This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]SaveTheInformation, Trojan.Agent, Win32.BHO & More!

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

Looking at earlier posts I'm hoping that you're the guys to help.

I am a student with some assessed work to do this weekend and my PC's practically unuseable! I'm really in the s**t - Any help would be gratefully received.

The problem appeared on Tuesday and I thought that I had got rid of it with AVG AntiSpyWare and Panda Active Scan Pro, in conjunction with AD - Aware SE & Spybot.

But no, the blinking yellow triangle is back, with balloons, home page redirects, popup dialog boxes, pop up windows, etc.

The PC hangs regularly, runs at snails pace, opens multiple IE windows,takes ages to boot and so on…

I have available;

smitRem
AVG Anti Spyware
Ad Aware
SpyBot
Panda Active Scan Pro
HijackThis

Is anyone able to lead me thru a solution please??

Thanks in advance.

Here's the HijackThis log (do I need to rename HijackThis.exe first??)

>>>>>>>> LOG FOLLOWS BELOW>>>>>>

Logfile of HijackThis v1.99.1
Scan saved at 20:47:10, on 30/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
e:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Toshiba Controls\CpRmtKey.EXE
C:\Program Files\EzButton\CplBTQ00.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
E:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
E:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\system32\ctfmon.exe
E:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\Executive Software\Undelete\UdServe.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\HijackThis\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Graham's Web Browser
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\eyracofx.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE"
O4 - HKLM\..\Run: [CplBTQ00] C:\Program Files\EzButton\CplBTQ00.EXE
O4 - HKLM\..\Run: [DiskeeperSystray] "E:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C48 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I091.EXE /P23 "EPSON Stylus C48 Series" /O11 "PS504983_P1" /M "Stylus C48"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [SMSTray] e:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [fc666316] rundll32.exe "C:\WINDOWS\system32\ysplnnqp.dll",b
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [RealPlayer] "e:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: MailWasherPro.lnk = E:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D6376DD2-C2BD-49B2-A1B1-138F869633F3} (ASPRO Installer Class) - http://acs.pandasoftware.com/activescanpro/as5/asproinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{879F1573-DE40-42B6-BE45-3EDE90A012ED}: NameServer = 192.168.0.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c0054C64.dat
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - e:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Diskeeper - Executive Software International, Inc. - E:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\raoqrfkv.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Symbol Technologies - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Executive Software Undelete (UndeleteService) - Executive Software International - E:\Program Files\Executive Software\Undelete\UdServe.exe

>>>>>>> HIJACKTHIS LOG ENDS HERE>>>>>>>

Thanks

Graham
Hello, and welcome to the forum.

My name is Simon V., and I'll be glad to help you with your computer problems.

Step 1

Please disable AVG Anti-Spyware Resident Shield, as it may interfere with the fix.

  • Double-click on the AVG Anti-Spyware icon in your system tray (next to your clock).
  • Under Status, click on Change state, next to Resident shield (this will change from Active to Inactive).
  • Close AVG Anti-Spyware.

Note: Be sure to enable AVG Anti-Spyware Resident Shield when you are clean!

Step 2

Please download ATF Cleaner. Double-click on ATF-Cleaner.exe to start the program.

  • Under the Main tab, put a check next to Select All.
    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)
  • If you use the Firefox browser:
    Click on Firefox at the top and put a check next to Select All.
    If you would like to keep your saved passwords, click No at the prompt.
    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)
  • If you use the Opera browser:
    Click on Opera at the top and put a check next to Select All.
    If you would like to keep your saved passwords, click No at the prompt.
    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)

Step 3

Please download Combofix:


Double-click on combofix.exe and follow the prompts.
When finished, it will produce a log for you. Save it to a convenient location.

Note: Do not mouseclick Combofix's window whilst it's running. That may cause it to stall.

Note: Combofix should never take more that 20 minutes including the reboot if malware is detected. If it does, press Ctrl, Alt and Del at the same time and, under the Processes tab, end any processes of findstr, find, sed or swreg, then Combofix should continue. If that happened I'd like to know and what process you had to end.

Step 4

Please download and install CCleaner.

  • Open CCleaner. In the Left Pane, click Tools.
  • Verify that Uninstall is highlighted in color, or click on it.
  • In the lower right, click Save to Text File.
  • Pull down the arrow at the top of the Save dialog and choose Desktop as the location.
  • You can leave the filename as install.txt.
  • Click Save.
  • Exit Ccleaner by clicking on the X button in the upper right of the CCleaner window.

Step 5

In your next reply, please post:

  • the Combofix log (C:\Combofix.txt)
  • the CCleaner Uninstall List (install.txt)
  • a new HijackThis log
Hi Simon V

Thanks for your super speedy response.

I admire your committment, thank you.

All of the tasks in your first reply have been carried out.

Things look better but I still have a "security toolbar" in IE.

I meant to mention a couple of other things that have been happening in the past 24 hours;

1) I keep ending up with a blank screen, no icons, toolbars, or taskbar.
2) Windows kept "updating personalised settings"
3) I've noticed in the root directory of at least one drive a new registry file; SAGESET2005.REG

Guess that these are all connected?

Anyhow, here are the new logfiles (since last running HijackThis I have reconnected a removable USB drive - I did this before running the programs above);

>>>>>> HERES HIJACKTHIS LOGFILE>>>>>>>

Logfile of HijackThis v1.99.1
Scan saved at 22:40:13, on 30/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
e:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
E:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\Executive Software\Undelete\UdServe.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Toshiba Controls\CpRmtKey.EXE
C:\Program Files\EzButton\CplBTQ00.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
E:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Documents and Settings\test\Desktop\Malware Fix\HijackThis\hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: {fdba1748-ef58-a43a-3b44-4603287dd912} - {219dd782-3064-44b3-a34a-85fe8471abdf} - C:\WINDOWS\system32\gasuqigt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: 0 - {8FF85704-85EB-454F-0090-199DB69EFF76} - C:\Program Files\MSN Gaming Zone\laculyxas231.dll (file missing)
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\eyracofx.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\eyracofx.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE"
O4 - HKLM\..\Run: [CplBTQ00] C:\Program Files\EzButton\CplBTQ00.EXE
O4 - HKLM\..\Run: [DiskeeperSystray] "E:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C48 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I091.EXE /P23 "EPSON Stylus C48 Series" /O11 "PS504983_P1" /M "Stylus C48"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [SMSTray] e:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [fc666316] rundll32.exe "C:\WINDOWS\system32\ysplnnqp.dll",b
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [RealPlayer] "e:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: MailWasherPro.lnk = E:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D6376DD2-C2BD-49B2-A1B1-138F869633F3} (ASPRO Installer Class) - http://acs.pandasoftware.com/activescanpro/as5/asproinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{879F1573-DE40-42B6-BE45-3EDE90A012ED}: NameServer = 192.168.0.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: bozjgrsr - bozjgrsr.dll (file missing)
O20 - Winlogon Notify: eyracofx - C:\WINDOWS\SYSTEM32\eyracofx.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - e:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Diskeeper - Executive Software International, Inc. - E:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Symbol Technologies - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Executive Software Undelete (UndeleteService) - Executive Software International - E:\Program Files\Executive Software\Undelete\UdServe.exe

>>>>>> END OF HIJACKTHIS LOGFILE>>>>>>


<<<<<<< HERES COMBOFIX.TXT <<<<<<<<<

ComboFix 07-11-19.4C - test 2007-11-30 22:15:31.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.199 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Malware Fix\ComboFix\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\test\Application Data\macromedia\Flash Player\#SharedObjects\G442C8BZ\iforex.com
C:\Documents and Settings\test\Application Data\macromedia\Flash Player\#SharedObjects\G442C8BZ\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\test\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\test\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\Documents and Settings\test\Desktop\Live Safety Center.lnk
C:\Documents and Settings\test\Desktop\Online Security Guide.lnk
C:\Documents and Settings\test\Favorites\Online Security Guide.lnk
C:\Program Files\MSN Gaming Zone\prolyzuror.html
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\bozjgrsr.dllbox
C:\WINDOWS\system32\eyracofx.dllbox
C:\WINDOWS\system32\ilnmp.ini
C:\WINDOWS\system32\ilnmp.ini2
C:\WINDOWS\system32\j3
C:\WINDOWS\system32\pmnli.dll
C:\WINDOWS\system32\r2
C:\WINDOWS\system32\u5
C:\WINDOWS\system32\u5\banedll2.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\DomainService
——-\nm


((((((((((((((((((((((((( Files Created from 2007-10-28 to 2007-11-30 )))))))))))))))))))))))))))))))
.

2007-11-30 19:38 793,802 –ahs—- C:\WINDOWS\system32\pqnnlpsy.ini
2007-11-30 19:38 78,912 –a—— C:\WINDOWS\system32\gasuqigt.dll
2007-11-30 19:36 145,984 –a—— C:\WINDOWS\system32\gkamgcpv.dll
2007-11-30 19:36 145,984 –a—— C:\WINDOWS\system32\eyracofx.dll
2007-11-29 09:27 69,632 –a—— C:\WINDOWS\system32\asprouni.exe
2007-11-29 09:26 3,377 –a—— C:\WINDOWS\system32\.ico
2007-11-29 09:26 2,550 –a—— C:\WINDOWS\system32\Uninstallpro.ico
2007-11-29 09:26 1,406 –a—— C:\WINDOWS\system32\Helppro.ico
2007-11-28 22:53 789,349 –ahs—- C:\WINDOWS\system32\ckifyoup.ini
2007-11-28 16:12 2,550 –a—— C:\WINDOWS\system32\Uninstall.ico
2007-11-28 16:12 1,406 –a—— C:\WINDOWS\system32\Help.ico
2007-11-28 13:10 d——– C:\Documents and Settings\test\Application Data\Grisoft
2007-11-28 13:09 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-28 13:09 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-27 22:34 38,912 –a—— C:\WINDOWS\system32\ddcbcdb.dll
2007-11-27 22:33 d–hs—- C:\WINDOWS\dGVzdA
2007-11-27 22:33 d——– C:\Temp\abW9
2007-11-27 22:33 d——– C:\Temp
2007-11-27 22:33 38,912 –a—— C:\WINDOWS\system32\ljjheef.dll
2007-10-18 12:38 d——– C:\Documents and Settings\test\Application Data\DataCast
2007-10-18 12:30 d——– C:\Program Files\MarkAny
2007-10-18 12:29 d——– C:\Documents and Settings\test\Application Data\InstallShield
2007-10-18 12:29 569,344 –a—— C:\WINDOWS\system32\muzdecode.ax
2007-10-18 12:29 471,040 –a—— C:\WINDOWS\system32\muzapp.dll
2007-10-18 12:29 245,408 –a—— C:\WINDOWS\system32\unicows.dll
2007-10-18 12:29 163,840 –a—— C:\WINDOWS\system32\muzapp.exe
2007-10-18 12:29 135,168 –a—— C:\WINDOWS\system32\muzaf1.dll
2007-10-18 12:29 110,592 –a—— C:\WINDOWS\system32\tg_dump.dll
2007-10-18 11:28 1,048,576 –a—— C:\WINDOWS\system32\lameACM.acm
2007-10-18 11:28 299,008 –a—— C:\WINDOWS\system32\LAME_MP3.dll
2007-10-18 11:28 401 –a—— C:\WINDOWS\system32\lame_acm.xml

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-30 22:28 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kontiki
2007-11-30 22:24 0 —-a-w C:\WINDOWS\system32\drivers\lvuvc.hs
2007-11-30 22:01 ——— d—–w C:\Documents and Settings\test\Application Data\MailWasherPro
2007-11-30 21:34 ——— d—–w C:\Documents and Settings\test\Application Data\Skype
2007-11-30 01:40 ——— d—–w C:\Program Files\Toshiba Controls
2007-11-30 01:39 ——— d—–w C:\Program Files\Kontiki
2007-11-30 01:33 ——— d—–w C:\Program Files\EzButton
2007-11-30 01:31 ——— d—–w C:\Program Files\Apoint2K
2007-11-19 23:07 ——— d—–w C:\Documents and Settings\test\Application Data\NewsBin
2007-11-19 01:08 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-19 01:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-10-18 12:38 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-18 11:28 65,024 —-a-w C:\WINDOWS\IFinst26.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{219dd782-3064-44b3-a34a-85fe8471abdf}]
2007-11-30 19:38 78912 –a—— C:\WINDOWS\system32\gasuqigt.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8FF85704-85EB-454F-0090-199DB69EFF76}]
C:\Program Files\MSN Gaming Zone\laculyxas231.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-30 19:36 145984 –a—— C:\WINDOWS\system32\eyracofx.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\eyracofx.dll [2007-11-30 19:36 145984]

[HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 18:31]
"RealPlayer"="e:\Program Files\Real\RealPlayer\realplay.exe" [2006-11-03 23:00]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-04 07:56]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 07:56 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2003-09-27 02:02 C:\WINDOWS\system32\nwiz.exe]
"CeEPOWER"="C:\Program Files\TOSHIBA\Power Management\CePMTray.exe" [2003-08-05 18:07]
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2003-07-29 16:19]
"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2003-07-18 15:24]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-06-17 21:44]
"CpRmtKey"="C:\Program Files\Toshiba Controls\CpRmtKey.EXE" [2003-05-29 11:54]
"CplBTQ00"="C:\Program Files\EzButton\CplBTQ00.EXE" [2003-06-27 16:33]
"DiskeeperSystray"="E:\Program Files\Executive Software\Diskeeper\DkIcon.exe" [2005-03-07 13:16]
"FinePrint Dispatcher v5"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" [2004-03-04 09:17]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-05-31 10:45]
"EPSON Stylus C48 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I091.exe" []
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" []
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 15:15]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-12-09 14:32]
"LogitechCameraAssistant"="C:\Program Files\Logitech\Video\CameraAssistant.exe" [2005-12-07 09:26]
"LogitechVideo[inspector]"="C:\Program Files\Logitech\Video\InstallHelper.exe" [2005-12-07 09:33]
"LogitechCameraService(E)"="C:\WINDOWS\system32\ElkCtrl.exe" [2004-11-01 16:22]
"SMSTray"="e:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-09-20 07:23]
"!AVG Anti-Spyware"="E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25]
"fc666316"="C:\WINDOWS\system32\ysplnnqp.dll" [2007-11-30 19:38]

C:\Documents and Settings\test\Start Menu\Programs\Startup\
MailWasherPro.lnk - E:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe [2004-09-29 18:06:56]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 15:51 192512]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\bozjgrsr]
bozjgrsr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\eyracofx]
eyracofx.dll 2007-11-30 19:36 145984 C:\WINDOWS\system32\eyracofx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\pmnli.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll, xlibgfl254.dll

R0 UdDrv;Executive Software Filter;C:\WINDOWS\system32\drivers\UdDrv.sys
R1 Cinemsup;Cinemsup;C:\WINDOWS\system32\drivers\Cinemsup.sys
R1 DVDVRRdr_xp;DVDVRRdr_xp;C:\WINDOWS\system32\drivers\DVDVRRdr_xp.sys
R1 SrvcEKIOMngr;SrvcEKIOMngr;C:\WINDOWS\system32\Drivers\EKIoMngr.sys
R1 SrvcEPIOMngr;SrvcEPIOMngr;C:\WINDOWS\system32\Drivers\EPIoMngr.sys
R1 SrvcSSIOMngr;SrvcSSIOMngr;C:\WINDOWS\system32\Drivers\SSIoMngr.sys
R1 SrvcTPIOMngr;SrvcTPIOMngr;C:\WINDOWS\system32\Drivers\TPIoMngr.sys
R1 UDFReadr;UDFReadr;C:\WINDOWS\system32\drivers\UDFReadr.sys
R2 UndeleteService;Executive Software Undelete;"E:\Program Files\Executive Software\Undelete\UdServe.exe"
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\system32\Drivers\DKbFltr.sys
R3 EPOWER;Compal E-POWER Driver;C:\WINDOWS\system32\Drivers\hkdrv.sys
R3 LVPrcMon;Logitech LVPrcMon Driver;\??\C:\WINDOWS\system32\drivers\LVPrcMon.sys
R3 TOSHIBASoftModem;TOSHIBA Software Modem;C:\WINDOWS\system32\DRIVERS\LTSM.sys
R3 tsdhd;TOSHIBA SD Card Host Controller Driver;C:\WINDOWS\system32\DRIVERS\tsdhd.sys
R3 wlags48b;Wireless LAN PCCard Driver;C:\WINDOWS\system32\DRIVERS\wlags48b.sys
S3 NDISLOOP;Virtual TT-DVB USB Adapter Driver;C:\WINDOWS\system32\DRIVERS\ndisloop.sys
S3 pciSd;pciSd;C:\WINDOWS\system32\DRIVERS\tossdpci.sys
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys
S3 TTDVBUSB;TechnoTrend - TT-DVB USB Driver;C:\WINDOWS\system32\Drivers\ttdvbusb.sys
S3 ttv100x;TOSHIBA USB2 TV Tuner;C:\WINDOWS\system32\DRIVERS\ttv100x.sys

.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-30 22:28:06
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-30 22:33:16 - machine was rebooted
.
— E O F —


<<<<<< END OF COMBOFIX.TXT<<<<<<<<<

************ HERES INSTALL.TXT *********

3Com DynamicAccess Mobile Connection Manager
7-Zip 4.23
AccessDiver v4.241
ACT!
Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Flash Player ActiveX
Adobe Reader 6.0
ALPS Touch Pad Driver
Atheros Client Utility
AVG Anti-Spyware 7.5
BBC iPlayer Library
Bluetooth Stack for Windows by Toshiba
CCleaner (remove only)
ConceptDraw MINDMAP
Diskeeper Professional Edition
Driver Genius Professional Edition 2005 5.3.016
Easy Button
EPSON Printer Software
FinePrint
Free Word Excel Password Wizard
FUJIFILM USB Driver
GeoWhere 2.61 (Lite)
Google Earth
guru's Yahoo! Group Downloader Shareware
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 1.99.1
Instant Architect
InterVideo WinDVD 4
Iolis
Java 2 Runtime Environment, SE v1.4.2
L&H TTS3000 British English
Lame ACM MP3 Codec
Logitech QuickCam Software
Logitech® Camera Driver
Macromedia Shockwave Player
MailWasher Pro
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.0 Hotfix (KB930494)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Application Compatibility Toolkit 5.0
Microsoft Office FrontPage 2003
Microsoft Office Professional Edition 2003
Microsoft Office Project Professional 2003
Microsoft Office Visio Professional 2003
Microsoft Windows Journal Viewer
MovieJack 3.5
mpegable DS decoder
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MyFreeCodec
NETGEAR Print Server Software
NewsBin Pro
NVIDIA Windows 2000/XP Display Drivers
OpenMG Limited Patch 4.3-05-10-05-01
OpenMG Secure Module
OpenMG Secure Module 4.3.00
OSS Audio CD Maker 3.0.0.1
Panda ActiveScan
Panda ActiveScan Pro
PartitionMagic
PowerQuest PartitionMagic 8.0
PrintFolder 1.3
QuickPar 0.9
QuickTime
RealPlayer
Realtek AC'97 Audio
Realtek Fast Ethernet Adapter Driver
Roxio Easy Media Creator 7
Samsung Media Studio
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB943460)
ShowShifter
Skype™ 3.5
SMSC IrCC Driver V5.1.2462.0 (WinXP)
Sonic Backup MyPC Deluxe
Sonic CinePlayer
Sonic MyDVD SlideShow
Spybot - Search & Destroy 1.4
StyleXP (remove only)
TOSHIBA ConfigFree
TOSHIBA Console
Toshiba Controls
TOSHIBA Hotkey Utility
TOSHIBA Manuals
TOSHIBA PC Diagnostic Tool
TOSHIBA Power Management Utility
Toshiba screensaver
TOSHIBA SD Memory Card Format
TOSHIBA Software Modem
TouchPad On/Off Utility
Turbo Lister 2
Undelete Home Edition
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
VNC 3.3.7
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Installer 3.1 (KB893803)
Windows Media Connect
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 9 Hotfix [See KB885492 for more information]
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB884020
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB887797
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinTV NOVA USB
WinZip
XQDC X-Setup Pro 7.0.300.Final1
XviD MPEG-4 Video Codec


***** END OF INSTALL.TXT ******

I hope that this helps and look forward to hearing from you soon.

Thanks again



Graham
Hey Whoa!! The blinking yellow triangle is back again!! Trust me it had gone away, in the meantime I had opened a couple of Explorer windows. Regards Graham
Hi :)

Guess that these are all connected?

We'll see ;) First I want to get all the malware off your computer, as there is still a lot left.

Step 1

Click on Start, then Control Panel. Double click on Add or Remove Programs.

Please remove the following program(s):

  • MyFreeCodec

Step 2

Open Notepad (Go to Start > Run, type Notepad and hit Enter), and copy/paste the text in the quotebox below into it:

File::

C:\WINDOWS\system32\pqnnlpsy.ini
C:\WINDOWS\system32\gasuqigt.dll
C:\WINDOWS\system32\gkamgcpv.dll
C:\WINDOWS\system32\eyracofx.dll
C:\WINDOWS\system32\ckifyoup.ini
C:\WINDOWS\system32\ddcbcdb.dll
C:\WINDOWS\system32\ljjheef.dll
C:\WINDOWS\system32\drivers\lvuvc.hs
C:\Program Files\MSN Gaming Zone\laculyxas231.dll
C:\WINDOWS\system32\ysplnnqp.dll
C:\WINDOWS\system32\bozjgrsr.dll

Folder::

C:\WINDOWS\dGVzdA
C:\Temp\abW9

Registry::

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{219dd782-3064-44b3-a34a-85fe8471abdf}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8FF85704-85EB-454F-0090-199DB69EFF76}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"=-
[-HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"fc666316"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\bozjgrsr]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\eyracofx]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

Click on File > Save as….

In the File Name box, copy/paste CFScript.txt (Note: Do not change the filename!)

Click Save.

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe.
It will create a log. Be sure to save it to a convenient location.

Step 3

In your next reply, please post:

  • the Combofix log (C:\Combofix.txt)
  • a new HijackThis log
Simon

All done, here's to logfiles;


ComboFix.txt


ComboFix 07-11-19.4C - test 2007-12-01 11:21:29.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.166 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Malware Fix\ComboFix\ComboFix.exe
Command switches used :: C:\Documents and Settings\test\Desktop\Malware Fix\ComboFix\CFScript.txt
* Created a new restore point

FILE
C:\Program Files\MSN Gaming Zone\laculyxas231.dll
C:\WINDOWS\system32\bozjgrsr.dll
C:\WINDOWS\system32\ckifyoup.ini
C:\WINDOWS\system32\ddcbcdb.dll
C:\WINDOWS\system32\drivers\lvuvc.hs
C:\WINDOWS\system32\eyracofx.dll
C:\WINDOWS\system32\gasuqigt.dll
C:\WINDOWS\system32\gkamgcpv.dll
C:\WINDOWS\system32\ljjheef.dll
C:\WINDOWS\system32\pqnnlpsy.ini
C:\WINDOWS\system32\ysplnnqp.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\test\Desktop\Live Safety Center.lnk
C:\Documents and Settings\test\Desktop\Online Security Guide.lnk
C:\Documents and Settings\test\Favorites\Online Security Guide.lnk
C:\Temp\abW9
C:\Temp\abW9\tPho.log
C:\WINDOWS\dGVzdA
C:\WINDOWS\system32\ckifyoup.ini
C:\WINDOWS\system32\ddcbcdb.dll
C:\WINDOWS\system32\drivers\lvuvc.hs
C:\WINDOWS\system32\eyracofx.dll
C:\WINDOWS\system32\eyracofx.dllbox
C:\WINDOWS\system32\gasuqigt.dll
C:\WINDOWS\system32\gkamgcpv.dll
C:\WINDOWS\system32\ljjheef.dll
C:\WINDOWS\system32\pqnnlpsy.ini
C:\WINDOWS\system32\ysplnnqp.dll

.
((((((((((((((((((((((((( Files Created from 2007-11-01 to 2007-12-01 )))))))))))))))))))))))))))))))
.

2007-11-29 09:27 69,632 –a—— C:\WINDOWS\system32\asprouni.exe
2007-11-29 09:26 d——– C:\WINDOWS\system32\ASPRO
2007-11-29 09:26 3,377 –a—— C:\WINDOWS\system32\.ico
2007-11-29 09:26 1,406 –a—— C:\WINDOWS\system32\Helppro.ico
2007-11-28 16:12 1,406 –a—— C:\WINDOWS\system32\Help.ico
2007-11-28 13:11 97 –a—— C:\WINDOWS\system32\mcrh.tmp
2007-11-28 13:10 d——– C:\Documents and Settings\test\Application Data\Grisoft
2007-11-28 13:09 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-28 13:09 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-27 22:33 d——– C:\Temp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-01 11:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kontiki
2007-11-30 23:01 ——— d—–w C:\Documents and Settings\test\Application Data\MailWasherPro
2007-11-30 21:34 ——— d—–w C:\Documents and Settings\test\Application Data\Skype
2007-11-30 01:40 ——— d—–w C:\Program Files\Toshiba Controls
2007-11-30 01:39 ——— d—–w C:\Program Files\Kontiki
2007-11-30 01:33 ——— d—–w C:\Program Files\EzButton
2007-11-30 01:31 ——— d—–w C:\Program Files\Apoint2K
2007-11-19 23:07 ——— d—–w C:\Documents and Settings\test\Application Data\NewsBin
2007-11-19 01:08 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-19 01:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-10-18 12:38 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-18 12:38 ——— d—–w C:\Documents and Settings\test\Application Data\DataCast
2007-10-18 12:30 ——— d—–w C:\Program Files\MarkAny
2007-10-18 12:29 ——— d—–w C:\Documents and Settings\test\Application Data\InstallShield
2007-10-18 11:28 65,024 —-a-w C:\WINDOWS\IFinst26.exe
.

((((((((((((((((((((((((((((( snapshot@2007-11-30_22.31.02.70 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-01 11:27:52 16,384 —-atw C:\WINDOWS\temp\Perflib_Perfdata_230.dat
+ 2007-12-01 11:27:54 16,384 —-atw C:\WINDOWS\temp\Perflib_Perfdata_554.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 18:31]
"RealPlayer"="e:\Program Files\Real\RealPlayer\realplay.exe" [2006-11-03 23:00]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-04 07:56]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 07:56 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2003-09-27 02:02 C:\WINDOWS\system32\nwiz.exe]
"CeEPOWER"="C:\Program Files\TOSHIBA\Power Management\CePMTray.exe" [2003-08-05 18:07]
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2003-07-29 16:19]
"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2003-07-18 15:24]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-06-17 21:44]
"CpRmtKey"="C:\Program Files\Toshiba Controls\CpRmtKey.EXE" [2003-05-29 11:54]
"CplBTQ00"="C:\Program Files\EzButton\CplBTQ00.EXE" [2003-06-27 16:33]
"DiskeeperSystray"="E:\Program Files\Executive Software\Diskeeper\DkIcon.exe" [2005-03-07 13:16]
"FinePrint Dispatcher v5"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" [2004-03-04 09:17]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-05-31 10:45]
"EPSON Stylus C48 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I091.exe" []
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" []
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 15:15]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-12-09 14:32]
"LogitechCameraAssistant"="C:\Program Files\Logitech\Video\CameraAssistant.exe" [2005-12-07 09:26]
"LogitechVideo[inspector]"="C:\Program Files\Logitech\Video\InstallHelper.exe" [2005-12-07 09:33]
"LogitechCameraService(E)"="C:\WINDOWS\system32\ElkCtrl.exe" [2004-11-01 16:22]
"SMSTray"="e:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-09-20 07:23]
"!AVG Anti-Spyware"="E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25]

C:\Documents and Settings\test\Start Menu\Programs\Startup\
MailWasherPro.lnk - E:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe [2004-09-29 18:06:56]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 15:51 192512]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll, xlibgfl254.dll

R0 UdDrv;Executive Software Filter;C:\WINDOWS\system32\drivers\UdDrv.sys
R1 Cinemsup;Cinemsup;C:\WINDOWS\system32\drivers\Cinemsup.sys
R1 DVDVRRdr_xp;DVDVRRdr_xp;C:\WINDOWS\system32\drivers\DVDVRRdr_xp.sys
R1 SrvcEKIOMngr;SrvcEKIOMngr;C:\WINDOWS\system32\Drivers\EKIoMngr.sys
R1 SrvcEPIOMngr;SrvcEPIOMngr;C:\WINDOWS\system32\Drivers\EPIoMngr.sys
R1 SrvcSSIOMngr;SrvcSSIOMngr;C:\WINDOWS\system32\Drivers\SSIoMngr.sys
R1 SrvcTPIOMngr;SrvcTPIOMngr;C:\WINDOWS\system32\Drivers\TPIoMngr.sys
R1 UDFReadr;UDFReadr;C:\WINDOWS\system32\drivers\UDFReadr.sys
R2 UndeleteService;Executive Software Undelete;"E:\Program Files\Executive Software\Undelete\UdServe.exe"
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\system32\Drivers\DKbFltr.sys
R3 EPOWER;Compal E-POWER Driver;C:\WINDOWS\system32\Drivers\hkdrv.sys
R3 LVPrcMon;Logitech LVPrcMon Driver;\??\C:\WINDOWS\system32\drivers\LVPrcMon.sys
R3 TOSHIBASoftModem;TOSHIBA Software Modem;C:\WINDOWS\system32\DRIVERS\LTSM.sys
R3 tsdhd;TOSHIBA SD Card Host Controller Driver;C:\WINDOWS\system32\DRIVERS\tsdhd.sys
R3 wlags48b;Wireless LAN PCCard Driver;C:\WINDOWS\system32\DRIVERS\wlags48b.sys
S3 NDISLOOP;Virtual TT-DVB USB Adapter Driver;C:\WINDOWS\system32\DRIVERS\ndisloop.sys
S3 pciSd;pciSd;C:\WINDOWS\system32\DRIVERS\tossdpci.sys
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys
S3 TTDVBUSB;TechnoTrend - TT-DVB USB Driver;C:\WINDOWS\system32\Drivers\ttdvbusb.sys
S3 ttv100x;TOSHIBA USB2 TV Tuner;C:\WINDOWS\system32\DRIVERS\ttv100x.sys

.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-01 11:28:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-01 11:32:38 - machine was rebooted
C:\ComboFix2.txt … 2007-11-30 22:33
.
— E O F —


HIJACKTHIS LOG;


Logfile of HijackThis v1.99.1
Scan saved at 11:40:39, on 01/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
e:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
E:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\Executive Software\Undelete\UdServe.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Toshiba Controls\CpRmtKey.EXE
C:\Program Files\EzButton\CplBTQ00.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
E:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
E:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\test\Desktop\Malware Fix\HijackThis\hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE"
O4 - HKLM\..\Run: [CplBTQ00] C:\Program Files\EzButton\CplBTQ00.EXE
O4 - HKLM\..\Run: [DiskeeperSystray] "E:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C48 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I091.EXE /P23 "EPSON Stylus C48 Series" /O11 "PS504983_P1" /M "Stylus C48"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [SMSTray] e:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [RealPlayer] "e:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: MailWasherPro.lnk = E:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D6376DD2-C2BD-49B2-A1B1-138F869633F3} (ASPRO Installer Class) - http://acs.pandasoftware.com/activescanpro/as5/asproinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{879F1573-DE40-42B6-BE45-3EDE90A012ED}: NameServer = 192.168.0.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - e:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Diskeeper - Executive Software International, Inc. - E:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Symbol Technologies - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Executive Software Undelete (UndeleteService) - Executive Software International - E:\Program Files\Executive Software\Undelete\UdServe.exe


I look forward to hearing from.

Thanks



Graham
Hi :)

Step 1

Your Java software is out of date. Follow these instructions to update it:

  • Go to Start and click on Control Panel, then double-click on Add or Remove Programs.
  • Search for previously installed versions of Java (J2SE Runtime Environment), and remove it. It should have this icon next to it: [external image: Posted Image]
  • Then download and install Java Runtime Environment (JRE) 6 Update 3.

Step 2

Please do an online scan with Kaspersky WebScanner.

Click on Kaspersky Online Scanner. On the welcome screen, click Accept.

You will be promted to install an ActiveX component from Kaspersky, click Install.

  • The program will launch and then begin downloading the latest definition files.
  • Once the files have been downloaded click on Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:

  • Scan using the following Anti-Virus database:

    Extended (if available, otherwise Standard)

  • Scan Options:

    Scan Archives
    Scan Mail Bases

  • Click OK.
  • Now under Select a Target to Scan:

    Select My Computer.

  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button and save the file to your desktop.

Step 3

Please copy and paste the text in the code box into Notepad (Go to Start > Run, type Notepad and hit Enter)

@echo off

if exist C:\export.txt del /q C:\export.txt
regedit /a C:\export.txt "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders"
start C:\export.txt
exit

Go to File > Save As:. Save the file as "Export.bat" (Including the quotes)

Double-click on Export.bat to run the file. A Notepad file should open. Post the contents of that file (C:\export.txt) along with the Kaspersky Online Scan report and a new HijackThis log. Also tell me how everything is working.
Hello again Simon

It's taken a while but I've completed the tasks listed in your previous post.

Everything seems OK at the moment with no odd or suspicious behaviour, lets hope it lasts!

Here are the log files requested;

$$$$$$$$$ EXPORT.BAT LISTING $$$$$$$$$$$

REGEDIT4

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll, xlibgfl254.dll"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SaslProfiles]
"GSSAPI"="Kerberos"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL]
"EventLogging"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Ciphers]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Ciphers\DES 56/56]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Ciphers\NULL]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Ciphers\RC2 128/128]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Ciphers\RC2 40/128]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Ciphers\RC2 56/128]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Ciphers\RC4 128/128]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Ciphers\RC4 40/128]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Ciphers\RC4 56/128]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Ciphers\Triple DES 168/168]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Hashes]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Hashes\MD5]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Hashes\SHA]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\KeyExchangeAlgorithms]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\KeyExchangeAlgorithms\Diffie-Hellman]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\KeyExchangeAlgorithms\PKCS]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols\Multi-Protocol Unified Hello]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols\Multi-Protocol Unified Hello\Client]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols\Multi-Protocol Unified Hello\Server]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols\PCT 1.0]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols\PCT 1.0\Client]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols\PCT 1.0\Server]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols\SSL 2.0]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols\SSL 2.0\Client]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols\SSL 2.0\Server]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols\SSL 3.0]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols\SSL 3.0\Client]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols\SSL 3.0\Server]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols\TLS 1.0]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols\TLS 1.0\Client]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\SCHANNEL\Protocols\TLS 1.0\Server]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders\WDigest]
"Lifetime"=dword:00008ca0
"Negotiate"=dword:00000000
"UTF8HTTP"=dword:00000001
"UTF8SASL"=dword:00000001

$$$$$$$$$$$$$$$$$$ END OF EXPORT.BAT LISTING $$$$$$$$$$$$


##################### START OF KASPERSKY ONLINE SCAN REPORT ##########

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Saturday, December 01, 2007 3:23:29 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 1/12/2007
Kaspersky Anti-Virus database records: 469757
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\

Scan Statistics:
Total number of scanned objects: 365255
Number of viruses found: 22
Number of infected objects: 64
Number of suspicious objects: 0
Duration of the scan process: 02:36:58

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Kontiki\error.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\test\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\test\Desktop\Group Downloaders\picture ripper 3_59\e-pir359-2006-10-30.rar/crack.exe Infected: Trojan-Downloader.Win32.Small.ddp skipped
C:\Documents and Settings\test\Desktop\Group Downloaders\picture ripper 3_59\e-pir359-2006-10-30.rar RAR: infected - 1 skipped
C:\Documents and Settings\test\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\test\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\test\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\test\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\test\ntuser.dat Object is locked skipped
C:\Documents and Settings\test\ntuser.dat.LOG Object is locked skipped
C:\qoobox\Quarantine\C\Program Files\MSN Gaming Zone\prolyzuror.html.vir Infected: Trojan-Clicker.HTML.IFrame.dn skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ddcbcdb.dll.vir Infected: Trojan.Win32.Obfuscated.lf skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\eyracofx.dll.vir Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\gkamgcpv.dll.vir Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ljjheef.dll.vir Infected: Trojan.Win32.Obfuscated.lf skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\u5\banedll2.exe.vir Infected: Trojan-Downloader.Win32.Small.guf skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ysplnnqp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\qoobox\Quarantine\catchme2007-12-01_112753.00.zip/eyracofx.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\qoobox\Quarantine\catchme2007-12-01_112753.00.zip ZIP: infected - 1 skipped
C:\RecoveryBin\Volume-20d8b761-6aeb-43a9-8852-d75fafa60ab5\windows\system32\oleyhjvy(01C8338866AA02B7).exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\RecoveryBin\Volume-20d8b761-6aeb-43a9-8852-d75fafa60ab5\windows\system32\raoqrfkv(01C83389ABB00002).exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\RecoveryBin\Volume-20d8b761-6aeb-43a9-8852-d75fafa60ab5\windows\system32\shohjcgb(01C833884D9802B5).dll Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{395D6ECC-73C1-43E5-AFE9-C4C70269033B}\RP2\A0000210.exe Infected: Trojan-Downloader.Win32.Small.guf skipped
C:\System Volume Information\_restore{395D6ECC-73C1-43E5-AFE9-C4C70269033B}\RP3\A0000449.dll Infected: Trojan.Win32.Obfuscated.lf skipped
C:\System Volume Information\_restore{395D6ECC-73C1-43E5-AFE9-C4C70269033B}\RP3\A0000451.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{395D6ECC-73C1-43E5-AFE9-C4C70269033B}\RP3\A0000452.dll Infected: Trojan.Win32.Obfuscated.lf skipped
C:\System Volume Information\_restore{395D6ECC-73C1-43E5-AFE9-C4C70269033B}\RP3\A0000453.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{395D6ECC-73C1-43E5-AFE9-C4C70269033B}\RP3\A0000454.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{395D6ECC-73C1-43E5-AFE9-C4C70269033B}\RP3\A0000458.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{395D6ECC-73C1-43E5-AFE9-C4C70269033B}\RP5\change.log Object is locked skipped
C:\WINDOWS\$NtUninstallKB824141$\user32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB824141$\win32k.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\cryptsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\newdev.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntdll.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ole32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\rpcrt4.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\rpcss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\shell32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\srrstr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\srv.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\winsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\temp\Perflib_Perfdata_230.dat Object is locked skipped
C:\WINDOWS\temp\Perflib_Perfdata_554.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1CDA3152.Uu Infected: Email-Worm.Win32.Nyxem.e skipped
E:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1F136E12.exe Infected: Trojan-Downloader.Win32.Small.on skipped
E:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\3A013588.tmp Infected: Trojan-Downloader.Win32.Small.cul skipped
E:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4C811014.exe Infected: Trojan-Downloader.Win32.Small.on skipped
E:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4CC92BC5.exe Infected: Trojan-Downloader.Win32.Small.on skipped
E:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4F7048DA.htm Infected: Exploit.JS.CVE-2006-1359.aa skipped
E:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\6C915919.dll Infected: Trojan-Downloader.Win32.Agent.bfj skipped
E:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\6E0D1715.dll Infected: Trojan.Win32.BHO.c skipped
E:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\7BFC7C23.tmp Infected: Trojan-Downloader.JS.Small.ch skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\Desktop Folder from Tosh 4600\Files from power pc\Power Files.ZIP/VNC/vnc-3.3.7-x86_win32.exe/data0002 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
F:\Desktop Folder from Tosh 4600\Files from power pc\Power Files.ZIP/VNC/vnc-3.3.7-x86_win32.exe/data0003 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
F:\Desktop Folder from Tosh 4600\Files from power pc\Power Files.ZIP/VNC/vnc-3.3.7-x86_win32.exe/data0004 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
F:\Desktop Folder from Tosh 4600\Files from power pc\Power Files.ZIP/VNC/vnc-3.3.7-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
F:\Desktop Folder from Tosh 4600\Files from power pc\Power Files.ZIP ZIP: infected - 4 skipped
F:\Desktop Folder from Tosh 4600\VGA Scart RGB Conversion\RealVNC\vnc-3.3.7-x86_win32.exe/data0002 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
F:\Desktop Folder from Tosh 4600\VGA Scart RGB Conversion\RealVNC\vnc-3.3.7-x86_win32.exe/data0003 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
F:\Desktop Folder from Tosh 4600\VGA Scart RGB Conversion\RealVNC\vnc-3.3.7-x86_win32.exe/data0004 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
F:\Desktop Folder from Tosh 4600\VGA Scart RGB Conversion\RealVNC\vnc-3.3.7-x86_win32.exe Inno: infected - 3 skipped
F:\Desktop Folder from Tosh 4600\VNC\vnc-3.3.7-x86_win32.exe/data0002 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
F:\Desktop Folder from Tosh 4600\VNC\vnc-3.3.7-x86_win32.exe/data0003 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
F:\Desktop Folder from Tosh 4600\VNC\vnc-3.3.7-x86_win32.exe/data0004 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
F:\Desktop Folder from Tosh 4600\VNC\vnc-3.3.7-x86_win32.exe Inno: infected - 3 skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\Recovered Data From Office PC\DataSET\Data Set 1\TripleXpage_com\counter.htm Infected: Trojan-Downloader.VBS.Small.e skipped
G:\Recovered Data From Office PC\DO NOT USE\d1\pand1\new stuff\Gallery 1_files\de.html Infected: Trojan.JS.Seeker-based skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0190324.EXE/data.rar/xpkey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0190324.EXE/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0190324.EXE/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0190324.EXE RarSFX: infected - 3 skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0190335.EXE/data0002 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0190335.EXE/data0003 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0190335.EXE/data0004 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0190335.EXE Inno: infected - 3 skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0191624.EXE/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0191624.EXE/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0191624.EXE RarSFX: infected - 2 skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0192538.exe/WISE0013.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0192538.exe/WISE0014.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0192538.exe WiseSFX: infected - 2 skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0192538.exe WiseSFX Dropper: infected - 2 skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0192539.EXE/WISE0013.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0192539.EXE/WISE0014.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0192539.EXE WiseSFX: infected - 2 skipped
G:\System Volume Information\_restore{2386F767-522C-479B-B0BE-7E7F2B0A73A1}\RP924\A0192539.EXE WiseSFX Dropper: infected - 2 skipped

Scan process completed.


###################################### END OF KASPERSKY ONLINE SCAN REPORT #############


%%%%%%%%%%%%%%%% START OF HIJACKTHIS LOG %%%%%%%%%%%%%%%%%%%%%%%%%%%%

Logfile of HijackThis v1.99.1
Scan saved at 15:31:25, on 01/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
e:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
E:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\Executive Software\Undelete\UdServe.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Toshiba Controls\CpRmtKey.EXE
C:\Program Files\EzButton\CplBTQ00.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
E:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\test\Desktop\Malware Fix\HijackThis\hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE"
O4 - HKLM\..\Run: [CplBTQ00] C:\Program Files\EzButton\CplBTQ00.EXE
O4 - HKLM\..\Run: [DiskeeperSystray] "E:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C48 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I091.EXE /P23 "EPSON Stylus C48 Series" /O11 "PS504983_P1" /M "Stylus C48"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [SMSTray] e:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [RealPlayer] "e:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: MailWasherPro.lnk = E:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D6376DD2-C2BD-49B2-A1B1-138F869633F3} (ASPRO Installer Class) - http://acs.pandasoftware.com/activescanpro/as5/asproinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{879F1573-DE40-42B6-BE45-3EDE90A012ED}: NameServer = 192.168.0.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - e:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Diskeeper - Executive Software International, Inc. - E:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Symbol Technologies - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Executive Software Undelete (UndeleteService) - Executive Software International - E:\Program Files\Executive Software\Undelete\UdServe.exe

%%%%%%%%%%%%%%%% END OF HIJACKTHIS LOG %%%%%%%%%%%%%%%%%%%%%%%%%%%


I forward to hearing from you.

Thanks again, I really appreciate you taking the time out to solve my problem for me.

I only acquired the pc recently, secondhand, and I suspect that there's a lot of unecessary stuff on here?

Regards



G
Hi :)

Step 1

You aren't running anti-virus software. Please make sure you download and install one anti-virus program.

Use an Anti-Virus Program - It is very important that your computer has an anti-virus program running on your machine. This alone can save you a lot of trouble with malware in the future.

Here are a few (free) anti-virus programs, please download and install one of them:


Update your Anti-Virus Software - It is very important that you update your anti-virus software at least once a week (even more if you wish). If you do not update your anti-virus software then it will not be able to catch any of the new variants that will come out.

Step 2

You aren't running a firewall; please make sure you download and install one.

Use a Firewall - Without a firewall your computer is susceptible to being hacked and taken over. The Windows firewall isn't sufficient as it only monitors incoming connections.

Here are a few (free) firewalls, please download and install one of them:


Step 3

Copy the text below into a Notepad (Go to Start > Run, type Notepad and hit Enter) document:

REGEDIT4

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

Note: Make sure there is no blank line before REGEDIT4 and one blank line at the end.

Go to File > Save As:. Save the file as "Fix.reg" (Including the quotes)

Double-click on Fix.reg. When asked if you want to merge the file with the registry, click Yes.

Step 4

Navigate to the following files/folders using Windows Explorer and delete them when found:

C:\Documents and Settings\test\Desktop\Group Downloaders\picture ripper 3_59\e-pir359-2006-10-30.rar <– File
G:\Recovered Data From Office PC\DataSET\Data Set 1\TripleXpage_com\counter.htm <– File
G:\Recovered Data From Office PC\DO NOT USE\d1\pand1\new stuff\Gallery 1_files\de.html <– File
E:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\ <– Delete everything inside of this folder, not the folder itself!

Step 5

Click Start then Run….

  • Type Combofix /u in the runbox and click OK. (Note: The space between the x and the /u needs to be there)

    [external image: Posted Image]
  • When shown the disclaimer, select 2.

I only acquired the pc recently, secondhand, and I suspect that there's a lot of unecessary stuff on here?

There are a few items that can be disabled at start up:

Open HijackThis, perform a scan and put a check next to the following items (if present)

Note: this are optional fixes. If you want to keep a program to load when Windows starts, don't put a check next to it. These programs aren't necessary for the functioning of your computer or Windows, but you should the link next to every item to be sure it doesn't break another function you'd like to keep.

O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Info)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup (Info)
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install (Info)
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe (Info)
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe (Info)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe (Info)
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE" (Info)
O4 - HKLM\..\Run: [CplBTQ00] C:\Program Files\EzButton\CplBTQ00.EXE (Info)
O4 - HKLM\..\Run: [DiskeeperSystray] "E:\Program Files\Executive Software\Diskeeper\DkIcon.exe" (Info)
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe (Info)
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN (Info)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Info)
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE (Info)
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe (Info)
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect (Info)
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation (Info)
O4 - HKLM\..\Run: [SMSTray] e:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe (Info)
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide (Info)
O4 - HKCU\..\Run: [RealPlayer] "e:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot (Info)


Close all programs except HijackThis and click on Fix checked.

Post back with a final HijackThis log, and I'll give you some tips to stay clean in the future.
Hi Simon Thanks for the latest update. I will get on and carry out these tasks straight away. A fully licensed version of Norton Antivirus 2007 was installed on here until recently. It kept causing various error messages and was uninstalled. Would it be better to re-install Norton and sort out any errors with it OR install one of the free anti virus products you suggested? Will be back soon with the latest Hijackthis log. Thanks again. G

Would it be better to re-install Norton and sort out any errors with it OR install one of the free anti virus products you suggested?

You should be good with a free one, security wise. Norton has been reported to massively slow down systems, and it's not a program I'd suggest. It's a personal preference really, I'm not saying it's a bad product :) If you are having problems with it, I'd suggest you install one from my list.
Simon For Free Firewalls, Comodo seems to be well reviewed. There's a new version out recently. Do you have any recommendations whether to use CFP2.4 or CFP3.0? Some people seem to have had issues with the lastest version but I do not know how significant these are. Thanks G
Hi :) I don't use Comodo, but I've heard a few good things about version 3.0. You should always try to install the newest version, as it will have more advanced techniques, better detection rates etc… Also, the older version will probably get obsolete after a while, which will lead to the inability to download updates. You should only download the older version if/when you are experiencing problems with the newer version.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI