This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Can't Beat it

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Unfortunately for me, if been here before so I somewhat know the drill.
I bought an all-in-one computer program for spyware, anti-virus and the like at the first sign of trouble. I thougth it was time to update anyway but it turned out to be a bust. It was DefenderPro 2008 and it did absolutely dick.

I followed the self-help, "before you post insturctions" but I had some difficulty completing them.
I've downloaded ATF cleaner and it sorted out just fine.
The spybot went ok but it was unable to delete a few red files that it had found.
I didn't even get a chance to run the AVG-Anti-spyware because I have no control over my computer when it is in safe mode. I keep getting a DOS box labeled "C:\WINDOWS\shell.exe" and an accomponying error message that refuses to go away. I also get a message that asks if I want to continue is safe mode or use system restore. I say continue but it keeps coming back. Also, the start bar and desktop icons come and go during the start up and end up gone leaving me with no options but to shut down my computer manually.

When I got the this portion of the post, my desktop icons and start bar disappeared. I emailed myself the HJT log as an attachment so i could paste it here for you. Thanks for the help..i need it…

Logfile of HijackThis v1.99.1
Scan saved at 7:04:37 PM, on 11/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DefenderPro\TSAntiSpy.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\emsfnekk.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\nuiesgif.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…age=www.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\shell.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [winshow] "C:\WINDOWS\winshow.exe"
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu77.exe 61A847B5BBF72815358B2B27128065E9C084320161C4661227A755E9C2933154389A
O4 - HKLM\..\Run: [bexqzihi] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\bexqzihi.dll"
O4 - HKLM\..\Run: [Printer] C:\WINDOWS\system32\printer.exe
O4 - HKLM\..\Run: [LaunchAntiSpy] C:\Program Files\DefenderPro\TSAntiSpy.exe /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [bc95ab82] rundll32.exe "C:\WINDOWS\system32\oparngjp.dll",b
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [Spoolsv] C:\WINDOWS\system32\spoolvs.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: findfast.exe
O4 - Global Startup: autorun.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: E404Helper - {8906b1e9-98d7-4fce-8972-b372afe3d301} - e404d.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\emsfnekk.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
Your system is badly infected and may require a full format and reinstall.
I will not be able to promise to be able to clean everything that's bad.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:

Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
That's not great news but I hope we can fix it. Here's the log files.

Logfile of HijackThis v1.99.1
Scan saved at 8:36:06 PM, on 12/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…age=www.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {559D61D8-A64A-4677-9DB6-ACE525EC9514} - (no file)
O2 - BHO: (no name) - {7722642D-C56A-55E4-6E7E-07D5462CC3EE} - C:\Program Files\Psdjvtoc\yfetudro.dll
O2 - BHO: (no name) - {7B6E3CD8-7C3E-4130-B012-A9553EDB4C67} - (no file)
O2 - BHO: (no name) - {9319C22D-66F6-4A87-9755-0E2FABFA1847} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LaunchAntiSpy] C:\Program Files\DefenderPro\TSAntiSpy.exe /startup
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Spoolsv] C:\WINDOWS\system32\spoolvs.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: opnmmli - opnmmli.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: E404Helper - {8906b1e9-98d7-4fce-8972-b372afe3d301} - e404d.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe



COMBO FIX
ComboFix 07-12-02.6 - Anderson Minnick 2007-12-03 19:52:17.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.514 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\check_LSA7.txt
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe
C:\Documents and Settings\Anderson Minnick\Application Data\Def\CnsMin.prf
C:\Documents and Settings\Anderson Minnick\Start Menu\Programs\Startup\findfast.exe
C:\Program Files\3269.exe
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe.bak
C:\Program Files\ucleaner_setup.exe
C:\Program Files\Windows Media Player\hokemory555077.dll
C:\Program Files\xloader10181.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\abW9
C:\Temp\abW9\tPho.log
C:\temp\tn3
C:\WINDOWS\cookies.ini
C:\WINDOWS\dobe~1
C:\WINDOWS\dobe~1\?dobe\
C:\WINDOWS\shell.exe
C:\WINDOWS\system32\buxioksj.ini
C:\WINDOWS\system32\c1
C:\WINDOWS\system32\ccnaxxop.exe
C:\WINDOWS\system32\cflfkhaw.dll
C:\WINDOWS\system32\cmiefxmi.dll
C:\WINDOWS\system32\cohxlpyc.exe
C:\WINDOWS\system32\dnpqiphi.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\emsfnekk.exe
C:\WINDOWS\system32\eqgdtnni.dll
C:\WINDOWS\system32\esowcgvt.exe
C:\WINDOWS\system32\fjtnvvxp.exe
C:\WINDOWS\system32\gaungwei.ini
C:\WINDOWS\system32\gptytqhv.dll
C:\WINDOWS\system32\hkeopole.dll
C:\WINDOWS\system32\hsdqphuw.exe
C:\WINDOWS\system32\iewgnuag.dll
C:\WINDOWS\system32\iveirjxj.dll
C:\WINDOWS\system32\iyfafcoq.exe
C:\WINDOWS\system32\j2
C:\WINDOWS\system32\j2\ppjup83122.exe
C:\WINDOWS\system32\jjkkj.bak1
C:\WINDOWS\system32\jjkkj.bak2
C:\WINDOWS\system32\jjkkj.ini
C:\WINDOWS\system32\jjkkj.ini2
C:\WINDOWS\system32\jjkkj.tmp
C:\WINDOWS\system32\jkkjj.dll
C:\WINDOWS\system32\jskoixub.dll
C:\WINDOWS\system32\khkuevaq.ini
C:\WINDOWS\system32\kwqwvgfb.dll
C:\WINDOWS\system32\lbbuwweo.dll
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\lgiydgmn.dll
C:\WINDOWS\system32\lvixehjt.dll
C:\WINDOWS\system32\m8
C:\WINDOWS\system32\m8\nsts2dll1.exe
C:\WINDOWS\system32\nuiesgif.exe
C:\WINDOWS\system32\nyistnkk.exe
C:\WINDOWS\system32\ovesngnh.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\povexsqn.exe
C:\WINDOWS\system32\printer.exe
C:\WINDOWS\system32\qaveukhk.dll
C:\WINDOWS\system32\qushqxgg.exe
C:\WINDOWS\system32\rlojhocl.exe
C:\WINDOWS\system32\rMa02yy
C:\WINDOWS\system32\sohwinsy.dll
C:\WINDOWS\system32\spoolvs.exe
C:\WINDOWS\system32\tjhexivl.ini
C:\WINDOWS\system32\towlhsbu.dll
C:\WINDOWS\system32\tpcwdoia
C:\WINDOWS\system32\tpcwdoia\bg1.gif
C:\WINDOWS\system32\tpcwdoia\bgtop.gif
C:\WINDOWS\system32\tpcwdoia\bottom1.gif
C:\WINDOWS\system32\tpcwdoia\essentials.gif
C:\WINDOWS\system32\tpcwdoia\icon1.ico
C:\WINDOWS\system32\tpcwdoia\install1.gif
C:\WINDOWS\system32\tpcwdoia\left1.gif
C:\WINDOWS\system32\tpcwdoia\li.gif
C:\WINDOWS\system32\tpcwdoia\logo.gif
C:\WINDOWS\system32\tpcwdoia\main.htm
C:\WINDOWS\system32\tpcwdoia\mainframe.htm
C:\WINDOWS\system32\tpcwdoia\reinstall1.gif
C:\WINDOWS\system32\tpcwdoia\right1.gif
C:\WINDOWS\system32\tpcwdoia\s1.htm
C:\WINDOWS\system32\tpcwdoia\s2.htm
C:\WINDOWS\system32\tpcwdoia\s3.htm
C:\WINDOWS\system32\tpcwdoia\SMTop1.gif
C:\WINDOWS\system32\tpcwdoia\SMTop2.gif
C:\WINDOWS\system32\tpcwdoia\SMTop3.gif
C:\WINDOWS\system32\tpcwdoia\SMTop4.gif
C:\WINDOWS\system32\tpcwdoia\soft1_off.gif
C:\WINDOWS\system32\tpcwdoia\soft1_off_ext.gif
C:\WINDOWS\system32\tpcwdoia\soft1_on.gif
C:\WINDOWS\system32\tpcwdoia\soft1_on_ext.gif
C:\WINDOWS\system32\tpcwdoia\soft2_off.gif
C:\WINDOWS\system32\tpcwdoia\soft2_off_ext.gif
C:\WINDOWS\system32\tpcwdoia\soft2_on.gif
C:\WINDOWS\system32\tpcwdoia\soft2_on_ext.gif
C:\WINDOWS\system32\tpcwdoia\soft3_off.gif
C:\WINDOWS\system32\tpcwdoia\soft3_off_ext.gif
C:\WINDOWS\system32\tpcwdoia\soft3_on.gif
C:\WINDOWS\system32\tpcwdoia\soft3_on_ext.gif
C:\WINDOWS\system32\tpcwdoia\softbottom_off.gif
C:\WINDOWS\system32\tpcwdoia\softbottom_on.gif
C:\WINDOWS\system32\tpcwdoia\softleft_off.gif
C:\WINDOWS\system32\tpcwdoia\softleft_on.gif
C:\WINDOWS\system32\tpcwdoia\top1.gif
C:\WINDOWS\system32\tpcwdoia\top2.gif
C:\WINDOWS\system32\tpcwdoia\tpcwdoia1.exe
C:\WINDOWS\system32\tpcwdoia\tpcwdoia2.exe
C:\WINDOWS\system32\tpcwdoia\tpcwdoia3.exe
C:\WINDOWS\system32\tpcwdoia\turnoff1.gif
C:\WINDOWS\system32\tpcwdoia\turnon1.gif
C:\WINDOWS\system32\vawllrvf.dll
C:\WINDOWS\system32\xdbvigdj.dll
C:\WINDOWS\system32\yevcyhlk.exe
C:\WINDOWS\tk58.exe
C:\WINDOWS\TTC-4444.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CORE
——-\LEGACY_DOMAINSERVICE
——-\core
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.

2007-12-03 09:16 . 2007-12-03 09:16 73,280 –a—— C:\WINDOWS\system32\pbvfehbr.dll
2007-12-01 14:11 . 2007-12-02 14:28 793,673 –ahs—- C:\WINDOWS\system32\mxfcjwts.ini
2007-11-29 18:30 . 2007-11-29 18:30 d——– C:\Documents and Settings\Anderson Minnick\Application Data\Grisoft
2007-11-29 18:30 . 2007-11-29 18:30 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-29 18:30 . 2007-05-30 07:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-29 15:24 . 2007-11-29 15:25 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-29 15:15 . 2007-11-29 18:45 789,968 –ahs—- C:\WINDOWS\system32\pjgnrapo.ini
2007-11-29 15:13 . 2007-12-03 19:56 d——– C:\Documents and Settings\Anderson Minnick\Application Data\Def
2007-11-29 15:13 . 2007-11-29 15:13 d——– C:\Documents and Settings\Anderson Minnick\Application Data\Bin
2007-11-29 11:14 . 2007-11-29 15:12 790,141 –ahs—- C:\WINDOWS\system32\xmxunpds.ini
2007-11-28 20:00 . 2007-11-29 11:14 789,418 –ahs—- C:\WINDOWS\system32\cfwulrgu.ini
2007-11-28 18:53 . 2007-11-29 18:37 0 –a—— C:\WINDOWS\system32\mcrh.tmp
2007-11-28 18:52 . 2007-11-28 18:52 90 –ahs—- C:\WINDOWS\klif.spi
2007-11-28 13:13 . 2007-11-28 13:13 d——– C:\WINDOWS\AntiSpy
2007-11-28 13:13 . 2007-11-29 12:00 137 –a—— C:\WINDOWS\tsiwinfile.dat
2007-11-28 13:09 . 2007-11-28 13:09 789,349 –ahs—- C:\WINDOWS\system32\uwdmlncc.ini
2007-11-27 20:00 . 2007-11-27 20:00 3,120 –a—— C:\WINDOWS\system32\DRWSJLAD.ocx
2007-11-27 20:00 . 2007-11-27 20:00 3,120 –a—— C:\WINDOWS\LJRGKDD9.ocx
2007-11-27 19:59 . 2007-11-29 11:24 d——– C:\Program Files\Defender Pro
2007-11-27 19:59 . 2007-11-28 20:00 d——– C:\Documents and Settings\All Users\Application Data\Defender Pro
2007-11-27 18:12 . 2007-11-27 18:24 10,240 –a—— C:\Program Files\spoolsv.exe
2007-11-27 18:11 . 2007-11-27 18:11 d——– C:\Program Files\Psdjvtoc
2007-11-27 18:11 . 2007-11-29 16:20 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2007-11-27 18:10 . 2007-11-27 18:10 1,149,472 –a—— C:\Install
2007-11-27 18:10 . 2007-11-27 18:10 123 –a—— C:\Documents and Settings\Anderson Minnick\mit.bat
2007-11-27 17:45 . 2007-11-27 18:12 d——– C:\Program Files\Mozilla Sunbird
2007-11-27 17:45 . 2007-11-27 17:45 d——– C:\Documents and Settings\Anderson Minnick\Application Data\Talkback
2007-11-25 17:51 . 2007-11-25 17:51 d——– C:\Documents and Settings\Anderson Minnick\Application Data\CyberLink
2007-11-24 21:16 . 2007-11-24 21:16 d——– C:\Documents and Settings\Anderson Minnick\Application Data\vlc
2007-11-24 20:44 . 2007-11-24 20:44 d——– C:\Documents and Settings\Anderson Minnick\Application Data\dvdcss
2007-11-24 20:42 . 2007-11-24 20:42 d——– C:\Program Files\Windows Media Bonus Pack for Windows XP
2007-11-24 20:42 . 2007-11-24 20:42 d——– C:\Program Files\VideoLAN
2007-11-24 20:42 . 2001-11-30 19:05 131,072 –a—— C:\WINDOWS\system32\dzip32.dll
2007-11-24 20:42 . 2001-11-30 19:05 110,592 –a—— C:\WINDOWS\system32\dunzip32.dll
2007-11-22 21:41 . 2007-11-22 21:42 d——– C:\Documents and Settings\Anderson Minnick\Application Data\DivX
2007-11-22 21:38 . 2007-11-28 19:13 d——– C:\Program Files\DivX
2007-11-22 21:38 . 2007-10-19 19:56 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2007-11-22 21:38 . 2007-10-19 19:56 9,464 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-22 21:38 . 2007-10-19 19:56 9,336 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-21 23:52 . 2007-11-21 23:52 0 –a—— C:\WINDOWS\tosOBEX.INI
2007-11-21 23:51 . 2007-11-21 23:51 d——– C:\Documents and Settings\Anderson Minnick\Application Data\Toshiba
2007-11-12 14:37 . 2007-11-12 14:37 d——– C:\Program Files\BitTorrent_DNA
2007-11-12 14:37 . 2007-12-03 19:58 d——– C:\Documents and Settings\Anderson Minnick\Application Data\BitTorrent DNA
2007-11-12 14:37 . 2007-11-24 20:45 d——– C:\Documents and Settings\Anderson Minnick\Application Data\BitTorrent
2007-11-11 16:28 . 2007-11-11 16:28 155,136 –a—— C:\WINDOWS\Doc1.doc
2007-11-09 13:11 . 2007-11-09 13:11 d——– C:\Program Files\iPod

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-29 00:13 ——— d—–w C:\Program Files\QuickTime
2007-11-29 00:13 ——— d—–w C:\Program Files\Modem Helper
2007-11-29 00:13 ——— d—–w C:\Program Files\Dell
2007-11-09 18:11 ——— d—–w C:\Program Files\iTunes
2007-10-29 17:40 ——— d—–w C:\Documents and Settings\Anderson Minnick\Application Data\MusicUploader
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-20 00:56 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2007-10-20 00:56 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-10-20 00:56 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2007-10-20 00:56 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2007-10-20 00:56 120,056 —-a-w C:\WINDOWS\system32\pxcpyi64.exe
2007-10-20 00:56 118,520 —-a-w C:\WINDOWS\system32\pxinsi64.exe
2007-10-20 00:56 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2007-10-20 00:54 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-10-20 00:54 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2007-10-20 00:54 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2007-10-20 00:54 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2007-10-20 00:54 739,840 —-a-w C:\WINDOWS\system32\DivX.dll
2007-10-20 00:54 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2007-10-18 09:06 156,992 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-10-18 09:03 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-10-18 09:03 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2007-10-18 09:03 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-10-18 09:03 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2007-10-18 09:03 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2007-10-18 09:03 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
2007-10-18 09:02 12,288 —-a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-10-10 01:40 ——— d—–w C:\Documents and Settings\Anderson Minnick\Application Data\Apple Computer
2007-10-07 17:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-05 22:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL OCP
2007-10-05 22:18 ——— d—–w C:\Program Files\AIM6
2007-10-05 22:18 ——— d—–w C:\Documents and Settings\Anderson Minnick\Application Data\acccore
2007-10-05 22:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-10-05 22:16 ——— d—–w C:\Program Files\Common Files\AOL
2007-10-04 20:51 ——— d—–w C:\Program Files\AxBx
2007-09-12 18:52 53,248 —-a-w C:\WINDOWS\hg173.exe
2007-09-12 18:50 53,248 —-a-w C:\WINDOWS\df87173.exe
2006-12-03 01:05 2,522 —-a-w C:\Program Files\func.js
2006-11-25 07:57 482 —-a-w C:\Program Files\Del.js
2005-07-29 21:24 472 –sha-r C:\WINDOWS\TWFydGluIE1pbm5pY2s\nqIVx35RKHYDvAcDsZP.vbs
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CB8F4B4-5F66-4D9E-BC3B-184596A58824}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{559D61D8-A64A-4677-9DB6-ACE525EC9514}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7722642D-C56A-55E4-6E7E-07D5462CC3EE}]
2007-11-27 18:11 110592 –a—— C:\Program Files\Psdjvtoc\yfetudro.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7B6E3CD8-7C3E-4130-B012-A9553EDB4C67}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9319C22D-66F6-4A87-9755-0E2FABFA1847}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A48A15DA-A31A-4403-ACE2-09B450EBA9FF}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FCD85C5E-B272-4CB8-9B01-38CE170A14A9}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 18:44]
"Aim6"="" []
"BitTorrent DNA"="C:\Program Files\BitTorrent_DNA\dna.exe" [2007-11-12 14:37]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 16:33]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 14:59]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-03 21:00]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-03-04 11:26]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-10 13:51]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"LaunchAntiSpy"="C:\Program Files\DefenderPro\TSAntiSpy.exe" []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-22 13:42:22]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-06-03 01:22:01]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"E404Helper"= {8906b1e9-98d7-4fce-8972-b372afe3d301} - e404d.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 16:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnmmli]
opnmmli.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchIndexer]
rundll32.exe C:\WINDOWS\system32\hgcessog.dll,sitypnow

S1 SAVOnAccessControl;SAVOnAccessControl;C:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys
S1 SAVOnAccessFilter;SAVOnAccessFilter;C:\WINDOWS\system32\DRIVERS\savonaccessfilter.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-11-28 18:15:36 C:\WINDOWS\Tasks\AntiSpy.job"
- C:\Program Files\DefenderPro\TSAntiSpy.exe
"2007-11-15 18:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-04 00:57:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-03 20:00:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-03 20:01:28 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-10-07 13:13
C:\ComboFix2.txt … 2007-10-07 13:13
.
— E O F —

Thank you very much for your help. What's the next step?
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\pbvfehbr.dll
C:\WINDOWS\system32\mxfcjwts.ini
C:\WINDOWS\system32\pjgnrapo.ini
C:\WINDOWS\system32\xmxunpds.ini
C:\WINDOWS\system32\cfwulrgu.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\uwdmlncc.ini
C:\WINDOWS\system32\DRWSJLAD.ocx
C:\WINDOWS\LJRGKDD9.ocx
C:\Documents and Settings\Anderson Minnick\mit.bat
C:\Program Files\spoolsv.exe
C:\WINDOWS\tosOBEX.INI
C:\WINDOWS\hg173.exe
C:\WINDOWS\df87173.exe
C:\WINDOWS\TWFydGluIE1pbm5pY2s\nqIVx35RKHYDvAcDsZP.vbs
C:\Program Files\Psdjvtoc\yfetudro.dll
C:\WINDOWS\system32\hgcessog.dll

Folder::
C:\Program Files\Psdjvtoc
C:\Documents and Settings\All Users\Application Data\Rabio
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\Program Files\AxBx

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CB8F4B4-5F66-4D9E-BC3B-184596A58824}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{559D61D8-A64A-4677-9DB6-ACE525EC9514}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7722642D-C56A-55E4-6E7E-07D5462CC3EE}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7B6E3CD8-7C3E-4130-B012-A9553EDB4C67}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9319C22D-66F6-4A87-9755-0E2FABFA1847}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A48A15DA-A31A-4403-ACE2-09B450EBA9FF}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FCD85C5E-B272-4CB8-9B01-38CE170A14A9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"E404Helper"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnmmli]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchIndexer]


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
My computer is behaving much better (Kind of makes it sound like a delinquent child, doesn't it?). My Desktop picture has returned and I wasn't greeted with the plethora or command prompts with fatal errors. So far so good. Here are the logs; is there anything else?


ComboFix:


ComboFix 07-12-02.6 - Anderson Minnick 2007-12-04 11:29:24.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.643 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Anderson Minnick\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\Documents and Settings\Anderson Minnick\mit.bat
C:\Program Files\Psdjvtoc\yfetudro.dll
C:\Program Files\spoolsv.exe
C:\WINDOWS\df87173.exe
C:\WINDOWS\hg173.exe
C:\WINDOWS\LJRGKDD9.ocx
C:\WINDOWS\system32\cfwulrgu.ini
C:\WINDOWS\system32\DRWSJLAD.ocx
C:\WINDOWS\system32\hgcessog.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mxfcjwts.ini
C:\WINDOWS\system32\pbvfehbr.dll
C:\WINDOWS\system32\pjgnrapo.ini
C:\WINDOWS\system32\uwdmlncc.ini
C:\WINDOWS\system32\xmxunpds.ini
C:\WINDOWS\tosOBEX.INI
C:\WINDOWS\TWFydGluIE1pbm5pY2s\nqIVx35RKHYDvAcDsZP.vbs
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Rabio
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\Documents and Settings\Anderson Minnick\mit.bat
C:\Program Files\AxBx
C:\Program Files\AxBx\VirusKeeper 2007 Pro Trial\Quarantaine\sejvmrub.exe
C:\Program Files\Psdjvtoc
C:\Program Files\Psdjvtoc\yfetudro.dll
C:\Program Files\spoolsv.exe
C:\WINDOWS\df87173.exe
C:\WINDOWS\hg173.exe
C:\WINDOWS\LJRGKDD9.ocx
C:\WINDOWS\system32\cfwulrgu.ini
C:\WINDOWS\system32\DRWSJLAD.ocx
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mxfcjwts.ini
C:\WINDOWS\system32\pbvfehbr.dll
C:\WINDOWS\system32\pjgnrapo.ini
C:\WINDOWS\system32\uwdmlncc.ini
C:\WINDOWS\system32\xmxunpds.ini
C:\WINDOWS\tosOBEX.INI
C:\WINDOWS\TWFydGluIE1pbm5pY2s\nqIVx35RKHYDvAcDsZP.vbs

.
((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.

2007-11-29 18:30 . 2007-11-29 18:30 d——– C:\Documents and Settings\Anderson Minnick\Application Data\Grisoft
2007-11-29 18:30 . 2007-11-29 18:30 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-29 18:30 . 2007-05-30 07:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-29 15:24 . 2007-11-29 15:25 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-29 15:13 . 2007-12-03 19:56 d——– C:\Documents and Settings\Anderson Minnick\Application Data\Def
2007-11-29 15:13 . 2007-11-29 15:13 d——– C:\Documents and Settings\Anderson Minnick\Application Data\Bin
2007-11-28 18:52 . 2007-11-28 18:52 90 –ahs—- C:\WINDOWS\klif.spi
2007-11-28 13:13 . 2007-11-28 13:13 d——– C:\WINDOWS\AntiSpy
2007-11-28 13:13 . 2007-11-29 12:00 137 –a—— C:\WINDOWS\tsiwinfile.dat
2007-11-27 19:59 . 2007-11-29 11:24 d——– C:\Program Files\Defender Pro
2007-11-27 19:59 . 2007-11-28 20:00 d——– C:\Documents and Settings\All Users\Application Data\Defender Pro
2007-11-27 18:10 . 2007-11-27 18:10 1,149,472 –a—— C:\Install
2007-11-27 17:45 . 2007-11-27 18:12 d——– C:\Program Files\Mozilla Sunbird
2007-11-27 17:45 . 2007-11-27 17:45 d——– C:\Documents and Settings\Anderson Minnick\Application Data\Talkback
2007-11-25 17:51 . 2007-11-25 17:51 d——– C:\Documents and Settings\Anderson Minnick\Application Data\CyberLink
2007-11-24 21:16 . 2007-11-24 21:16 d——– C:\Documents and Settings\Anderson Minnick\Application Data\vlc
2007-11-24 20:44 . 2007-11-24 20:44 d——– C:\Documents and Settings\Anderson Minnick\Application Data\dvdcss
2007-11-24 20:42 . 2007-11-24 20:42 d——– C:\Program Files\Windows Media Bonus Pack for Windows XP
2007-11-24 20:42 . 2007-11-24 20:42 d——– C:\Program Files\VideoLAN
2007-11-24 20:42 . 2001-11-30 19:05 131,072 –a—— C:\WINDOWS\system32\dzip32.dll
2007-11-24 20:42 . 2001-11-30 19:05 110,592 –a—— C:\WINDOWS\system32\dunzip32.dll
2007-11-22 21:41 . 2007-11-22 21:42 d——– C:\Documents and Settings\Anderson Minnick\Application Data\DivX
2007-11-22 21:38 . 2007-11-28 19:13 d——– C:\Program Files\DivX
2007-11-22 21:38 . 2007-10-19 19:56 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2007-11-22 21:38 . 2007-10-19 19:56 9,464 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-22 21:38 . 2007-10-19 19:56 9,336 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-21 23:51 . 2007-11-21 23:51 d——– C:\Documents and Settings\Anderson Minnick\Application Data\Toshiba
2007-11-12 14:37 . 2007-11-12 14:37 d——– C:\Program Files\BitTorrent_DNA
2007-11-12 14:37 . 2007-12-04 11:31 d——– C:\Documents and Settings\Anderson Minnick\Application Data\BitTorrent DNA
2007-11-12 14:37 . 2007-11-24 20:45 d——– C:\Documents and Settings\Anderson Minnick\Application Data\BitTorrent
2007-11-11 16:28 . 2007-11-11 16:28 155,136 –a—— C:\WINDOWS\Doc1.doc
2007-11-09 13:11 . 2007-11-09 13:11 d——– C:\Program Files\iPod

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-29 00:13 ——— d—–w C:\Program Files\QuickTime
2007-11-29 00:13 ——— d—–w C:\Program Files\Modem Helper
2007-11-29 00:13 ——— d—–w C:\Program Files\Dell
2007-11-09 18:11 ——— d—–w C:\Program Files\iTunes
2007-10-29 17:40 ——— d—–w C:\Documents and Settings\Anderson Minnick\Application Data\MusicUploader
2007-10-20 00:56 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-10-10 01:40 ——— d—–w C:\Documents and Settings\Anderson Minnick\Application Data\Apple Computer
2007-10-05 22:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL OCP
2007-10-05 22:18 ——— d—–w C:\Program Files\AIM6
2007-10-05 22:18 ——— d—–w C:\Documents and Settings\Anderson Minnick\Application Data\acccore
2007-10-05 22:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-10-05 22:16 ——— d—–w C:\Program Files\Common Files\AOL
2006-12-03 01:05 2,522 —-a-w C:\Program Files\func.js
2006-11-25 07:57 482 —-a-w C:\Program Files\Del.js
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CB8F4B4-5F66-4D9E-BC3B-184596A58824}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{559D61D8-A64A-4677-9DB6-ACE525EC9514}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7722642D-C56A-55E4-6E7E-07D5462CC3EE}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7B6E3CD8-7C3E-4130-B012-A9553EDB4C67}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9319C22D-66F6-4A87-9755-0E2FABFA1847}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A48A15DA-A31A-4403-ACE2-09B450EBA9FF}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FCD85C5E-B272-4CB8-9B01-38CE170A14A9}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 18:44]
"Aim6"="" []
"BitTorrent DNA"="C:\Program Files\BitTorrent_DNA\dna.exe" [2007-11-12 14:37]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 16:33]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 14:59]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-03 21:00]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-03-04 11:26]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-10 13:51]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"LaunchAntiSpy"="C:\Program Files\DefenderPro\TSAntiSpy.exe" []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-22 13:42:22]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-06-03 01:22:01]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 16:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnmmli]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime

S1 SAVOnAccessControl;SAVOnAccessControl;C:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys
S1 SAVOnAccessFilter;SAVOnAccessFilter;C:\WINDOWS\system32\DRIVERS\savonaccessfilter.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-11-28 18:15:36 C:\WINDOWS\Tasks\AntiSpy.job"
- C:\Program Files\DefenderPro\TSAntiSpy.exe
"2007-11-15 18:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-04 16:27:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-04 11:33:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-04 11:33:51 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-10-07 13:13
C:\ComboFix2.txt … 2007-12-03 20:01
C:\ComboFix3.txt … 2007-10-07 13:13
.
— E O F —



Hijack This:

Logfile of HijackThis v1.99.1
Scan saved at 11:38:15 AM, on 12/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…age=www.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LaunchAntiSpy] C:\Program Files\DefenderPro\TSAntiSpy.exe /startup
O4 - HKLM\..\Run: [winshow] "C:\WINDOWS\winshow.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [Spoolsv] C:\WINDOWS\system32\spoolvs.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
Please go to http://virusscan.jotti.org , click on Browse, and upload the following file for analysis:

C:\WINDOWS\system32\spoolvs.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.


If Jotti is too busy you can try these.

http://www.kaspersky.com/scanforvirus.html


http://www.virustotal.com/en/indexf.html
When I went to upload the file to kaspersky, i couldn't find it where you had designated. So i searched through windows32 and still couldn't find it. I ran HJT to try and locate it but it didn't show up. I then restarted my computer thinking maybe that would bring it back or something. Still nothing in the folder or from HJT. I did eventually find it after a doing a full search through my start bar. Here's the file path. I uploaded this and was told that i was clean.

C:\qoobox\Quarantine\C\WINDOWS\system32
Logfile of HijackThis v1.99.1
Scan saved at 18:08, on 2007-12-04
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…age=www.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LaunchAntiSpy] C:\Program Files\DefenderPro\TSAntiSpy.exe /startup
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\BitTorrent_DNA\dna.exe"
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
You need to update SunJava.
Updating Java:
Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says Java Runtime Environment (JRE) 6u2
    The Java SE Runtime Environment (JRE) allows end-users to run Java applications.
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the [external image: Posted Image] icon next to it.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on 6-windowsi586-p.exe to install the newest version.
Once installed you can test to see that it is in fact installed
Sun Java Test
http://www.java.com/en/download/installed.jsp

After the above:

Good job :thumbup:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]
  • If shown the disclaimer, Select "2"


Here's my usual all clean post

Log looks good :D


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide realtime spyware & hijacker protection on your computer alongside your virus protection.
    You should also scan your computer with this program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers
  • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
    settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

    Using IE-SPYAD to help block unwanted sites and activities

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Wonderful to hear. Thank you again for your all of your help. Just a few more questions to clear some things up. I have the Defender Pro 2008, 15-in-1 bundle (A / V, Firewall, Anti-spy to name the main ones). Will that provide the same type of protection as the programs you mentioned such as Spybot S&D, Spywareblaster, and IE-SPYAD? Also, I use firefox so will Spywareblaster and SPYAD work just the same? Thanks again for all of your help!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI