This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please Help

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

K well Im not the most computery person so Ill appoligize ahead of time (not the best speller either) anyway I am trying to fix this before this computer gets reformatted yet again (by a reformat happy person). Anyway Recently after someone was using the computer I noticed the screens background had changed to this red thing that says "your privacy is in danger" Im also getting pop up trying to get me to download things. anyway I hit ctrl alt del to see all the thingys (computer terminolligy isnt great) anyway there was one i didnt recognize SSDK02.exe anyway I googled it and all my results were forum posts with hijackthis so i downloaded it and here i am. Oh and i ran all my norton virus and spyware things and it didnt pick anything up, anyway here are all the logs i got from hijackthis…… (Oh and if I had to guess whatever this is got on the comp either threw a messenger service or explorer, those were the applications the person was using just before this happened, if that helps at all.

StartupList report, 11/25/2007, 12:37:12 AM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\paul\Desktop\HiJackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16544)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Advanced Parental Control\BackProcessAPC.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\Rogers\SelfHealing\rogersagent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\paul\Desktop\HiJackThis.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe

————————————————–

Listing of startup folders:

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

Media Codec Update Service = C:\Program Files\Essentials Codec Pack\update.exe -silent
NeroFilterCheck = C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
NBKeyScan = "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
ISUSPM = "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
CloneCDTray = "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
VirtualCloneDrive = "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
SunJavaUpdateSched = "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
YOP = C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
osCheck = "C:\PROGRA~1\Symantec\osCheck.exe"
Symantec PIF AlertEng = "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
QuickTime Task = "C:\Program Files\QuickTime\QTTask.exe" -atboottime
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
APC = C:\Program Files\Advanced Parental Control\BackProcessAPC.exe

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

MsnMsgr = "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} = "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
µTorrent = "C:\Program Files\uTorrent\utorrent.exe"
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
RogersAgent = c:\Program Files\Rogers\SelfHealing\rogersagent.exe
SHS = "C:\Program Files\Rogers\SelfHealing\SHS.exe" /background
Update Manager = "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
AnyDVD = C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
APC = C:\Program Files\Advanced Parental Control\BackProcessAPC.exe

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

[AdobeUpdater]
=

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - (no file) - {02478D38-C3F9-4efb-9B51-7695ECA05670}
(no name) - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll - {3049C3E9-B461-4BC5-8870-4C09146192CA}
(no name) - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - C:\WINDOWS\werbetdqw.dll - {A477EBE4-ABE9-4A9D-B1B4-0EB1D0D025CE}
(no name) - c:\program files\google\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
(no name) - C:\PROGRA~1\Neopets\Toolbar\Toolbar.dll - {CD292324-974F-4224-D074-CACA427AA030}
(no name) - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D}

————————————————–

Enumerating Task Scheduler jobs:

1-Click Maintenance.job
AppleSoftwareUpdate.job
Norton Security Online - Run Full System Scan - paul.job

————————————————–

Enumerating Download Program Files:

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\macromed\Director\SwDir.dll
CODEBASE = http://fpdownload.macromedia.com/pub/shock…director/sw.cab

[Installation Support]
InProcServer32 = C:\Program Files\Yahoo!\Common\Yinsthelper.dll
CODEBASE = C:\Program Files\Yahoo!\Common\Yinsthelper.dll

[Virtools WebPlayer Class]
InProcServer32 = C:\Program Files\Virtools\3D Life Player\WebPlayer.ocx
CODEBASE = http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe

————————————————–

Enumerating Winsock LSP files:

NameSpace #4: C:\Program Files\Bonjour\mdnsNSP.dll

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
gormet: C:\WINDOWS\gormet.dll
pmkret: C:\WINDOWS\pmkret.dll

————————————————–
End of report, 9,180 bytes
Report generated in 0.093 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:35:13 AM, on 11/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Advanced Parental Control\BackProcessAPC.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\Rogers\SelfHealing\rogersagent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\paul\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: MSVPS System - {A477EBE4-ABE9-4A9D-B1B4-0EB1D0D025CE} - C:\WINDOWS\werbetdqw.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Neopets - {CD292324-974F-4224-D074-CACA427AA030} - C:\PROGRA~1\Neopets\Toolbar\Toolbar.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Neopets - {CD292324-974F-4224-D074-CACA427AA030} - C:\PROGRA~1\Neopets\Toolbar\Toolbar.dll
O3 - Toolbar: The hdtip - {85B2F289-7128-4C5A-A330-F9FC01432D3A} - C:\WINDOWS\hdtip.dll
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [APC] C:\Program Files\Advanced Parental Control\BackProcessAPC.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [µTorrent] "C:\Program Files\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RogersAgent] c:\Program Files\Rogers\SelfHealing\rogersagent.exe
O4 - HKCU\..\Run: [SHS] "C:\Program Files\Rogers\SelfHealing\SHS.exe" /background
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [APC] C:\Program Files\Advanced Parental Control\BackProcessAPC.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\paul\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe
O21 - SSODL: gormet - {DD62F780-5BA0-4601-A18F-AF3AF04FB347} - C:\WINDOWS\gormet.dll
O21 - SSODL: pmkret - {26E19283-B48D-438D-9B74-FAE15B41BCDF} - C:\WINDOWS\pmkret.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

–
End of file - 11518 bytes
I know your not suppose to bump your thingy but people who posted theirs after me have been getting answers and if i cant fix this soon my comp will be getting reformatted and ill lose most of my stuff, which i really want to avoid. So can someone please please help me. *gets on knees and begs*
Im not posting this to bump my board but because i saw someone post their problem this morning (which is the same one i have) and since he got an answer ive been following what that person has been telling him to do anyway, gotta wait for them to tell him what to do next but i got a new log from another program now so i figured id post it since i guess it must help find the problem, oh and this is the link to the board with the person with the same problem as me… http://forums.whatthetech.com/Malware_link…ure_t85637.html

and this is the report thing (oh and when the log for it poped up 2 pop up windows did too saying a certain thingy couldnt be found)….


ComboFix 07-11-19.3 - paul 2007-11-25 16:27:53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.546 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\paul\Application Data\inst.exe
C:\Documents and Settings\paul\Desktop\Error Cleaner.url
C:\Documents and Settings\paul\Desktop\Privacy Protector.url
C:\Documents and Settings\paul\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\paul\Favorites\Error Cleaner.url
C:\Documents and Settings\paul\Favorites\Privacy Protector.url
C:\Documents and Settings\paul\Favorites\Spyware&Malware Protection.url
C:\WINDOWS\dat.txt
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\rs.txt
C:\WINDOWS\search_res.txt

.
((((((((((((((((((((((((( Files Created from 2007-10-25 to 2007-11-25 )))))))))))))))))))))))))))))))
.

2007-11-25 14:21 230 –a—— C:\WINDOWS\system32\spupdsvc.inf
2007-11-25 14:20 66,048 –a—— C:\WINDOWS\ieResetIcons.exe
2007-11-25 11:57 d——– C:\WINDOWS\LastGood
2007-11-25 11:53 d——– C:\Program Files\DVDFab Platinum 4
2007-11-25 08:55 d——– C:\Program Files\Lavasoft
2007-11-25 08:55 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-25 08:54 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-11-25 00:21 d——– C:\Documents and Settings\Administrator\Application Data\Apple Computer
2007-11-24 21:44 22,112 -ra—— C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-11-24 21:44 10,592 -ra—— C:\WINDOWS\system32\drivers\COH_Mon.cat
2007-11-24 21:44 705 -ra—— C:\WINDOWS\system32\drivers\COH_Mon.inf
2007-11-24 17:39 737,280 –a—— C:\WINDOWS\iun6002.exe
2007-11-24 17:33 d——– C:\Program Files\DivX
2007-11-24 17:32 20,996 –a—— C:\WINDOWS\system32\divxg400.htm
2007-11-24 17:19 d——– C:\Program Files\Advanced Parental Control
2007-11-24 17:19 d——– C:\Documents and Settings\All Users\Application Data\APC
2007-11-24 17:19 244,024 –a—— C:\WINDOWS\system32\MSFLXGRD.OCX
2007-11-24 17:19 180,224 –a—— C:\WINDOWS\system32\ijl11.dll
2007-11-24 17:19 140,096 –a—— C:\WINDOWS\system32\COMDLG32.OCX
2007-11-24 17:18 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-24 16:35 331,776 –a—— C:\WINDOWS\gormet.dll
2007-11-24 16:35 319,488 –a—— C:\WINDOWS\werbetdqw.dll
2007-11-24 16:35 282,112 –a—— C:\WINDOWS\pmkret.dll
2007-11-24 16:35 188,416 –a—— C:\WINDOWS\hdtip.dll
2007-11-24 16:35 151,552 –a—— C:\WINDOWS\monhop.exe
2007-11-22 16:14 d——– C:\DVR108
2007-11-21 17:42 d——– C:\WINDOWS\nview
2007-11-21 17:42 356,352 –a—— C:\WINDOWS\system32\nvudisp.exe
2007-11-21 17:42 140,158 –a—— C:\WINDOWS\system32\nvapps.xml
2007-11-21 17:42 17,525 –a—— C:\WINDOWS\system32\nvdisp.nvu
2007-11-21 17:41 356,352 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2007-11-21 17:40 d——– C:\NVIDIA
2007-11-21 17:34 d——– C:\Documents and Settings\paul\Application Data\SystemRequirementsLab
2007-11-21 16:15 d——– C:\Program Files\Virtools
2007-11-20 12:32 d——– C:\Documents and Settings\Default User\Application Data\Apple Computer
2007-11-12 17:07 d——– C:\Documents and Settings\paul\Application Data\Apple Computer
2007-11-12 17:02 d——– C:\Program Files\QuickTime
2007-11-07 13:39 60,800 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-11-07 13:38 d——– C:\Program Files\Symantec
2007-11-07 13:38 d——– C:\Program Files\Common Files\Symantec Shared
2007-11-07 13:38 d——– C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-07 13:36 344,064 –a—— C:\WINDOWS\system32\msvcr70.dll
2007-11-07 13:36 89,088 –a—— C:\WINDOWS\system32\ATL71.DLL
2007-11-07 13:36 84,992 –a—— C:\WINDOWS\system32\ATL70.DLL
2007-11-07 13:36 24,576 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-11-07 13:35 d——– C:\Program Files\Rogers
2007-10-30 06:01 d——– C:\WINDOWS\ShellNew
2007-10-30 05:59 d——– C:\Documents and Settings\paul\Application Data\Microsoft Web Folders
2007-10-30 05:38 d——– C:\WINDOWS\Sun
2007-10-29 10:30 d——– C:\Program Files\Bonjour
2007-10-27 19:40 d——– C:\Documents and Settings\Guest\Application Data\MySpace
2007-10-27 17:38 d——– C:\Documents and Settings\Guest\Application Data\Yahoo!
2007-10-27 17:38 d——– C:\Documents and Settings\Guest\Application Data\Neopets Toolbar
2007-10-27 17:35 d——– C:\Documents and Settings\Guest\Application Data\Nero

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-25 19:22 ——— d—–w C:\Documents and Settings\paul\Application Data\uTorrent
2007-11-25 17:06 ——— d—–w C:\Documents and Settings\paul\Application Data\Vso
2007-11-25 13:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2007-11-25 13:39 ——— d—–w C:\Program Files\Apple Software Update
2007-11-25 03:55 ——— d—–w C:\Documents and Settings\paul\Application Data\Yahoo!
2007-11-25 03:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-25 03:52 ——— d—–w C:\Program Files\Yahoo!
2007-11-25 03:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-25 02:37 ——— d—–w C:\Program Files\AC3Filter
2007-11-21 22:41 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-09 18:13 ——— d—–w C:\Program Files\Elaborate Bytes
2007-11-07 18:53 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-11-07 18:53 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-11-07 18:53 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-11-07 18:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2007-10-31 00:55 625,032 —-a-w C:\WINDOWS\system32\SymNeti.dll
2007-10-31 00:55 39,856 —-a-w C:\WINDOWS\system32\drivers\symids.sys
2007-10-31 00:55 37,936 —-a-w C:\WINDOWS\system32\drivers\symndisv.sys
2007-10-31 00:55 35,120 —-a-w C:\WINDOWS\system32\drivers\symndis.sys
2007-10-31 00:55 27,696 —-a-w C:\WINDOWS\system32\drivers\symredrv.sys
2007-10-31 00:55 242,056 —-a-w C:\WINDOWS\system32\SymRedir.dll
2007-10-31 00:55 191,536 —-a-w C:\WINDOWS\system32\drivers\symtdi.sys
2007-10-31 00:55 145,968 —-a-w C:\WINDOWS\system32\drivers\symfw.sys
2007-10-31 00:55 12,848 —-a-w C:\WINDOWS\system32\drivers\symdns.sys
2007-10-31 00:24 12,963 —-a-w C:\WINDOWS\system32\drivers\SymRedir.cat
2007-10-31 00:24 1,358 —-a-w C:\WINDOWS\system32\drivers\SymRedir.inf
2007-10-29 15:30 ——— d—–w C:\Program Files\Common Files\Adobe
2007-10-27 22:29 ——— d—–w C:\Documents and Settings\paul\Application Data\InterVideo
2007-10-24 21:43 ——— d—–w C:\Program Files\Java
2007-10-24 21:43 ——— d—–w C:\Program Files\Common Files\Java
2007-10-23 22:33 ——— d—–w C:\Program Files\Neopets
2007-10-23 22:33 ——— d—–w C:\Documents and Settings\paul\Application Data\Neopets Toolbar
2007-10-23 16:47 ——— d–h–w C:\Documents and Settings\All Users\Application Data\CanonBJ
2007-10-22 19:38 ——— d—–w C:\Program Files\Common Files\logishrd
2007-10-22 19:22 ——— d—–w C:\Program Files\SlySoft
2007-10-20 19:29 96,832 —-a-w C:\WINDOWS\system32\drivers\AnyDVD.sys
2007-10-18 09:06 156,992 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-10-16 22:40 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-16 22:02 ——— d—–w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-10-16 20:34 ——— d—–w C:\Program Files\Common Files\Macrovision Shared
2007-10-15 15:49 ——— d—–w C:\Program Files\InterVideo
2007-10-13 14:27 ——— d—–w C:\Documents and Settings\paul\Application Data\TuneUp Software
2007-10-13 11:40 ——— d—–w C:\Program Files\MSXML 4.0
2007-10-13 03:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\vsosdk
2007-10-12 21:45 ——— d—–w C:\Program Files\Real
2007-10-12 21:45 ——— d—–w C:\Program Files\Common Files\xing shared
2007-10-12 21:45 ——— d—–w C:\Program Files\Common Files\Real
2007-10-12 21:39 ——— d—–w C:\Program Files\InterVideo Information Service
2007-10-12 21:39 ——— d—–w C:\Program Files\Common Files\Ulead
2007-10-12 21:38 ——— d—–w C:\Program Files\Common Files\InterVideo
2007-10-12 21:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-10-12 21:21 47,360 —-a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2007-10-12 21:21 47,360 —-a-w C:\Documents and Settings\paul\Application Data\pcouffin.sys
2007-10-12 21:21 ——— d—–w C:\Program Files\VSO
2007-10-12 20:48 ——— d—–w C:\Documents and Settings\paul\Application Data\Nero
2007-10-12 20:45 ——— d—–w C:\Program Files\Nero
2007-10-12 20:01 ——— d—–w C:\Documents and Settings\All Users\Application Data\Elaborate Bytes
2007-10-12 19:55 ——— d—–w C:\Program Files\Alcohol Soft
2007-10-12 19:53 685,816 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-10-12 19:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\SlySoft
2007-10-11 19:39 ——— d—–w C:\Program Files\uTorrent
2007-10-11 19:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-10-11 02:01 ——— d—–w C:\Program Files\Google
2007-10-11 00:36 ——— d—–w C:\Program Files\microsoft frontpage
2007-10-10 22:31 ——— d—–w C:\Documents and Settings\paul\Application Data\InterTrust
2007-10-10 22:28 ——— d—–w C:\Program Files\Intel
2007-10-04 22:14 81,920 —-a-w C:\WINDOWS\system32\nvwddi.dll
2007-10-04 22:14 81,920 —-a-w C:\WINDOWS\system32\nvmctray.dll
2007-10-04 22:14 8,491,008 —-a-w C:\WINDOWS\system32\nvcpl.dll
2007-10-04 22:14 753,664 —-a-w C:\WINDOWS\system32\nvcplui.exe
2007-10-04 22:14 6,854,464 —-a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-10-04 22:14 6,750,208 —-a-w C:\WINDOWS\system32\nvoglnt.dll
2007-10-04 22:14 6,344,704 —-a-w C:\WINDOWS\system32\nvdisps.dll
2007-10-04 22:14 5,783,424 —-a-w C:\WINDOWS\system32\nv4_disp.dll
2007-10-04 22:14 466,944 —-a-w C:\WINDOWS\system32\nvshell.dll
2007-10-04 22:14 45,056 —-a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-10-04 22:14 442,368 —-a-w C:\WINDOWS\system32\nvappbar.exe
2007-10-04 22:14 425,984 —-a-w C:\WINDOWS\system32\keystone.exe
2007-10-04 22:14 364,544 —-a-w C:\WINDOWS\system32\nvapi.dll
2007-10-04 22:14 36,864 —-a-w C:\WINDOWS\system32\nvcodins.dll
2007-10-04 22:14 36,864 —-a-w C:\WINDOWS\system32\nvcod.dll
2007-10-04 22:14 307,200 —-a-w C:\WINDOWS\system32\nvexpbar.dll
2007-10-04 22:14 3,551,232 —-a-w C:\WINDOWS\system32\nvvitvs.dll
2007-10-04 22:14 3,334,144 —-a-w C:\WINDOWS\system32\nvgames.dll
2007-10-04 22:14 286,720 —-a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-10-04 22:14 229,376 —-a-w C:\WINDOWS\system32\nvmccs.dll
2007-10-04 22:14 2,371,584 —-a-w C:\WINDOWS\system32\nvwss.dll
2007-10-04 22:14 188,416 —-a-w C:\WINDOWS\system32\nvmccss.dll
2007-10-04 22:14 155,716 —-a-w C:\WINDOWS\system32\nvsvc32.exe
2007-10-04 22:14 147,456 —-a-w C:\WINDOWS\system32\nvcolor.exe
2007-10-04 22:14 1,703,936 —-a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-10-04 22:14 1,626,112 —-a-w C:\WINDOWS\system32\nwiz.exe
2007-10-04 22:14 1,478,656 —-a-w C:\WINDOWS\system32\nview.dll
2007-10-04 22:14 1,339,392 —-a-w C:\WINDOWS\system32\nvdspsch.exe
2007-10-04 22:14 1,150,976 —-a-w C:\WINDOWS\system32\nvmobls.dll
2007-10-04 22:14 1,019,904 —-a-w C:\WINDOWS\system32\nvwimg.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A477EBE4-ABE9-4A9D-B1B4-0EB1D0D025CE}]
2007-11-24 10:53 319488 –a—— C:\WINDOWS\werbetdqw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{85B2F289-7128-4C5A-A330-F9FC01432D3A}"= C:\WINDOWS\hdtip.dll [2007-11-24 10:53 188416]

[HKEY_CLASSES_ROOT\clsid\{85b2f289-7128-4c5a-a330-f9fc01432d3a}]
[HKEY_CLASSES_ROOT\hdtip.ToolBar.1]
[HKEY_CLASSES_ROOT\TypeLib\{AE73C3E4-88F7-41A0-AF79-87BE6826B8DF}]
[HKEY_CLASSES_ROOT\hdtip.ToolBar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" []
"µTorrent"="C:\Program Files\uTorrent\utorrent.exe" [2006-07-02 11:29]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"RogersAgent"="c:\Program Files\Rogers\SelfHealing\rogersagent.exe" [2007-04-23 15:51]
"SHS"="C:\Program Files\Rogers\SelfHealing\SHS.exe" [2007-10-12 15:30]
"Update Manager"="C:\Program Files\Rogers\Update Manager\UpdateManager.exe" [2007-10-12 15:30]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2007-11-09 13:50]
"APC"="C:\Program Files\Advanced Parental Control\BackProcessAPC.exe" [2007-04-20 16:25]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Media Codec Update Service"="C:\Program Files\Essentials Codec Pack\update.exe" []
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" []
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 16:34]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-12 16:45]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 14:21]
"VirtualCloneDrive"="C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 08:21]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2007-06-26 13:48]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 00:59]
"osCheck"="C:\PROGRA~1\Symantec\osCheck.exe" [2007-01-14 02:11]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 20:16]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 02:56 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2007-10-04 17:14 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-04 02:56 C:\WINDOWS\system32\rundll32.exe]
"APC"="C:\Program Files\Advanced Parental Control\BackProcessAPC.exe" [2007-04-20 16:25]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv.exe" [2004-08-04 02:56 C:\WINDOWS\system32\grpconv.exe]
"IERESETATTRIB"="C:\WINDOWS\system32\cmd.exe" [2004-08-04 02:56]
"IERESETICONS"="C:\WINDOWS\system32\cmd.exe" [2004-08-04 02:56]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 00:48:20]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-22 23:01:50]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-10-15 10:50:00]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"gormet"= {DD62F780-5BA0-4601-A18F-AF3AF04FB347} - C:\WINDOWS\gormet.dll [2007-11-24 10:52 331776]
"pmkret"= {26E19283-B48D-438D-9B74-FAE15B41BCDF} - C:\WINDOWS\pmkret.dll [2007-11-24 10:52 282112]

R0 iviVD;iviVD;C:\WINDOWS\system32\DRIVERS\iviVD.sys
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-11-24 22:09:45 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2007-11-20 01:44:18 C:\WINDOWS\Tasks\Norton Security Online - Run Full System Scan - paul.job"
- C:\PROGRA~1\Symantec\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-25 16:30:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-25 16:30:39
.
— E O F —
Ok that other board added something else to do…"Open notepad and copy/paste the text in the quotebox below into it:

QUOTE
File::
C:\WINDOWS\rmvgor.dll
C:\WINDOWS\nethop.exe
C:\WINDOWS\jokwmp.dll
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\sapnet.dll
C:\WINDOWS\TEMP\025895~1.EXE
C:\DOCUME~1\Steve\LOCALS~1\Temp\o1394bul.sys

Folder::
C:\WINDOWS\privacy_danger

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{6BA27973-068D-4F85-BE84-1251E0B20FD3}]
[-HKEY_CLASSES_ROOT\clsid\{6ba27973-068d-4f85-be84-1251e0b20fd3}]
[-HKEY_CLASSES_ROOT\jokwmp.ToolBar.1]
[-HKEY_CLASSES_ROOT\TypeLib\{83AFF385-2051-4ADA-8001-549F0A671402}]
[-HKEY_CLASSES_ROOT\jokwmp.ToolBar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"rmvgor"=-
"sapnet"=-


Save this as Save this as "CFScript"




Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log."

I didnt have all the same things as that person did but i figured it couldnt hurt to follow those directions anyway so yeah here are my new logs……..

ComboFix 07-11-19.3 - paul 2007-11-25 16:52:34.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.544 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\paul\My Documents\CFScript.txt
* Created a new restore point

FILE
C:\DOCUME~1\Steve\LOCALS~1\Temp\o1394bul.sys
C:\WINDOWS\jokwmp.dll
C:\WINDOWS\nethop.exe
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\rmvgor.dll
C:\WINDOWS\sapnet.dll
C:\WINDOWS\TEMP\025895~1.EXE
.

((((((((((((((((((((((((( Files Created from 2007-10-25 to 2007-11-25 )))))))))))))))))))))))))))))))
.

2007-11-25 14:21 230 –a—— C:\WINDOWS\system32\spupdsvc.inf
2007-11-25 14:20 66,048 –a—— C:\WINDOWS\ieResetIcons.exe
2007-11-25 11:57 d——– C:\WINDOWS\LastGood
2007-11-25 11:53 d——– C:\Program Files\DVDFab Platinum 4
2007-11-25 08:55 d——– C:\Program Files\Lavasoft
2007-11-25 08:55 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-25 08:54 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-11-25 00:21 d——– C:\Documents and Settings\Administrator\Application Data\Apple Computer
2007-11-24 21:44 22,112 -ra—— C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-11-24 21:44 10,592 -ra—— C:\WINDOWS\system32\drivers\COH_Mon.cat
2007-11-24 21:44 705 -ra—— C:\WINDOWS\system32\drivers\COH_Mon.inf
2007-11-24 17:39 737,280 –a—— C:\WINDOWS\iun6002.exe
2007-11-24 17:33 d——– C:\Program Files\DivX
2007-11-24 17:32 20,996 –a—— C:\WINDOWS\system32\divxg400.htm
2007-11-24 17:19 d——– C:\Program Files\Advanced Parental Control
2007-11-24 17:19 d——– C:\Documents and Settings\All Users\Application Data\APC
2007-11-24 17:19 244,024 –a—— C:\WINDOWS\system32\MSFLXGRD.OCX
2007-11-24 17:19 180,224 –a—— C:\WINDOWS\system32\ijl11.dll
2007-11-24 17:19 140,096 –a—— C:\WINDOWS\system32\COMDLG32.OCX
2007-11-24 17:18 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-24 16:35 331,776 –a—— C:\WINDOWS\gormet.dll
2007-11-24 16:35 319,488 –a—— C:\WINDOWS\werbetdqw.dll
2007-11-24 16:35 282,112 –a—— C:\WINDOWS\pmkret.dll
2007-11-24 16:35 188,416 –a—— C:\WINDOWS\hdtip.dll
2007-11-24 16:35 151,552 –a—— C:\WINDOWS\monhop.exe
2007-11-22 16:14 d——– C:\DVR108
2007-11-21 17:42 d——– C:\WINDOWS\nview
2007-11-21 17:42 356,352 –a—— C:\WINDOWS\system32\nvudisp.exe
2007-11-21 17:42 140,158 –a—— C:\WINDOWS\system32\nvapps.xml
2007-11-21 17:42 17,525 –a—— C:\WINDOWS\system32\nvdisp.nvu
2007-11-21 17:41 356,352 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2007-11-21 17:40 d——– C:\NVIDIA
2007-11-21 17:34 d——– C:\Documents and Settings\paul\Application Data\SystemRequirementsLab
2007-11-21 16:15 d——– C:\Program Files\Virtools
2007-11-20 12:32 d——– C:\Documents and Settings\Default User\Application Data\Apple Computer
2007-11-12 17:07 d——– C:\Documents and Settings\paul\Application Data\Apple Computer
2007-11-12 17:02 d——– C:\Program Files\QuickTime
2007-11-07 13:39 60,800 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-11-07 13:38 d——– C:\Program Files\Symantec
2007-11-07 13:38 d——– C:\Program Files\Common Files\Symantec Shared
2007-11-07 13:38 d——– C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-07 13:36 344,064 –a—— C:\WINDOWS\system32\msvcr70.dll
2007-11-07 13:36 89,088 –a—— C:\WINDOWS\system32\ATL71.DLL
2007-11-07 13:36 84,992 –a—— C:\WINDOWS\system32\ATL70.DLL
2007-11-07 13:36 24,576 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-11-07 13:35 d——– C:\Program Files\Rogers
2007-10-30 06:01 d——– C:\WINDOWS\ShellNew
2007-10-30 05:59 d——– C:\Documents and Settings\paul\Application Data\Microsoft Web Folders
2007-10-30 05:38 d——– C:\WINDOWS\Sun
2007-10-29 10:30 d——– C:\Program Files\Bonjour
2007-10-27 19:40 d——– C:\Documents and Settings\Guest\Application Data\MySpace
2007-10-27 17:38 d——– C:\Documents and Settings\Guest\Application Data\Yahoo!
2007-10-27 17:38 d——– C:\Documents and Settings\Guest\Application Data\Neopets Toolbar
2007-10-27 17:35 d——– C:\Documents and Settings\Guest\Application Data\Nero

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-25 19:22 ——— d—–w C:\Documents and Settings\paul\Application Data\uTorrent
2007-11-25 17:06 ——— d—–w C:\Documents and Settings\paul\Application Data\Vso
2007-11-25 13:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2007-11-25 13:39 ——— d—–w C:\Program Files\Apple Software Update
2007-11-25 03:55 ——— d—–w C:\Documents and Settings\paul\Application Data\Yahoo!
2007-11-25 03:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-25 03:52 ——— d—–w C:\Program Files\Yahoo!
2007-11-25 03:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-25 02:37 ——— d—–w C:\Program Files\AC3Filter
2007-11-21 22:41 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-09 18:13 ——— d—–w C:\Program Files\Elaborate Bytes
2007-11-07 18:53 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-11-07 18:53 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-11-07 18:53 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-11-07 18:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2007-10-31 00:55 625,032 —-a-w C:\WINDOWS\system32\SymNeti.dll
2007-10-31 00:55 39,856 —-a-w C:\WINDOWS\system32\drivers\symids.sys
2007-10-31 00:55 37,936 —-a-w C:\WINDOWS\system32\drivers\symndisv.sys
2007-10-31 00:55 35,120 —-a-w C:\WINDOWS\system32\drivers\symndis.sys
2007-10-31 00:55 27,696 —-a-w C:\WINDOWS\system32\drivers\symredrv.sys
2007-10-31 00:55 242,056 —-a-w C:\WINDOWS\system32\SymRedir.dll
2007-10-31 00:55 191,536 —-a-w C:\WINDOWS\system32\drivers\symtdi.sys
2007-10-31 00:55 145,968 —-a-w C:\WINDOWS\system32\drivers\symfw.sys
2007-10-31 00:55 12,848 —-a-w C:\WINDOWS\system32\drivers\symdns.sys
2007-10-31 00:24 12,963 —-a-w C:\WINDOWS\system32\drivers\SymRedir.cat
2007-10-31 00:24 1,358 —-a-w C:\WINDOWS\system32\drivers\SymRedir.inf
2007-10-29 15:30 ——— d—–w C:\Program Files\Common Files\Adobe
2007-10-27 22:29 ——— d—–w C:\Documents and Settings\paul\Application Data\InterVideo
2007-10-24 21:43 ——— d—–w C:\Program Files\Java
2007-10-24 21:43 ——— d—–w C:\Program Files\Common Files\Java
2007-10-23 22:33 ——— d—–w C:\Program Files\Neopets
2007-10-23 22:33 ——— d—–w C:\Documents and Settings\paul\Application Data\Neopets Toolbar
2007-10-23 16:47 ——— d–h–w C:\Documents and Settings\All Users\Application Data\CanonBJ
2007-10-22 19:38 ——— d—–w C:\Program Files\Common Files\logishrd
2007-10-22 19:22 ——— d—–w C:\Program Files\SlySoft
2007-10-20 19:29 96,832 —-a-w C:\WINDOWS\system32\drivers\AnyDVD.sys
2007-10-18 09:06 156,992 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-10-16 22:40 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-16 22:02 ——— d—–w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-10-16 20:34 ——— d—–w C:\Program Files\Common Files\Macrovision Shared
2007-10-15 15:49 ——— d—–w C:\Program Files\InterVideo
2007-10-13 14:27 ——— d—–w C:\Documents and Settings\paul\Application Data\TuneUp Software
2007-10-13 11:40 ——— d—–w C:\Program Files\MSXML 4.0
2007-10-13 03:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\vsosdk
2007-10-12 21:45 ——— d—–w C:\Program Files\Real
2007-10-12 21:45 ——— d—–w C:\Program Files\Common Files\xing shared
2007-10-12 21:45 ——— d—–w C:\Program Files\Common Files\Real
2007-10-12 21:39 ——— d—–w C:\Program Files\InterVideo Information Service
2007-10-12 21:39 ——— d—–w C:\Program Files\Common Files\Ulead
2007-10-12 21:38 ——— d—–w C:\Program Files\Common Files\InterVideo
2007-10-12 21:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-10-12 21:21 47,360 —-a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2007-10-12 21:21 47,360 —-a-w C:\Documents and Settings\paul\Application Data\pcouffin.sys
2007-10-12 21:21 ——— d—–w C:\Program Files\VSO
2007-10-12 20:48 ——— d—–w C:\Documents and Settings\paul\Application Data\Nero
2007-10-12 20:45 ——— d—–w C:\Program Files\Nero
2007-10-12 20:01 ——— d—–w C:\Documents and Settings\All Users\Application Data\Elaborate Bytes
2007-10-12 19:55 ——— d—–w C:\Program Files\Alcohol Soft
2007-10-12 19:53 685,816 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-10-12 19:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\SlySoft
2007-10-11 19:39 ——— d—–w C:\Program Files\uTorrent
2007-10-11 19:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-10-11 02:01 ——— d—–w C:\Program Files\Google
2007-10-11 00:36 ——— d—–w C:\Program Files\microsoft frontpage
2007-10-10 22:31 ——— d—–w C:\Documents and Settings\paul\Application Data\InterTrust
2007-10-10 22:28 ——— d—–w C:\Program Files\Intel
2007-10-04 22:14 81,920 —-a-w C:\WINDOWS\system32\nvwddi.dll
2007-10-04 22:14 81,920 —-a-w C:\WINDOWS\system32\nvmctray.dll
2007-10-04 22:14 8,491,008 —-a-w C:\WINDOWS\system32\nvcpl.dll
2007-10-04 22:14 753,664 —-a-w C:\WINDOWS\system32\nvcplui.exe
2007-10-04 22:14 6,854,464 —-a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-10-04 22:14 6,750,208 —-a-w C:\WINDOWS\system32\nvoglnt.dll
2007-10-04 22:14 6,344,704 —-a-w C:\WINDOWS\system32\nvdisps.dll
2007-10-04 22:14 5,783,424 —-a-w C:\WINDOWS\system32\nv4_disp.dll
2007-10-04 22:14 466,944 —-a-w C:\WINDOWS\system32\nvshell.dll
2007-10-04 22:14 45,056 —-a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-10-04 22:14 442,368 —-a-w C:\WINDOWS\system32\nvappbar.exe
2007-10-04 22:14 425,984 —-a-w C:\WINDOWS\system32\keystone.exe
2007-10-04 22:14 364,544 —-a-w C:\WINDOWS\system32\nvapi.dll
2007-10-04 22:14 36,864 —-a-w C:\WINDOWS\system32\nvcodins.dll
2007-10-04 22:14 36,864 —-a-w C:\WINDOWS\system32\nvcod.dll
2007-10-04 22:14 307,200 —-a-w C:\WINDOWS\system32\nvexpbar.dll
2007-10-04 22:14 3,551,232 —-a-w C:\WINDOWS\system32\nvvitvs.dll
2007-10-04 22:14 3,334,144 —-a-w C:\WINDOWS\system32\nvgames.dll
2007-10-04 22:14 286,720 —-a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-10-04 22:14 229,376 —-a-w C:\WINDOWS\system32\nvmccs.dll
2007-10-04 22:14 2,371,584 —-a-w C:\WINDOWS\system32\nvwss.dll
2007-10-04 22:14 188,416 —-a-w C:\WINDOWS\system32\nvmccss.dll
2007-10-04 22:14 155,716 —-a-w C:\WINDOWS\system32\nvsvc32.exe
2007-10-04 22:14 147,456 —-a-w C:\WINDOWS\system32\nvcolor.exe
2007-10-04 22:14 1,703,936 —-a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-10-04 22:14 1,626,112 —-a-w C:\WINDOWS\system32\nwiz.exe
2007-10-04 22:14 1,478,656 —-a-w C:\WINDOWS\system32\nview.dll
2007-10-04 22:14 1,339,392 —-a-w C:\WINDOWS\system32\nvdspsch.exe
2007-10-04 22:14 1,150,976 —-a-w C:\WINDOWS\system32\nvmobls.dll
2007-10-04 22:14 1,019,904 —-a-w C:\WINDOWS\system32\nvwimg.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A477EBE4-ABE9-4A9D-B1B4-0EB1D0D025CE}]
2007-11-24 10:53 319488 –a—— C:\WINDOWS\werbetdqw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{85B2F289-7128-4C5A-A330-F9FC01432D3A}"= C:\WINDOWS\hdtip.dll [2007-11-24 10:53 188416]

[HKEY_CLASSES_ROOT\clsid\{85b2f289-7128-4c5a-a330-f9fc01432d3a}]
[HKEY_CLASSES_ROOT\hdtip.ToolBar.1]
[HKEY_CLASSES_ROOT\TypeLib\{AE73C3E4-88F7-41A0-AF79-87BE6826B8DF}]
[HKEY_CLASSES_ROOT\hdtip.ToolBar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" []
"µTorrent"="C:\Program Files\uTorrent\utorrent.exe" [2006-07-02 11:29]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"RogersAgent"="c:\Program Files\Rogers\SelfHealing\rogersagent.exe" [2007-04-23 15:51]
"SHS"="C:\Program Files\Rogers\SelfHealing\SHS.exe" [2007-10-12 15:30]
"Update Manager"="C:\Program Files\Rogers\Update Manager\UpdateManager.exe" [2007-10-12 15:30]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2007-11-09 13:50]
"APC"="C:\Program Files\Advanced Parental Control\BackProcessAPC.exe" [2007-04-20 16:25]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Media Codec Update Service"="C:\Program Files\Essentials Codec Pack\update.exe" []
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" []
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 16:34]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-12 16:45]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 14:21]
"VirtualCloneDrive"="C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 08:21]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2007-06-26 13:48]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 00:59]
"osCheck"="C:\PROGRA~1\Symantec\osCheck.exe" [2007-01-14 02:11]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 20:16]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 02:56 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2007-10-04 17:14 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-04 02:56 C:\WINDOWS\system32\rundll32.exe]
"APC"="C:\Program Files\Advanced Parental Control\BackProcessAPC.exe" [2007-04-20 16:25]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv.exe" [2004-08-04 02:56 C:\WINDOWS\system32\grpconv.exe]
"IERESETATTRIB"="C:\WINDOWS\system32\cmd.exe" [2004-08-04 02:56]
"IERESETICONS"="C:\WINDOWS\system32\cmd.exe" [2004-08-04 02:56]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 00:48:20]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-22 23:01:50]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-10-15 10:50:00]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"gormet"= {DD62F780-5BA0-4601-A18F-AF3AF04FB347} - C:\WINDOWS\gormet.dll [2007-11-24 10:52 331776]
"pmkret"= {26E19283-B48D-438D-9B74-FAE15B41BCDF} - C:\WINDOWS\pmkret.dll [2007-11-24 10:52 282112]

R0 iviVD;iviVD;C:\WINDOWS\system32\DRIVERS\iviVD.sys
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-11-24 22:09:45 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2007-11-20 01:44:18 C:\WINDOWS\Tasks\Norton Security Online - Run Full System Scan - paul.job"
- C:\PROGRA~1\Symantec\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-25 16:53:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-25 16:54:08
C:\ComboFix2.txt … 2007-11-25 16:30
.
— E O F —
and this is the new hijack this log i got after i did those steps, the posts looked so huge i decided to put the logs in seperate posts.


Also The background pic is now gone but it is now white, and when i right click to change it it doesnt give me the normal options and its properties say… file://C:\WINDOWS\privacy_danger\index.htm and some other things, and when i search for that on my comp it says it may be on a hard drive or network or something i dont know

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:57:11 PM, on 11/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 SP2 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\paul\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: MSVPS System - {A477EBE4-ABE9-4A9D-B1B4-0EB1D0D025CE} - C:\WINDOWS\werbetdqw.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Neopets - {CD292324-974F-4224-D074-CACA427AA030} - C:\PROGRA~1\Neopets\Toolbar\Toolbar.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Neopets - {CD292324-974F-4224-D074-CACA427AA030} - C:\PROGRA~1\Neopets\Toolbar\Toolbar.dll
O3 - Toolbar: The hdtip - {85B2F289-7128-4C5A-A330-F9FC01432D3A} - C:\WINDOWS\hdtip.dll
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [APC] C:\Program Files\Advanced Parental Control\BackProcessAPC.exe
O4 - HKLM\..\RunOnce: [GrpConv] grpconv.exe -o
O4 - HKLM\..\RunOnce: [IERESETATTRIB] %SystemRoot%\system32\cmd.exe /d /q /c %SystemRoot%\system32\ieudinit.exe -ResetFileAttributes
O4 - HKLM\..\RunOnce: [IERESETICONS] %SystemRoot%\system32\cmd.exe /d /q /c %SystemRoot%\iereseticons.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [µTorrent] "C:\Program Files\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RogersAgent] c:\Program Files\Rogers\SelfHealing\rogersagent.exe
O4 - HKCU\..\Run: [SHS] "C:\Program Files\Rogers\SelfHealing\SHS.exe" /background
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [APC] C:\Program Files\Advanced Parental Control\BackProcessAPC.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\paul\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe
O21 - SSODL: gormet - {DD62F780-5BA0-4601-A18F-AF3AF04FB347} - C:\WINDOWS\gormet.dll
O21 - SSODL: pmkret - {26E19283-B48D-438D-9B74-FAE15B41BCDF} - C:\WINDOWS\pmkret.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

–
End of file - 10106 bytes
thought I had gotten rid of it but its back. I noticed someone with the same problem so i followed half of their directions someone gave them plus my dad gave me this start up cop program to help and i tried deleting things on my own from my hijackthins thingy and it was fine, but the pop ups and the background changing to that biohazard thing is now back. If someone is online can you please help, ive been feeling ignored all day when tons of people who asked their question after me got answers and i did not. Ive done everything i could think of to try to resolve this myself but nothing.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI