create a log (C:\Combofix.txt). Post it back here, along with a new HijackThis log.
hello :) ok, not to sound stupid, but i had combined the two, the combofix.exe and the CFScript. how do i go about changing that? I apologize for the inconvienence. I am sorry, i figured it out. Just a second :)

i had combined the two, the combofix.exe and the CFScript. how do i go about changing that?

What do you mean by 'combined the two'? If you mean dragging CFScript into Combofix, like my instructions say, that's OK. I just need you to run another CFScript, and instructed you to delete the last one, if it was still on your machine. If it's not present anymore, continue with making the CFScript and dragging it into Combofix.
OK i am sorry for the misunderstanding. Here are the combofix and hijackthis logs.

ComboFix 07-11-19.3 - Tim 2007-11-25 13:03:17.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tim\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\CRACK MA.DAT
C:\Temp\u900Y714.exe
C:\WINDOWS\system32\jwwujokc.dll
C:\WINDOWS\system32\kpaapmhn.exe
C:\WINDOWS\system32\mllnpucy.ini
C:\WINDOWS\system32\uchjpuwm.dll
C:\WINDOWS\system32\vhycqtsk.dll
C:\WINDOWS\system32\ycupnllm.dll
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\CRACK MA.DAT
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Tim\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Tim\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Tim\Favorites\Online Security Guide.lnk
C:\Temp\u900Y714.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\jwwujokc.dll
C:\WINDOWS\system32\kpaapmhn.exe
C:\WINDOWS\system32\mllnpucy.ini
C:\WINDOWS\system32\uchjpuwm.dll
C:\WINDOWS\system32\vhycqtsk.dll
C:\WINDOWS\system32\vhycqtsk.dllbox
C:\WINDOWS\system32\ycupnllm.dll
C:\WINDOWS\VGlt
C:\WINDOWS\VGlt\p35Q.vbs

.
((((((((((((((((((((((((( Files Created from 2007-10-25 to 2007-11-25 )))))))))))))))))))))))))))))))
.

2007-11-24 19:55 d——– C:\Program Files\directx
2007-11-23 19:51 d——– C:\WINDOWS\ERUNT
2007-11-23 14:21 d——– C:\Program Files\Trend Micro
2007-11-23 14:06 d——– C:\WINDOWS\system32\cc1
2007-11-23 14:05 d——– C:\Temp
2007-11-22 18:22 d——– C:\Program Files\Common Files\Download Manager
2007-11-22 18:22 1,152 –a—— C:\WINDOWS\system32\windrv.sys
2007-11-21 18:24 d——– C:\Documents and Settings\Tim\Application Data\Sonic
2007-11-21 12:40 d——– C:\Program Files\IrfanView
2007-11-20 14:49 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-11-20 14:49 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-11-20 14:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-11-20 14:49 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-11-20 14:48 d——– C:\Program Files\Alwil Software
2007-11-20 14:48 801,144 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-11-20 14:48 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-11-20 14:48 94,416 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-11-20 14:48 92,848 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-11-20 14:37 d——– C:\Program Files\Ares
2007-11-20 13:16 d——– C:\Program Files\Common Files\Nullsoft
2007-11-18 15:29 d——– C:\Documents and Settings\Tim\Application Data\Move Networks
2007-11-17 23:29 d——– C:\Program Files\InterActual
2007-11-17 23:27 d——– C:\Documents and Settings\LocalService\Application Data\Yahoo!
2007-11-17 13:52 d——– C:\Documents and Settings\Tim\Application Data\RegClean
2007-11-17 13:51 d——– C:\Program Files\RegClean
2007-11-17 13:34 d——– C:\Program Files\Windows Live Safety Center
2007-11-15 22:12 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-13 18:12 d——– C:\Program Files\Bullfrog
2007-11-13 18:12 156 –a—— C:\WINDOWS\tmpcpyis.bat
2007-11-13 18:12 122 –a—— C:\WINDOWS\tmpdelis.bat
2007-11-13 18:12 26 –a—— C:\WINDOWS\winstart.bat
2007-11-13 18:11 299,008 –a—— C:\WINDOWS\uninst.exe
2007-11-12 19:32 d——– C:\Documents and Settings\Tim\WINDOWS
2007-11-12 18:06 d——– C:\Games
2007-11-12 00:19 d——– C:\WINDOWS\CinemaTycoonCC
2007-11-12 00:11 d——– C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL
2007-11-11 22:40 d——– C:\Documents and Settings\All Users\Application Data\Trymedia
2007-11-11 19:09 d——– C:\EbayTycoon
2007-11-11 17:28 483,328 –a—— C:\WINDOWS\system32\actskn45.ocx
2007-11-10 20:14 d——– C:\Program Files\PokerStars
2007-11-10 14:42 d——– C:\Program Files\Disney
2007-11-10 07:15 d——– C:\Program Files\MySpace
2007-11-10 07:15 d——– C:\Documents and Settings\Tim\Application Data\MySpace
2007-11-09 21:37 d——– C:\Program Files\Wizards of the Coast
2007-11-09 17:18 d——– C:\Program Files\Conquer 2.0
2007-11-09 00:47 d——– C:\Downloads

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-25 00:45 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-23 01:21 ——— d—–w C:\Program Files\Yahoo!
2007-11-22 19:02 ——— d—–w C:\Program Files\Iomega
2007-11-20 20:32 ——— d—–w C:\Documents and Settings\Tim\Application Data\Lenovo
2007-11-20 18:49 ——— d—–w C:\Program Files\WordPerfect Office 12
2007-11-20 18:40 ——— d—–w C:\Program Files\Lenovo
2007-11-20 18:40 ——— d—–w C:\Program Files\Common Files\Lenovo
2007-11-20 18:38 23,552 —-a-w C:\WINDOWS\system32\drivers\psasrv.exe
2007-11-20 18:38 17,536 —-a-w C:\WINDOWS\system32\drivers\psadd.sys
2007-11-18 22:47 ——— d—–w C:\Program Files\Google
2007-10-15 02:20 ——— d—–w C:\Documents and Settings\Tim\Application Data\Apple Computer
2007-10-07 02:36 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-07 02:36 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-07 02:36 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-07 02:36 ——— d—–w C:\Program Files\Symantec
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL —-

2006-01-22 00:45 22 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\zipnew.dat
2006-01-22 00:45 20 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\rarnew.dat
2002-05-15 14:51 435 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\rarreg.key
2002-05-15 14:32 747520 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\WinRAR.exe
2002-05-15 14:32 275968 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Rar.exe
2002-05-14 18:23 607 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Uninstall.lst
2002-05-14 18:22 99840 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Uninstall.exe
2002-05-14 18:22 318240 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\WinRAR.hlp
2002-05-14 18:22 31232 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Zip.SFX
2002-05-14 18:22 122880 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\RarExt.dll
2002-05-14 18:21 93816 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Dos.SFX
2002-05-14 18:21 69120 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Formats\bz2.fmt
2002-05-14 18:21 62976 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Formats\lzh.fmt
2002-05-14 18:21 62464 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Formats\ace.fmt
2002-05-14 18:21 57856 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Formats\gz.fmt
2002-05-14 18:21 57856 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Formats\arj.fmt
2002-05-14 18:21 55808 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Formats\cab.fmt
2002-05-14 18:21 55296 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Formats\iso.fmt
2002-05-14 18:21 52224 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Formats\uue.fmt
2002-05-14 18:21 51712 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Formats\tar.fmt
2002-05-14 18:21 47104 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Default.SFX
2002-05-14 18:20 37376 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\WinCon.SFX
2002-05-14 18:20 194048 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\UnRAR.exe
2002-05-13 21:54 16671 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Rar_Site.txt
2002-05-12 15:43 52115 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Rar.txt
2002-05-12 15:43 15194 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\WhatsNew.txt
2002-05-08 03:50 3323 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Order.txt
2002-04-29 21:51 539 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\File_Id.diz
2002-04-18 23:52 2721 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Register.txt
2002-04-18 23:52 136 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\UnrarSrc.txt
2002-04-10 14:59 5698 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\License.txt
2002-03-06 18:40 1075 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\RarFiles.lst
2002-01-31 18:53 7997 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\WinRAR.cnt
2002-01-31 18:35 10619 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\TechNote.txt
2002-01-23 04:42 1714 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\ReadMe.txt
2001-10-22 02:56 1100 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Descript.ion
2001-03-01 02:00 73728 –a—— C:\Program Files\winrar use to unzip all these games-JUST MOVE THE ENTIRE FOLDER INSIDE HERE TO YOUR PROGRAM FILES FOL\WinRAR\Formats\UNACEV2.DLL


((((((((((((((((((((((((((((( snapshot@2007-11-23_14.05.54.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-23 18:11:56 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2007-11-24 00:52:28 4,513,792 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2007-11-24 00:52:28 217,088 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2007-11-23 18:11:56 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2007-11-24 00:52:09 4,513,792 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2007-11-24 00:52:09 217,088 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2007-11-18 05:00:11 5,427 —-a-w C:\WINDOWS\system32\EGATHDRV.SYS
+ 2007-11-25 06:09:43 5,427 —-a-w C:\WINDOWS\system32\EGATHDRV.SYS
- 2007-11-23 19:01:09 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_158.dat
+ 2007-11-25 18:09:55 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_158.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 19:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-19 00:51]
"TPHOTKEY"="C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe" [2006-05-07 20:34]
"TPWAUDAP"="C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe" [2006-04-19 17:29]
"PMHandler"="C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe" [2006-08-22 02:54]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 02:56 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 04:04 C:\WINDOWS\SkyTel.exe]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2006-01-25 04:45]
"AGRSMMSG"="AGRSMMSG.exe" [2006-08-30 02:40 C:\WINDOWS\AGRSMMSG.exe]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-06-25 08:19]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-22 23:17]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-22 23:13]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-22 23:17]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-12-05 14:53]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2006-07-14 21:05]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-08-09 09:03]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 13:44]
"LPManager"="C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe" [2006-07-03 11:11]
"AMSG"="C:\Program Files\ThinkVantage\AMSG\Amsg.exe" [2005-11-22 06:36]
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-18 19:24]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2006-03-15 18:07]
"cssauth"="C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" [2006-07-14 21:13]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2006-01-10 21:01]
"ADUserMon"="C:\Program Files\Iomega\AutoDisk\ADUserMon.exe" [2002-09-24 16:39]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-27 19:03]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 06:06]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 19:04]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 01:06:58]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-06-02 03:29:26]
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [1999-09-04 17:23:00]
officejet 6100.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe [2003-04-06 00:37:38]
Photags AutoDetect.lnk - C:\Program Files\PhoTags Express\Photags AutoDetect.exe [2007-07-04 17:51:24]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
ACNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
tphklock.dll 2006-01-11 01:05 13824 C:\WINDOWS\system32\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"= scecli ACGina

R1 ANC;ANC;C:\WINDOWS\system32\drivers\ANC.SYS
R1 IBMTPCHK;IBMTPCHK;\??\C:\WINDOWS\system32\Drivers\IBMBLDID.sys
R1 PMHler;PMHler;C:\WINDOWS\system32\drivers\PMHler.sys
R2 smi2;smi2;\??\C:\Program Files\SMI2\smi2.sys
S3 TPPWRIF;TPPWRIF;\??\C:\WINDOWS\_tpb0000.tmp\TPPWRIF.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-11-11 14:40:09 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1173451077.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe:-I
"2007-11-25 08:30:00 C:\WINDOWS\Tasks\RegClean Scheduled Scan.job"
- C:\Program Files\RegClean\RegClean.ex
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-25 13:10:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WAM]
"ImagePath"="\??\C:\Program Files\Lenovo\Rescue and Recovery\WAM.sys"
.
Completion time: 2007-11-25 13:12:26 - machine was rebooted
C:\ComboFix2.txt … 2007-11-24 18:18
C:\ComboFix3.txt … 2007-11-23 14:08
.
— E O F —




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:15:13 PM, on 11/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Lenovo\PM Driver\PMSveH.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Common Files\Lenovo\Logger\logmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe
C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
C:\Program Files\ThinkVantage\AMSG\Amsg.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\PhoTags Express\Photags AutoDetect.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.worldusa.com
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: (no name) - `@497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - @B9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: (no name) - À@8ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TPWAUDAP] C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
O4 - HKLM\..\Run: [PMHandler] C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: officejet 6100.lnk = ?
O4 - Global Startup: Photags AutoDetect.lnk = C:\Program Files\PhoTags Express\Photags AutoDetect.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.topsoftwarefeed.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.topsoftwarefeed.com/redirect.php (file missing)
O9 - Extra button: System Update - {DA320635-F48C-4613-8325-D75A933C549E} - C:\Program Files\Lenovo\System Update\sulauncher.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/welcome/3000notebook
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex…wareControl.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PMSveH - Lenovo - C:\Program Files\Lenovo\PM Driver\PMSveH.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: System Update (SUService) - - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkVantage Registry Monitor Service - Unknown owner - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

–
End of file - 11679 bytes




**:)**AND ONCE AGAIN, THE TOOLBAR HAS DISAPPEARED, ONLY IT IS ENTIRELY GONE THIS TIME**:)**
Hi,

**:)**AND ONCE AGAIN, THE TOOLBAR HAS DISAPPEARED, ONLY IT IS ENTIRELY GONE THIS TIME**:)**

That's great to hear :thumbup: We still have some cleaning up to do, though:

Step 1

Please download ATF Cleaner. Double-click on ATF-Cleaner.exe to start the program.

  • Under the Main tab, put a check next to Select All.
    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)
  • If you use the Firefox browser:
    Click on Firefox at the top and put a check next to Select All.
    If you would like to keep your saved passwords, click No at the prompt.
    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)
  • If you use the Opera browser:
    Click on Opera at the top and put a check next to Select All.
    If you would like to keep your saved passwords, click No at the prompt.
    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)

Step 2

Open HijackThis, perform a scan and put a check next to the following items (if present):

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: (no name) - `@497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: (no name) - @B9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: (no name) - À@8ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.topsoftwarefeed.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.topsoftwarefeed.com/redirect.php (file missing)


Close all programs except HijackThis and click on Fix checked.

Step 3

Click Start then Run….

  • Type Combofix /u in the runbox and click OK. (Note: The space between the x and the /u needs to be there)

    [external image: Posted Image]
  • When shown the disclaimer, select 2.

Step 4

Please try the Kaspersky WebScanner again. If it still doesn't work, skip this step.

Click on Kaspersky Online Scanner. On the welcome screen, click Accept.

You will be promted to install an ActiveX component from Kaspersky, click Install.

  • The program will launch and then begin downloading the latest definition files.
  • Once the files have been downloaded click on Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:

  • Scan using the following Anti-Virus database:

    Extended (if available, otherwise Standard)

  • Scan Options:

    Scan Archives
    Scan Mail Bases

  • Click OK.
  • Now under Select a Target to Scan:

    Select My Computer.

  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button and save the file to your desktop.

Step 5

In your next reply, please post:

  • a new HijackThis log
  • the Kaspersky Online Scan report (if it worked)
  • How is your computer running now?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:19:43 PM, on 11/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Lenovo\PM Driver\PMSveH.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Common Files\Lenovo\Logger\logmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe
C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
C:\Program Files\ThinkVantage\AMSG\Amsg.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\PhoTags Express\Photags AutoDetect.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.worldusa.com
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TPWAUDAP] C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
O4 - HKLM\..\Run: [PMHandler] C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: officejet 6100.lnk = ?
O4 - Global Startup: Photags AutoDetect.lnk = C:\Program Files\PhoTags Express\Photags AutoDetect.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: System Update - {DA320635-F48C-4613-8325-D75A933C549E} - C:\Program Files\Lenovo\System Update\sulauncher.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/welcome/3000notebook
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex…wareControl.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PMSveH - Lenovo - C:\Program Files\Lenovo\PM Driver\PMSveH.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: System Update (SUService) - - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkVantage Registry Monitor Service - Unknown owner - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

–
End of file - 10824 bytes


Still no luck with the Kaspersky Scanner
Other than that, the toolbar is gone, and since i told you earlier that it was gone, i have not encountered any popups (YES!!!!) and things have been running good. at first everytime i opened IE it would bring up a blank page (after the toolbar disappeared) and now, it is bringing up MSN.com. So things seem to be running smoothly as they used to!!! Thank you SOOOO much! You have been very helpful, and patient.
So, what do we do next?
Hi :)

I'm still a bit unsure about the Kaspersky Scanner. If I'm correct, the problem is that when you click the Kasperksy Online Scanner button, nothing happens. Maybe it's a Java problem.

First, update Java:

Your Java software is out of date. Follow these instructions to update it:

  • Go to Start and click on Control Panel, then double-click on Add or Remove Programs.
  • Search for previously installed versions of Java (J2SE Runtime Environment), and remove it. It should have this icon next to it: [external image: Posted Image]
  • Then download and install Java Runtime Environment (JRE) 6 Update 3.

Reboot your computer.

Then, make sure Java is enabled in Internet Explorer, by following the instructions on this site.

Try the Kaspersky Online Scan again. If it doesn't work, let me know whether you have problems clicking on other links, like the links I'm providing you. Also, do you have software installed that blocks pop ups?
i am still not able to get the Kaspersky Scan to work. You are correct, whenever I click on the "scan now" button, nothing happens. I have right clicked on it and went to open link, open link in a new tab, open link in a new window, and nothing. All of the other links that you have given me have worked fine. The only other time that i have noticed a link not working like it is with Kaspersky was when my husband got on an employment site and tried to sign in, and the log in link was not working. Now, as far as the pop-up blocker goes, i am unsure exactly if it s a a specific software, but we do have one. I actually think that it is included with IE. i get to it by clicking on the tools menu and going to pop-up blocker that way. i have tried to turn it off when i click on the "Scan Now" icon on the Kaspersky site, and still no luck.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI