This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Live Safety Center, Online Security Guide Lots of pop

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Got this lame malware/adware/virus thing which:
- Live safety center and online security guides icons pop up again even after I delete them
- Pop ups saying that I have this virus and that spyware click this balloon to install official spyware/virus
removal programs
-Flashing caution sign on my toolbar which hides when I try to right click it

Heres the log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:36:55 PM, on 03/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [startdrv] C:\WINDOWS\Temp\startdrv.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [90f4b4ab] rundll32.exe "C:\WINDOWS\system32\dsikgyee.dll",b
O4 - HKLM\..\Run: [tcxspufw] rundll32.exe "C:\Program Files\otojqnid\utubknij.dll",Init
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvvur.dll,startup
O4 - HKLM\..\Run: [wdmzejqd] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\wdmzejqd.dll"
O4 - HKLM\..\Run: [SC2] C:\Program Files\SecCenter\scprot4.exe
O4 - HKLM\..\Run: [avp] C:\WINDOWS\TEMP\win58.exe
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Block this popup - C:\Program Files\Shaw Secure\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?21d93abd64f344d7a98459d0c3ea1d95
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?21d93abd64f344d7a98459d0c3ea1d95
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O20 - AppInit_DLLs: fontview.dll
O21 - SSODL: Internet Explorer - {F28A40D7-AD0E-034A-C651-5F0ED76232E6} - C:\WINDOWS\system32\Jjolpc32.dll
O21 - SSODL: fEEVPQCvKpeLHPX - {90F4B405-3A5E-1EAF-BA11-B61A92105CD4} - C:\WINDOWS\system32\ib.dll
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

–
End of file - 4848 bytes

Help please! :(
Welcome to the forum.

Download combofix.exe To Your Desktop from the link below:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Double click combofix.exe & follow the prompts.
A window will open with a warning.
Type "Y" (and Enter) to start the fix.
When the scan completes it will open a text window.
Please attach that log back here together with a fresh HJT log.
Caution - do not touch your mouse/keyboard until the scan has completed.
The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

Combofix will automatically save the log file to C:\combofix.txt

===================================

Please download SUPERAntiSpyware Home Edition (free)

Install it and double-click the icon on your desktop to run it.
It will ask if you want to update the program definitions, click Yes, Let it through your firewall!
Under Configuration and Preferences, click the Preferences button.
Click the Scanning Control tab.
Under Scanner Options make sure the following are checked:
  • Close browsers before scanning
  • Scan for tracking cookies
  • Terminate memory threats before quarantining.
  • Ignore System Restore/Volume Information on ME and XP
  • Please leave the others unchecked.
  • Click the Close button to leave the control center screen.
On the main screen, under Scan for Harmful Software click Scan your computer.
On the left check C:\Fixed Drive.
On the right, under Complete Scan, choose Perform Complete Scan.
Click Next to start the scan. Please be patient while it scans your computer.
After the scan is complete a summary box will appear. Click OK.
Make sure everything in the white box has a check next to it, then click Next.
It will quarantine what it found and if it asks if you want to reboot, click
Yes.

To retrieve the removal information - please do the following:
  • After reboot, double-click the SUPERAntispyware icon on your desktop.
  • Click Preferences . Click the Statistics/Logs tab .
  • Under Scanner Logs , double-click SUPERAntiSpyware Scan Log .
  • It will open in your default text editor (such as Notepad/Wordpad).
  • Please highlight everything , then right-click and choose copy.
  • Click close and close again to exit the program.
Now please paste the removal information along with a fresh HijackThis log and the log from ComboFix in your reply. If it's a large log, you may need several replies to post it.

MrC
ComboFix 07-12-02.7 - Ho 2007-12-07 15:42:32.2 - NTFSx86 DSREPAIR
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Ho\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Ho\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Ho\Favorites\Online Security Guide.lnk
C:\WINDOWS\system32\drivers\ctl_w32.sys
C:\WINDOWS\system32\drivers\symavc32.sys
C:\WINDOWS\system32\osrkcrky.dllbox
C:\WINDOWS\system32\xpdx.sys
.
—- Previous Run ——-
.
C:\Documents and Settings\Administrator\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Administrator\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Administrator\Favorites\Online Security Guide.lnk
C:\Documents and Settings\All Users\Application Data.\bcjalijy.dll
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Ho\Application Data\1602128405.exe
C:\Documents and Settings\Ho\Application Data\BestsellerAntivirus
C:\Documents and Settings\Ho\Application Data\BestsellerAntivirus\avtasks.dat
C:\Documents and Settings\Ho\Application Data\BestsellerAntivirus\Logs\av.log
C:\Documents and Settings\Ho\Application Data\BestsellerAntivirus\Logs\ga6Support.log
C:\Documents and Settings\Ho\Application Data\BestsellerAntivirus\Logs\update.log
C:\Documents and Settings\Ho\Application Data\BestsellerAntivirus\PGE.dat
C:\Documents and Settings\Ho\Application Data\c0mbta2.exe
C:\Documents and Settings\Ho\Application Data\macromedia\Flash Player\#SharedObjects\A8TEPN8S\iforex.com
C:\Documents and Settings\Ho\Application Data\macromedia\Flash Player\#SharedObjects\A8TEPN8S\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\Ho\Application Data\macromedia\Flash Player\#SharedObjects\A8TEPN8S\www.broadcaster.com
C:\Documents and Settings\Ho\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\Ho\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\Documents and Settings\Ho\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Ho\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\Ho\Application Data\SMANTE~1
C:\Documents and Settings\Ho\Application Data\SMANTE~1\S?mantec\
C:\Documents and Settings\Ho\Application Data\SMANTE~1\wucrtupd.exe
C:\Documents and Settings\Ho\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Ho\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Ho\Favorites\Online Security Guide.lnk
C:\paging.sys
C:\Program Files\Common Files\microsoft shared\web folders\ibm00001.dll
C:\Program Files\Common Files\microsoft shared\web folders\ibm00002.dll
C:\Program Files\Common Files\winctl.dll
C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe
C:\Program Files\winupdates
C:\UGA6P
C:\WINDOWS\avp.exe
C:\WINDOWS\b.exe
C:\WINDOWS\icroso~1.net
C:\WINDOWS\icroso~1.net\??curity\
C:\WINDOWS\mgrs.exe
C:\WINDOWS\qmdispatch.dll
C:\WINDOWS\system32\2_exception.nls
C:\WINDOWS\system32\drivers\ip6fw.sys
C:\WINDOWS\system32\drivers\symavc32.sys
C:\WINDOWS\system32\drvvurr.dll
C:\WINDOWS\system32\enwcfhuc.dll
C:\WINDOWS\system32\eyqvbgda.exe
C:\WINDOWS\system32\kbaqcsep.dll
C:\WINDOWS\system32\nuinopsd
C:\WINDOWS\system32\nuinopsd\bg1.gif
C:\WINDOWS\system32\nuinopsd\bgtop.gif
C:\WINDOWS\system32\nuinopsd\bottom1.gif
C:\WINDOWS\system32\nuinopsd\essentials.gif
C:\WINDOWS\system32\nuinopsd\icon1.ico
C:\WINDOWS\system32\nuinopsd\install1.gif
C:\WINDOWS\system32\nuinopsd\left1.gif
C:\WINDOWS\system32\nuinopsd\li.gif
C:\WINDOWS\system32\nuinopsd\logo.gif
C:\WINDOWS\system32\nuinopsd\main.htm
C:\WINDOWS\system32\nuinopsd\mainframe.htm
C:\WINDOWS\system32\nuinopsd\nuinopsd1.exe
C:\WINDOWS\system32\nuinopsd\nuinopsd2.exe
C:\WINDOWS\system32\nuinopsd\nuinopsd3.exe
C:\WINDOWS\system32\nuinopsd\reinstall1.gif
C:\WINDOWS\system32\nuinopsd\right1.gif
C:\WINDOWS\system32\nuinopsd\s1.htm
C:\WINDOWS\system32\nuinopsd\s2.htm
C:\WINDOWS\system32\nuinopsd\s3.htm
C:\WINDOWS\system32\nuinopsd\SMTop1.gif
C:\WINDOWS\system32\nuinopsd\SMTop2.gif
C:\WINDOWS\system32\nuinopsd\SMTop3.gif
C:\WINDOWS\system32\nuinopsd\SMTop4.gif
C:\WINDOWS\system32\nuinopsd\soft1_off.gif
C:\WINDOWS\system32\nuinopsd\soft1_off_ext.gif
C:\WINDOWS\system32\nuinopsd\soft1_on.gif
C:\WINDOWS\system32\nuinopsd\soft1_on_ext.gif
C:\WINDOWS\system32\nuinopsd\soft2_off.gif
C:\WINDOWS\system32\nuinopsd\soft2_off_ext.gif
C:\WINDOWS\system32\nuinopsd\soft2_on.gif
C:\WINDOWS\system32\nuinopsd\soft2_on_ext.gif
C:\WINDOWS\system32\nuinopsd\soft3_off.gif
C:\WINDOWS\system32\nuinopsd\soft3_off_ext.gif
C:\WINDOWS\system32\nuinopsd\soft3_on.gif
C:\WINDOWS\system32\nuinopsd\soft3_on_ext.gif
C:\WINDOWS\system32\nuinopsd\softbottom_off.gif
C:\WINDOWS\system32\nuinopsd\softbottom_on.gif
C:\WINDOWS\system32\nuinopsd\softleft_off.gif
C:\WINDOWS\system32\nuinopsd\softleft_on.gif
C:\WINDOWS\system32\nuinopsd\top1.gif
C:\WINDOWS\system32\nuinopsd\top2.gif
C:\WINDOWS\system32\nuinopsd\turnoff1.gif
C:\WINDOWS\system32\nuinopsd\turnon1.gif
C:\WINDOWS\system32\osrkcrky.dllbox
C:\WINDOWS\system32\pdifuyrb.dll
C:\WINDOWS\system32\prutv.ini
C:\WINDOWS\system32\prutv.ini2
C:\WINDOWS\system32\uaggcvqp.dll
C:\WINDOWS\system32\windbg__
C:\WINDOWS\system32\winrzf32.dll
C:\WINDOWS\system32\wnsxs~1
C:\WINDOWS\system32\wvuuvvs.dll
C:\WINDOWS\system32\xpdx.sys
C:\WINDOWS\xpupdate.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CTL_W32
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_NTMLSVC
——-\LEGACY_RUNTIME
——-\LEGACY_SYMAVC32
——-\DomainService
——-\NtmlSvc
——-\runtime
——-\symavc32


——-\ctl_w32


((((((((((((((((((((((((( Files Created from 2007-11-08 to 2007-12-08 )))))))))))))))))))))))))))))))
.

2007-12-19 16:06 . 2007-12-06 17:58 159,298 –a–c— C:\pic.bmp
2007-12-19 16:04 . 2007-12-19 15:56 109,248 –a—— C:\WINDOWS\system\MSWINSCK.OCX
2007-12-19 15:56 . 2007-12-19 15:56 109,248 –a—— C:\WINDOWS\system32\MSWINSCK.OCX
2007-12-07 15:34 . 2007-12-07 16:25 6,661 –ahs—- C:\WINDOWS\system32\prutv.ini
2007-12-07 15:34 . 2007-12-07 16:25 6,559 –ahs—- C:\WINDOWS\system32\prutv.ini2
2007-12-07 14:38 . 2007-12-07 14:38 d——– C:\Program Files\Jpvxatts
2007-12-07 14:36 . 2007-12-07 14:36 d——– C:\Program Files\wlsdqbmn
2007-12-06 19:11 . 2007-12-06 19:11 d—-c— C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-06 18:34 . 2007-12-06 18:34 d—-c— C:\Lager
2007-12-06 18:16 . 2007-12-06 18:16 74,304 –a—— C:\WINDOWS\system32\vkosnwwb.exe
2007-12-06 17:48 . 2007-12-06 17:48 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-06 17:48 . 2007-12-06 17:48 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-05 21:18 . 2007-12-05 21:18 d——– C:\Program Files\AmitySource
2007-12-05 16:12 . 2007-12-05 16:12 807,468 —hs—- C:\WINDOWS\system32\dslvgnpu.ini
2007-12-05 16:02 . 2007-12-05 16:02 74,304 –a—— C:\WINDOWS\system32\kxyjcpkf.exe
2007-12-05 16:00 . 2007-12-05 16:00 145,984 –a—— C:\WINDOWS\system32\osrkcrky.dll
2007-12-05 15:59 . 2007-12-05 15:59 145,984 –a—— C:\WINDOWS\system32\feuniyly.dll
2007-12-03 20:36 . 2007-12-06 20:11 d——– C:\Program Files\Trend Micro
2007-12-03 20:04 . 2007-12-03 20:04 d——– C:\Program Files\Fefwmdpc
2007-12-03 20:04 . 2007-12-03 20:08 143 –a—— C:\WINDOWS\system32\mcrh.tmp
2007-12-03 20:03 . 2007-12-03 20:03 34,304 –a—— C:\WINDOWS\system32\ddccywt.dll
2007-12-03 19:29 . 2007-12-03 19:29 d—-c— C:\VundoFix Backups
2007-12-03 17:18 . 2007-12-03 17:18 793,980 —hs—- C:\WINDOWS\system32\eeygkisd.ini
2007-12-03 14:47 . 2007-12-03 14:54 d—-c— C:\Starcraft
2007-12-02 14:12 . 2007-12-03 19:33 d—-c— C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-02 13:30 . 2007-12-02 13:30 d——– C:\Program Files\Bonjour
2007-12-02 13:18 . 2007-12-02 13:18 d——– C:\Program Files\Common Files\Macrovision Shared
2007-12-02 12:58 . 2004-10-07 13:39 89,088 –a—— C:\WINDOWS\system32\atl71.dll
2007-12-02 12:58 . 2001-03-08 18:30 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-12-02 08:16 . 2007-12-02 08:16 40,448 –a—— C:\WINDOWS\system32\urqqqrr.dll
2007-12-02 08:15 . 2007-12-02 08:15 793,664 —hs—- C:\WINDOWS\system32\gimgfkbc.ini
2007-12-02 08:15 . 2007-12-02 08:15 40,448 –a—— C:\WINDOWS\system32\gebyywu.dll
2007-12-02 08:12 . 2007-12-02 08:12 40,448 –a—— C:\WINDOWS\system32\pmnkjge.dll
2007-12-02 08:12 . 2007-12-02 08:16 283 –a–c— C:\-1863011324
2007-11-24 10:28 . 2007-11-06 14:31 d——– C:\Program Files\Cheat Engine
2007-11-24 10:28 . 2006-09-04 19:16 1,970,176 –a—— C:\WINDOWS\system32\d3dx9.dll
2007-11-24 10:28 . 2006-09-04 19:16 679,936 –a—— C:\WINDOWS\system32\D3DX81ab.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-07 04:10 ——— d—–w C:\Program Files\Project64 1.6
2007-12-07 04:07 ——— d—–w C:\Program Files\Steam
2007-12-07 03:11 ——— d—–w C:\Program Files\Lavasoft
2007-12-07 03:11 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-07 02:39 ——— d—–w C:\Program Files\FlashGet
2007-12-07 02:34 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-04 23:43 ——— d—–w C:\Program Files\Trickster Online
2007-12-04 21:27 ——— dc—-w C:\Documents and Settings\Ho\Application Data\Reno 911 Paintball
2007-12-04 04:03 ——— d—–w C:\Program Files\MalwareAlarm
2007-12-04 01:24 ——— dc-h–w C:\Documents and Settings\Ho\Application Data\ijjigame
2007-12-03 22:49 94,208 —-a-w C:\WINDOWS\ScUnin.exe
2007-12-03 00:45 ——— dc—-w C:\Documents and Settings\Ho\Application Data\gtk-2.0
2007-12-02 21:30 ——— d—–w C:\Program Files\Common Files\Adobe
2007-12-02 04:16 64,512 -c–a-w C:\Documents and Settings\Ho\keygen.exe
2007-11-18 20:17 31 -c–a-w C:\Documents and Settings\Ho\RUNME.bat
2007-11-15 16:15 9,728 -c–a-w C:\Documents and Settings\Ho\crack.exe
2007-11-07 06:17 ——— d—–w C:\Program Files\QuickTime
2007-11-07 06:15 ——— d—–w C:\Program Files\Apple Software Update
2007-11-07 06:13 ——— d—–w C:\Program Files\Windows Installer Clean Up
2007-11-07 06:13 ——— d—–w C:\Program Files\MSECACHE
2007-11-07 06:00 ——— d—–w C:\Program Files\Easy FLV Converter
2007-11-07 05:55 ——— d—–w C:\Program Files\Total Video Converter
2007-11-07 05:48 ——— d—–w C:\Program Files\Moyea
2007-11-07 05:42 ——— dc—-w C:\Documents and Settings\Ho\Application Data\Moyea
2007-11-07 01:07 ——— dc—-w C:\Documents and Settings\Ho\Application Data\LimeWire
2007-11-06 04:46 65,536 —-a-w C:\WINDOWS\IFinst27.exe
2007-11-06 02:28 ——— d—–w C:\Program Files\SealOnlineUSA
2007-10-27 22:00 ——— d—–w C:\Program Files\Starcraft
2007-10-24 04:19 ——— d—–w C:\Program Files\Speed Gear 5
2007-10-24 04:17 ——— dc—-w C:\Documents and Settings\Ho\Application Data\GetRightToGo
2007-10-24 04:16 ——— d—–w C:\Program Files\SpeederXP
2007-10-21 04:30 ——— d—–w C:\Program Files\UrbanTerror
2007-10-21 03:24 ——— d—–w C:\Program Files\AssaultCube
2007-10-21 01:03 ——— d—–w C:\Program Files\e-Games
2007-10-19 01:56 ——— d—–w C:\Program Files\Softnyx
2007-10-13 03:56 ——— d—–w C:\Program Files\GustoSoft
2007-10-13 03:55 ——— d—–w C:\Program Files\Zortam Mp3 Player
2007-10-13 03:46 ——— dc–a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-11 01:13 ——— d—–w C:\Program Files\Common Files\Apple
2007-10-09 02:59 ——— d—–w C:\Program Files\Common Files\xing shared
2007-10-09 02:59 ——— d—–w C:\Program Files\Common Files\Real
2007-10-09 02:58 ——— d—–w C:\Program Files\Real
2007-10-08 20:16 ——— d—–w C:\Program Files\Windows Media Connect 2
2007-09-10 18:55 692,224 —-a-w C:\WINDOWS\system32\ijjiSetup.exe
2004-06-09 23:03 832,728 —-a-w C:\Program Files\NPSWF32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0CF46468-AC82-9EC5-5B79-008AA7762D88}]
2007-12-07 14:38 106496 –a—— C:\Program Files\Jpvxatts\ypzaqftl.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30BAA4DF-E0AB-4AFD-B6D8-FFAA032D0468}]
2005-11-06 22:49 34304 –a—— C:\WINDOWS\system32\yaywxwt.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4ACAA103-B0E1-4774-9917-BBCE4EB87691}]
2005-11-06 22:54 336480 –a—— C:\WINDOWS\system32\vturp.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{62780D18-D103-03D3-323A-01F43008B839}]
2007-12-03 20:04 98304 –a—— C:\Program Files\Fefwmdpc\rarrgffu.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-12-05 16:00 145984 –a—— C:\WINDOWS\system32\osrkcrky.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\osrkcrky.dll [2007-12-05 16:00 145984]

[HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-11 19:50]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-03 14:56]
"pccguide.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe" [2003-03-26 05:00]
"PCCClient.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe" [2003-03-26 04:52]
"Pop3trap.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe" [2003-03-26 04:56]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 14:56]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{30BAA4DF-E0AB-4AFD-B6D8-FFAA032D0468}"= C:\WINDOWS\system32\yaywxwt.dll [2005-11-06 22:49 34304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"Internet Explorer"= {F28A40D7-AD0E-034A-C651-5F0ED76232E6} - C:\WINDOWS\system32\Jjolpc32.dll [2007-07-10 12:53 6657]
"fEEVPQCvKpeLHPX"= {90F4B405-3A5E-1EAF-BA11-B61A92105CD4} - C:\WINDOWS\system32\ib.dll [2004-08-03 14:56 32256]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\osrkcrky]
osrkcrky.dll 2007-12-05 16:00 145984 C:\WINDOWS\system32\osrkcrky.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yaywxwt]
yaywxwt.dll 2005-11-06 22:49 34304 C:\WINDOWS\system32\yaywxwt.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\vturp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Nintendo Wi-Fi USB Connector Registration Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Run Nintendo Wi-Fi USB Connector Registration Tool.lnk
backup=C:\WINDOWS\pss\Run Nintendo Wi-Fi USB Connector Registration Tool.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^svchost.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe
backup=C:\WINDOWS\pss\svchost.exeCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ho^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Ho\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\90f4b4ab]
rundll32.exe C:\WINDOWS\system32\upngvlsd.dll,b

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\TEMP\win58.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
rundll32.exe C:\WINDOWS\system32\drvvur.dll,startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-03 14:56 15360 –a—— C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\epqtqdwj]
rundll32.exe C:\Program Files\epqtqdwj\ohevwhet.dll,Init

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
Logi_MwX.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaKey]
2003-05-21 19:19 180224 –a—— C:\PROGRA~1\MediaKey\MMKeybd.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft ActiveSync]
2007-07-10 12:53 23552 –a—— C:\WINDOWS\twain_32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rtasks]
C:\Program Files\BestsellerAntivirus\rtasks.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Salestart]
C:\Program Files\Common Files\BestsellerAntivirus\bm.exe dm=http://bestsellerantivirus.com; ad=http://bestsellerantivirus.com

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SC2]
C:\Program Files\SecCenter\scprot4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Tray]
2003-08-19 13:12 675840 –a—— C:\WINDOWS\system32\sistray.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook]
2003-08-19 13:11 249856 –a—— C:\WINDOWS\system32\keyhook.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]
2002-07-12 02:15 114688 –a—— C:\WINDOWS\SiSUSBrg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp]
2003-05-05 07:57 151552 –a—— C:\Program Files\Analog Devices\SoundMAX\SMTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
mgrs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sncpufyh]
regsvr32 /u C:\Documents and Settings\All Users\Application Data\sncpufyh.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-03-14 02:43 83608 –a—— C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-08-11 19:50 68856 –a—— C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tcxspufw]
rundll32.exe C:\Program Files\otojqnid\utubknij.dll,Init

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wdmzejqd]
regsvr32 /u C:\Documents and Settings\All Users\Application Data\wdmzejqd.dll

R2 PCC_PFW;PC-Cillin Personal Firewall;C:\WINDOWS\system32\Drivers\PCC_PFW.sys
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\system32\Drivers\DKbFltr.sys
S3 CEDRIVER53;CEDRIVER53;\??\C:\Program Files\Cheat Engine\dbk32.sys
S3 CrucialSMBusScan;CrucialSMBusScan;\??\C:\WINDOWS\system32\drivers\CrucialSMBusScan.sys
S3 geebers12;geebers12;\??\C:\Documents and Settings\Ho\Desktop\Hax\Exterm\Xterminator Engine 2.0\Xterminator.sys
S3 iCheat1;iCheat1;\??\C:\Program Files\Maple-Fun\iCheat\nvid999.sys
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;\??\C:\Documents and Settings\Ho\Desktop\Hack pack\Moonlight Engine 1059.22\MoonLight Engine_1059.22\IlvMoney1059a.sys
S3 kaspersky1;kaspersky1;\??\C:\Documents and Settings\Ho\Desktop\Folders\Hax\Kaspersky_Engine_3[1][1].2\kaspersky.sys
S3 memxers12;memxers12;\??\C:\Documents and Settings\Ho\Desktop\Hax\vicious 5.1\New Folder\nvid999.sys
S3 muIO;muIO;\??\C:\WINDOWS\system32\muIO.sys
S3 PageFau1t;PageFau1t;\??\C:\Documents and Settings\Ho\Desktop\launcher\bypasss\bypasss\PageFau1t.sys

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Bin\Assetup.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-11-07 06:16:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-07 23:58:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-07 16:25:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
"ImagePath"="\??\C:\Documents and Settings\Ho\Desktop\Folders\Hax\Kaspersky_Engine_3
[1][1].2\kaspersky.sys"

.
Completion time: 2007-12-07 16:35:30 - machine was rebooted
.
— E O F —






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:49:15 PM, on 07/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\osrkcrky.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Block this popup - C:\Program Files\Shaw Secure\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?21d93abd64f344d7a98459d0c3ea1d95
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?21d93abd64f344d7a98459d0c3ea1d95
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O21 - SSODL: Internet Explorer - {F28A40D7-AD0E-034A-C651-5F0ED76232E6} - C:\WINDOWS\system32\Jjolpc32.dll
O21 - SSODL: fEEVPQCvKpeLHPX - {90F4B405-3A5E-1EAF-BA11-B61A92105CD4} - C:\WINDOWS\system32\ib.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe

–
End of file - 6333 bytes


ISP was down for a couple of days startup used to take about 2 mins now its about 40

1 question the SUPER Anti-Spyware scanner thing always stops on a file and just freezes there.Do I really have to do the scan?
OK, please follow these directions carefully.

Enable hidden files:
Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked.
Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK" (reverse this procedure when we are done)

——————-

Please find these files and upload them
HERE for a free scan - let me know the results.

C:\Documents and Settings\Ho\keygen.exe
C:\Documents and Settings\Ho\crack.exe
C:\WINDOWS\IFinst27.exe


If it's too busy - try here:
http://www.virustotal.com/en/indexf.html

—————————–

Please open Notepad (Start > Run > in the Open field type: notepad)
Click: OK

Copy/ paste the blue text below to Notepad:

File::
C:\WINDOWS\system32\prutv.ini
C:\WINDOWS\system32\prutv.ini2
C:\WINDOWS\system32\vkosnwwb.exe
C:\WINDOWS\system32\dslvgnpu.ini
C:\WINDOWS\system32\kxyjcpkf.exe
C:\WINDOWS\system32\osrkcrky.dll
C:\WINDOWS\system32\feuniyly.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\ddccywt.dll
C:\WINDOWS\system32\eeygkisd.ini
C:\WINDOWS\system32\urqqqrr.dll
C:\WINDOWS\system32\gimgfkbc.ini
C:\WINDOWS\system32\gebyywu.dll
C:\WINDOWS\system32\pmnkjge.dll
C:\WINDOWS\system32\ijjiSetup.exe
C:\WINDOWS\system32\yaywxwt.dll
C:\WINDOWS\system32\vturp.dll
C:\WINDOWS\system32\Jjolpc32.dll
C:\WINDOWS\system32\upngvlsd.dll
C:\WINDOWS\system32\drvvur.dll
C:\WINDOWS\system32\ib.dll
C:\Documents and Settings\All Users\Application Data\wdmzejqd.dll
C:\Documents and Settings\All Users\Application Data\sncpufyh.dll
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe

Folder::
C:\Program Files\Jpvxatts
C:\Program Files\wlsdqbmn
C:\Program Files\Fefwmdpc
C:\Program Files\epqtqdwj
C:\Program Files\otojqnid
C:\Program Files\Common Files\BestsellerAntivirus
C:\WINDOWS\pss

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0CF46468-AC82-9EC5-5B79-008AA7762D88}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30BAA4DF-E0AB-4AFD-B6D8-FFAA032D0468}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4ACAA103-B0E1-4774-9917-BBCE4EB87691}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{62780D18-D103-03D3-323A-01F43008B839}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= -
[-HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{30BAA4DF-E0AB-4AFD-B6D8-FFAA032D0468}"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"Internet Explorer"=-
"fEEVPQCvKpeLHPX"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\osrkcrky]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yaywxwt]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^svchost.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\90f4b4ab]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\epqtqdwj]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Salestart]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sncpufyh]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tcxspufw]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wdmzejqd]


Save as CFScript.txt
Change the "Save as type" to "All Files"
Save it to the Desktop.
Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

After reboot, (in case it asks to reboot)……
Please provide the contents of the ComboFix log in your next reply and a fresh HJT log, MrC
File: keygen.exe Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) MD5: 4da280c5fa0d02de0df7eb3da20da2af Packers detected: - Bit9 reports: File not found Scan taken on 08 Dec 2007 17:24:22 (GMT) A-Squared Found nothing AntiVir Found ADSPY/Virtumonde.bho ArcaVir Found Adware.Virtumonde.Bho Avast Found nothing AVG Antivirus Found SHeur.AEJQ BitDefender Found nothing ClamAV Found nothing CPsecure Found AdWare.W32.Virtumonde.bho Dr.Web Found Trojan.Virtumod.245 F-Prot Antivirus Found nothing F-Secure Anti-Virus Found not-a-virus:AdWare.Win32.Virtumonde.bho (4, 1, 400) Fortinet Found nothing Ikarus Found not-a-virus:AdWare.Win32.Virtumonde.bho Kaspersky Anti-Virus Found not-a-virus:AdWare.Win32.Virtumonde.bho NOD32 Found nothing Norman Virus Control Found Vundo.AD Panda Antivirus Found nothing Rising Antivirus Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found AdWare.Win32.Virtumonde.bho File: crack.exe Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) MD5: bbd571f939426a23b07f60f981816c4d Packers detected: - Bit9 reports: File not found Scan taken on 08 Dec 2007 17:28:24 (GMT) A-Squared Found Trojan.Win32.Inject.ks AntiVir Found TR/Crypt.U.Gen ArcaVir Found Trojan.Inject.Ks Avast Found nothing AVG Antivirus Found Proxy.VVE BitDefender Found Trojan.Downloader.LoadAdv.XXA ClamAV Found Trojan.Inject-51 CPsecure Found Troj.W32.Inject.ks Dr.Web Found Trojan.Packed.155 F-Prot Antivirus Found nothing F-Secure Anti-Virus Found Trojan.Win32.Inject.ks Fortinet Found W32/Small.0E6F!tr Ikarus Found Trojan.Win32.Inject.ks Kaspersky Anti-Virus Found Trojan.Win32.Inject.ks NOD32 Found a variant of Win32/TrojanDownloader.Agent.NSP Norman Virus Control Found W32/Inject.ZI Panda Antivirus Found nothing Rising Antivirus Found nothing Sophos Antivirus Found Mal/HckPk-A VirusBuster Found nothing VBA32 Found Trojan.Win32.Inject.ks C:\WINDOWS\IFinst27.exe File: IFinst27.exe Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) MD5: 9c17bca3ef837bacded7e4299508e71d Packers detected: UPX Bit9 reports: No threat detected (more info) can taken on 08 Dec 2007 17:19:56 (GMT) A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Ikarus Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Rising Antivirus Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found Trojan-Downloader.Win32.Banload.tn
ComboFix 07-12-02.7 - Ho 2007-12-08 9:33:00.3 - NTFSx86 DSREPAIR
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Ho\Desktop\cfscript.txt

FILE
C:\Documents and Settings\All Users\Application Data\sncpufyh.dll
C:\Documents and Settings\All Users\Application Data\wdmzejqd.dll
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe
C:\WINDOWS\system32\ddccywt.dll
C:\WINDOWS\system32\drvvur.dll
C:\WINDOWS\system32\dslvgnpu.ini
C:\WINDOWS\system32\eeygkisd.ini
C:\WINDOWS\system32\feuniyly.dll
C:\WINDOWS\system32\gebyywu.dll
C:\WINDOWS\system32\gimgfkbc.ini
C:\WINDOWS\system32\ib.dll
C:\WINDOWS\system32\ijjiSetup.exe
C:\WINDOWS\system32\Jjolpc32.dll
C:\WINDOWS\system32\kxyjcpkf.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\osrkcrky.dll
C:\WINDOWS\system32\pmnkjge.dll
C:\WINDOWS\system32\prutv.ini
C:\WINDOWS\system32\prutv.ini2
C:\WINDOWS\system32\upngvlsd.dll
C:\WINDOWS\system32\urqqqrr.dll
C:\WINDOWS\system32\vkosnwwb.exe
C:\WINDOWS\system32\vturp.dll
C:\WINDOWS\system32\yaywxwt.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Ho\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Ho\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Ho\Favorites\Online Security Guide.lnk
C:\WINDOWS\pss
C:\WINDOWS\pss\Adobe Gamma.lnkStartup
C:\WINDOWS\pss\boot.ini.backup
C:\WINDOWS\pss\NaturalColorLoad.lnkCommon Startup
C:\WINDOWS\pss\NaturalColorLoad.lnkStartup
C:\WINDOWS\pss\Run Nintendo Wi-Fi USB Connector Registration Tool.lnkCommon Startup
C:\WINDOWS\pss\svchost.exeCommon Startup
C:\WINDOWS\pss\system.ini.backup
C:\WINDOWS\pss\win.ini.backup
C:\WINDOWS\pss\Xfire.lnkStartup
C:\WINDOWS\system32\ddccywt.dll
C:\WINDOWS\system32\dslvgnpu.ini
C:\WINDOWS\system32\eeygkisd.ini
C:\WINDOWS\system32\feuniyly.dll
C:\WINDOWS\system32\gebyywu.dll
C:\WINDOWS\system32\gimgfkbc.ini
C:\WINDOWS\system32\ib.dll
C:\WINDOWS\system32\ijjiSetup.exe
C:\WINDOWS\system32\Jjolpc32.dll
C:\WINDOWS\system32\kxyjcpkf.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\osrkcrky.dll
C:\WINDOWS\system32\osrkcrky.dllbox
C:\WINDOWS\system32\pmnkjge.dll
C:\WINDOWS\system32\prutv.ini
C:\WINDOWS\system32\prutv.ini2
C:\WINDOWS\system32\urqqqrr.dll
C:\WINDOWS\system32\vkosnwwb.exe
C:\WINDOWS\system32\vturp.dll
C:\WINDOWS\system32\yaywxwt.dll

.
((((((((((((((((((((((((( Files Created from 2007-11-08 to 2007-12-08 )))))))))))))))))))))))))))))))
.

2007-12-19 16:06 . 2007-12-08 09:08 159,298 –a–c— C:\pic.bmp
2007-12-19 16:04 . 2007-12-19 15:56 109,248 –a—— C:\WINDOWS\system\MSWINSCK.OCX
2007-12-19 15:56 . 2007-12-19 15:56 109,248 –a—— C:\WINDOWS\system32\MSWINSCK.OCX
2007-12-07 20:04 . 2007-12-07 20:04 d——– C:\Program Files\YourWare Solutions
2007-12-07 17:08 . 2007-12-07 17:08 d—-c— C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-07 17:02 . 2007-12-07 18:55 d——– C:\Program Files\SUPERAntiSpyware
2007-12-07 17:02 . 2007-12-07 17:02 d—-c— C:\Documents and Settings\Ho\Application Data\SUPERAntiSpyware.com
2007-12-06 19:11 . 2007-12-06 19:11 d—-c— C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-06 17:48 . 2007-12-06 17:48 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-06 17:48 . 2007-12-06 17:48 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-05 21:18 . 2007-12-05 21:18 d——– C:\Program Files\AmitySource
2007-12-03 20:36 . 2007-12-06 20:11 d——– C:\Program Files\Trend Micro
2007-12-03 19:29 . 2007-12-03 19:29 d—-c— C:\VundoFix Backups
2007-12-03 14:47 . 2007-12-03 14:54 d—-c— C:\Starcraft
2007-12-02 14:12 . 2007-12-03 19:33 d—-c— C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-02 13:30 . 2007-12-02 13:30 d——– C:\Program Files\Bonjour
2007-12-02 13:18 . 2007-12-02 13:18 d——– C:\Program Files\Common Files\Macrovision Shared
2007-12-02 12:58 . 2004-10-07 13:39 89,088 –a—— C:\WINDOWS\system32\atl71.dll
2007-12-02 12:58 . 2001-03-08 18:30 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-12-02 08:12 . 2007-12-02 08:16 283 –a–c— C:\-1863011324
2007-11-24 10:28 . 2007-11-06 14:31 d——– C:\Program Files\Cheat Engine
2007-11-24 10:28 . 2006-09-04 19:16 1,970,176 –a—— C:\WINDOWS\system32\d3dx9.dll
2007-11-24 10:28 . 2006-09-04 19:16 679,936 –a—— C:\WINDOWS\system32\D3DX81ab.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-08 00:59 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-07 04:07 ——— d—–w C:\Program Files\Steam
2007-12-07 03:11 ——— d—–w C:\Program Files\Lavasoft
2007-12-07 02:39 ——— d—–w C:\Program Files\FlashGet
2007-12-07 02:34 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-04 21:27 ——— dc—-w C:\Documents and Settings\Ho\Application Data\Reno 911 Paintball
2007-12-04 01:24 ——— dc-h–w C:\Documents and Settings\Ho\Application Data\ijjigame
2007-12-03 22:49 94,208 —-a-w C:\WINDOWS\ScUnin.exe
2007-12-03 00:45 ——— dc—-w C:\Documents and Settings\Ho\Application Data\gtk-2.0
2007-12-02 21:30 ——— d—–w C:\Program Files\Common Files\Adobe
2007-12-02 04:16 64,512 -c–a-w C:\Documents and Settings\Ho\keygen.exe
2007-11-18 20:17 31 -c–a-w C:\Documents and Settings\Ho\RUNME.bat
2007-11-15 16:15 9,728 -c–a-w C:\Documents and Settings\Ho\crack.exe
2007-11-07 06:17 ——— d—–w C:\Program Files\QuickTime
2007-11-07 06:15 ——— d—–w C:\Program Files\Apple Software Update
2007-11-07 06:13 ——— d—–w C:\Program Files\Windows Installer Clean Up
2007-11-07 06:13 ——— d—–w C:\Program Files\MSECACHE
2007-11-07 06:00 ——— d—–w C:\Program Files\Easy FLV Converter
2007-11-07 05:55 ——— d—–w C:\Program Files\Total Video Converter
2007-11-07 05:42 ——— dc—-w C:\Documents and Settings\Ho\Application Data\Moyea
2007-11-07 01:07 ——— dc—-w C:\Documents and Settings\Ho\Application Data\LimeWire
2007-11-06 04:46 65,536 —-a-w C:\WINDOWS\IFinst27.exe
2007-10-27 22:00 ——— d—–w C:\Program Files\Starcraft
2007-10-24 04:19 ——— d—–w C:\Program Files\Speed Gear 5
2007-10-24 04:17 ——— dc—-w C:\Documents and Settings\Ho\Application Data\GetRightToGo
2007-10-24 04:16 ——— d—–w C:\Program Files\SpeederXP
2007-10-21 04:30 ——— d—–w C:\Program Files\UrbanTerror
2007-10-19 01:56 ——— d—–w C:\Program Files\Softnyx
2007-10-13 03:46 ——— dc–a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-11 01:13 ——— d—–w C:\Program Files\Common Files\Apple
2007-10-09 02:59 ——— d—–w C:\Program Files\Common Files\xing shared
2007-10-09 02:59 ——— d—–w C:\Program Files\Common Files\Real
2007-10-09 02:58 ——— d—–w C:\Program Files\Real
2007-10-08 20:16 ——— d—–w C:\Program Files\Windows Media Connect 2
2004-06-09 23:03 832,728 —-a-w C:\Program Files\NPSWF32.dll
.

((((((((((((((((((((((((((((( snapshot@2007-12-07_16.26.41.96 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-08 01:05:22 29,696 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
+ 2007-12-08 01:05:22 18,944 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2007-12-08 01:05:22 65,024 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
- 2007-12-04 00:55:06 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-12-08 17:05:38 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-12-04 00:55:06 49,152 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-08 17:05:38 49,152 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-08 17:05:37 10,752 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\317571UA\runfile[4].exe
- 2007-12-04 00:55:06 81,920 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-08 17:05:38 81,920 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-11 19:50]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"FreeRAM XP"="C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 00:13]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-03 14:56]
"pccguide.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe" [2003-03-26 05:00]
"PCCClient.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe" [2003-03-26 04:52]
"Pop3trap.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe" [2003-03-26 04:56]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 14:56]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\vturp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Nintendo Wi-Fi USB Connector Registration Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Run Nintendo Wi-Fi USB Connector Registration Tool.lnk
backup=C:\WINDOWS\pss\Run Nintendo Wi-Fi USB Connector Registration Tool.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ho^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Ho\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\TEMP\win58.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-03 14:56 15360 –a—— C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
Logi_MwX.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaKey]
2003-05-21 19:19 180224 –a—— C:\PROGRA~1\MediaKey\MMKeybd.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft ActiveSync]
2007-07-10 12:53 23552 –a—— C:\WINDOWS\twain_32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rtasks]
C:\Program Files\BestsellerAntivirus\rtasks.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SC2]
C:\Program Files\SecCenter\scprot4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Tray]
2003-08-19 13:12 675840 –a—— C:\WINDOWS\system32\sistray.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook]
2003-08-19 13:11 249856 –a—— C:\WINDOWS\system32\keyhook.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]
2002-07-12 02:15 114688 –a—— C:\WINDOWS\SiSUSBrg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp]
2003-05-05 07:57 151552 –a—— C:\Program Files\Analog Devices\SoundMAX\SMTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-03-14 02:43 83608 –a—— C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-08-11 19:50 68856 –a—— C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Bin\Assetup.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-11-07 06:16:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-08 05:58:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-08 09:40:31
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

**************************************************************************
"ImagePath"="\??\C:\Documents and Settings\Ho\Desktop\Folders\Hax\Kaspersky_Engine_3
[1][1].2\kaspersky.sys"

.
Completion time: 2007-12-08 9:42:55 - machine was rebooted
C:\ComboFix2.txt … 2007-12-07 16:35
.
— E O F —












Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:46:29 AM, on 08/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Block this popup - C:\Program Files\Shaw Secure\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?21d93abd64f344d7a98459d0c3ea1d95
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?21d93abd64f344d7a98459d0c3ea1d95
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe

–
End of file - 6804 bytes

To retrieve the removal information - please do the following:

  • After reboot, double-click the SUPERAntispyware icon on your desktop.
  • Click Preferences . Click the Statistics/Logs tab .
  • Under Scanner Logs , double-click SUPERAntiSpyware Scan Log .
  • It will open in your default text editor (such as Notepad/Wordpad).
  • Please highlight everything , then right-click and choose copy.
  • Click close and close again to exit the program.
Now please paste the removal information along with a fresh HijackThis log and the log from ComboFix in your reply. If it's a large log, you may need several replies to post it.

MrC



Finally the scan finishes had to do it twice




SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/07/2007 at 06:04 PM

Application Version : 3.9.1008

Core Rules Database Version : 3358
Trace Rules Database Version: 1357

Scan type : Complete Scan
Total Scan Time : 00:51:23

Memory items scanned : 294
Memory threats detected : 3
Registry items scanned : 5103
Registry threats detected : 40
File items scanned : 2838
File threats detected : 45

Adware.Vundo-Variant
C:\WINDOWS\SYSTEM32\OSRKCRKY.DLL
C:\WINDOWS\SYSTEM32\OSRKCRKY.DLL
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\osrkcrky

Adware.Vundo-Variant/Small
C:\WINDOWS\SYSTEM32\YAYWXWT.DLL
C:\WINDOWS\SYSTEM32\YAYWXWT.DLL
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\yaywxwt

Adware.Vundo Variant
C:\WINDOWS\SYSTEM32\VTURP.DLL
C:\WINDOWS\SYSTEM32\VTURP.DLL
HKLM\Software\Classes\CLSID\{30BAA4DF-E0AB-4AFD-B6D8-FFAA032D0468}
HKCR\CLSID\{30BAA4DF-E0AB-4AFD-B6D8-FFAA032D0468}
HKCR\CLSID\{30BAA4DF-E0AB-4AFD-B6D8-FFAA032D0468}\InprocServer32
HKCR\CLSID\{30BAA4DF-E0AB-4AFD-B6D8-FFAA032D0468}\InprocServer32#ThreadingModel
HKLM\Software\Classes\CLSID\{4ACAA103-B0E1-4774-9917-BBCE4EB87691}
HKCR\CLSID\{4ACAA103-B0E1-4774-9917-BBCE4EB87691}
HKCR\CLSID\{4ACAA103-B0E1-4774-9917-BBCE4EB87691}\InprocServer32
HKCR\CLSID\{4ACAA103-B0E1-4774-9917-BBCE4EB87691}\InprocServer32#ThreadingModel
HKLM\Software\Classes\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30BAA4DF-E0AB-4AFD-B6D8-FFAA032D0468}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4ACAA103-B0E1-4774-9917-BBCE4EB87691}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{30BAA4DF-E0AB-4AFD-B6D8-FFAA032D0468}
HKCR\CLSID\{30BAA4DF-E0AB-4AFD-B6D8-FFAA032D0468}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32#ThreadingModel
HKLM\Software\Classes\CLSID\{62780D18-D103-03D3-323A-01F43008B839}
HKCR\CLSID\{62780D18-D103-03D3-323A-01F43008B839}
HKCR\CLSID\{62780D18-D103-03D3-323A-01F43008B839}\InprocServer32
HKCR\CLSID\{62780D18-D103-03D3-323A-01F43008B839}\InprocServer32#ThreadingModel
HKCR\CLSID\{62780D18-D103-03D3-323A-01F43008B839}\InprocServer32#t
C:\PROGRAM FILES\FEFWMDPC\RARRGFFU.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{62780D18-D103-03D3-323A-01F43008B839}
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{62780D18-D103-03D3-323A-01F43008B839}

Trojan.Downloader-Gen/MobRules
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0CF46468-AC82-9EC5-5B79-008AA7762D88}
HKCR\CLSID\{0CF46468-AC82-9EC5-5B79-008AA7762D88}
HKCR\CLSID\{0CF46468-AC82-9EC5-5B79-008AA7762D88}\InprocServer32
HKCR\CLSID\{0CF46468-AC82-9EC5-5B79-008AA7762D88}\InprocServer32#ThreadingModel
HKCR\CLSID\{0CF46468-AC82-9EC5-5B79-008AA7762D88}\InprocServer32#t
C:\PROGRAM FILES\JPVXATTS\YPZAQFTL.DLL

Trojan.Downloader-Gen/DDC
HKLM\System\ControlSet002\Services\DomainService
C:\WINDOWS\SYSTEM32\KXYJCPKF.EXE
HKLM\System\ControlSet004\Services\DomainService

Adware.Tracking Cookie
C:\Documents and Settings\Ho\Cookies\ho@msnportal.112.2o7[1].txt
C:\Documents and Settings\Ho\Cookies\[removed][1].txt
C:\Documents and Settings\Ho\Cookies\ho@hitbox[1].txt
C:\Documents and Settings\Ho\Cookies\ho@atdmt[2].txt
C:\Documents and Settings\Ho\Cookies\ho@cgi-bin[2].txt
C:\Documents and Settings\Ho\Cookies\ho@specificclick[2].txt
C:\Documents and Settings\Ho\Cookies\ho@msnservices.112.2o7[1].txt
C:\Documents and Settings\Ho\Cookies\ho@nhl.112.2o7[1].txt
C:\Documents and Settings\Ho\Cookies\[removed][2].txt
C:\Documents and Settings\Ho\Cookies\ho@eyewonder[2].txt
C:\Documents and Settings\Ho\Cookies\[removed][1].txt
C:\Documents and Settings\Ho\Cookies\ho@burstnet[1].txt
C:\Documents and Settings\Ho\Cookies\[removed][1].txt
C:\Documents and Settings\Ho\Cookies\[removed][1].txt
C:\Documents and Settings\Ho\Cookies\ho@redorbit[2].txt
C:\Documents and Settings\Ho\Cookies\ho@realmedia[1].txt
C:\Documents and Settings\Ho\Cookies\ho@adcentriconline[1].txt
C:\Documents and Settings\Ho\Cookies\ho@tribalfusion[1].txt
C:\Documents and Settings\Ho\Cookies\ho@adinterax[2].txt
C:\Documents and Settings\Ho\Cookies\ho@adbrite[1].txt
C:\Documents and Settings\Ho\Cookies\[removed]-sys[1].txt
C:\Documents and Settings\Ho\Cookies\[removed][1].txt
C:\Documents and Settings\Ho\Cookies\ho@tacoda[2].txt
C:\Documents and Settings\Ho\Cookies\[removed][2].txt
C:\Documents and Settings\Ho\Cookies\ho@2o7[1].txt
C:\Documents and Settings\Ho\Cookies\ho@edge.ru4[2].txt
C:\Documents and Settings\Ho\Cookies\ho@apmebf[1].txt
C:\Documents and Settings\Ho\Cookies\ho@adlegend[1].txt
C:\Documents and Settings\Ho\Cookies\ho@atwola[1].txt
C:\Documents and Settings\Ho\Cookies\ho@serving-sys[2].txt
C:\Documents and Settings\Ho\Cookies\[removed][2].txt
C:\Documents and Settings\Ho\Cookies\ho@fastclick[2].txt
C:\Documents and Settings\Ho\Cookies\ho@doubleclick[1].txt
C:\Documents and Settings\Ho\Cookies\ho@bestsellerantivirus[1].txt
C:\Documents and Settings\Ho\Cookies\ho@zedo[2].txt

Malware.MalwareAlarm
C:\Program Files\MalwareAlarm\MalwareAlarm.exe
C:\Program Files\MalwareAlarm\MalwareAlarm.lic
C:\Program Files\MalwareAlarm\Uninstall.exe
C:\Program Files\MalwareAlarm






SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/08/2007 at 10:25 AM

Application Version : 3.9.1008

Core Rules Database Version : 3259
Trace Rules Database Version: 1270

Scan type : Complete Scan
Total Scan Time : 00:36:48

Memory items scanned : 283
Memory threats detected : 0
Registry items scanned : 5069
Registry threats detected : 0
File items scanned : 30780
File threats detected : 51

Adware.Tracking Cookie
C:\Documents and Settings\Ho\Cookies\ho@msnportal.112.2o7[1].txt
C:\Documents and Settings\Ho\Cookies\[removed][1].txt
C:\Documents and Settings\Ho\Cookies\ho@hitbox[1].txt
C:\Documents and Settings\Ho\Cookies\ho@atdmt[2].txt
C:\Documents and Settings\Ho\Cookies\ho@cgi-bin[2].txt
C:\Documents and Settings\Ho\Cookies\ho@specificclick[2].txt
C:\Documents and Settings\Ho\Cookies\ho@msnservices.112.2o7[1].txt
C:\Documents and Settings\Ho\Cookies\ho@nhl.112.2o7[1].txt
C:\Documents and Settings\Ho\Cookies\[removed][2].txt
C:\Documents and Settings\Ho\Cookies\ho@eyewonder[2].txt
C:\Documents and Settings\Ho\Cookies\[removed][1].txt
C:\Documents and Settings\Ho\Cookies\ho@burstnet[1].txt
C:\Documents and Settings\Ho\Cookies\[removed][1].txt
C:\Documents and Settings\Ho\Cookies\[removed][1].txt
C:\Documents and Settings\Ho\Cookies\ho@redorbit[2].txt
C:\Documents and Settings\Ho\Cookies\ho@realmedia[1].txt
C:\Documents and Settings\Ho\Cookies\ho@adcentriconline[1].txt
C:\Documents and Settings\Ho\Cookies\ho@tribalfusion[1].txt
C:\Documents and Settings\Ho\Cookies\ho@adinterax[2].txt
C:\Documents and Settings\Ho\Cookies\ho@adbrite[1].txt
C:\Documents and Settings\Ho\Cookies\[removed]-sys[1].txt
C:\Documents and Settings\Ho\Cookies\[removed][1].txt
C:\Documents and Settings\Ho\Cookies\ho@tacoda[2].txt
C:\Documents and Settings\Ho\Cookies\[removed][2].txt
C:\Documents and Settings\Ho\Cookies\ho@2o7[1].txt
C:\Documents and Settings\Ho\Cookies\ho@edge.ru4[2].txt
C:\Documents and Settings\Ho\Cookies\ho@apmebf[1].txt
C:\Documents and Settings\Ho\Cookies\ho@adlegend[1].txt
C:\Documents and Settings\Ho\Cookies\ho@atwola[1].txt
C:\Documents and Settings\Ho\Cookies\ho@serving-sys[2].txt
C:\Documents and Settings\Ho\Cookies\[removed][2].txt
C:\Documents and Settings\Ho\Cookies\ho@fastclick[1].txt
C:\Documents and Settings\Ho\Cookies\ho@doubleclick[1].txt
C:\Documents and Settings\Ho\Cookies\ho@zedo[2].txt

Adware.ClickSpring
C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\HO\APPLICATION DATA\SMANTE~1\WUCRTUPD.EXE.VIR

Trojan.Downloader-WinCtrl
C:\QOOBOX\QUARANTINE\C\PAGING.SYS.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\WINCTL.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{73F73A7F-A811-41B9-8E00-5965AA436577}\RP0\A0001066.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{73F73A7F-A811-41B9-8E00-5965AA436577}\RP0\A0001069.SYS

Adware.ClickSpring/Yazzle
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\YAZZLE1162OINADMIN.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\YAZZLE1162OINUNINSTALLER.EXE.VIR

Trojan.Downloader-Gen/AVP
C:\QOOBOX\QUARANTINE\C\WINDOWS\AVP.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{73F73A7F-A811-41B9-8E00-5965AA436577}\RP0\A0001070.EXE

Malware.Ultimate Defender
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\NUINOPSD\NUINOPSD1.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\NUINOPSD\NUINOPSD2.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\NUINOPSD\NUINOPSD3.EXE.VIR
C:\WINDOWS\SYSTEM32\SKJLRSJP\SKJLRSJP1.EXE
C:\WINDOWS\SYSTEM32\SKJLRSJP\SKJLRSJP2.EXE
C:\WINDOWS\SYSTEM32\SKJLRSJP\SKJLRSJP3.EXE

Trojan.Downloader-Twain/Fake
C:\WINDOWS\TWAIN_32.EXE
C:\WINDOWS\TWAIN_32.EX_
Same as before:

Please open Notepad (Start > Run > in the Open field type: notepad)
Click: OK

Copy/ paste the blue text below to Notepad:

File::
C:\Documents and Settings\Ho\keygen.exe
C:\Documents and Settings\Ho\crack.exe
C:\WINDOWS\IFinst27.exe
C:\WINDOWS\TEMP\win58.exe

Registry::
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]




Save as CFScript.txt
Change the "Save as type" to "All Files"
Save it to the Desktop.
Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

After reboot, (in case it asks to reboot)……
Please provide the contents of the ComboFix log in your next reply and a fresh HJT log, MrC
ComboFix 07-12-02.7 - Ho 2007-11-05 18:35:58.4 - NTFSx86 DSREPAIR
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Ho\Desktop\CFScript.txt

FILE
C:\Documents and Settings\Ho\crack.exe
C:\Documents and Settings\Ho\keygen.exe
C:\WINDOWS\IFinst27.exe
C:\WINDOWS\TEMP\win58.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Ho\crack.exe
C:\Documents and Settings\Ho\keygen.exe
C:\WINDOWS\IFinst27.exe

.
((((((((((((((((((((((((( Files Created from 2007-11-03 to 2007-12-03 )))))))))))))))))))))))))))))))
.

2007-12-19 16:06 . 2007-11-05 15:10 159,298 –a–c— C:\pic.bmp
2007-12-19 16:04 . 2007-12-19 15:56 109,248 –a—— C:\WINDOWS\system\MSWINSCK.OCX
2007-12-19 15:56 . 2007-12-08 10:55 109,248 –a—— C:\WINDOWS\system32\MSWINSCK.OCX
2007-12-07 20:04 . 2007-12-07 20:04 d——– C:\Program Files\YourWare Solutions
2007-12-07 17:08 . 2007-12-07 17:08 d—-c— C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-07 17:02 . 2007-12-08 10:37 d——– C:\Program Files\SUPERAntiSpyware
2007-12-07 17:02 . 2007-12-07 17:02 d—-c— C:\Documents and Settings\Ho\Application Data\SUPERAntiSpyware.com
2007-12-06 19:11 . 2007-12-06 19:11 d—-c— C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-05 21:18 . 2007-12-05 21:18 d——– C:\Program Files\AmitySource
2007-12-03 20:36 . 2007-12-06 20:11 d——– C:\Program Files\Trend Micro
2007-12-03 19:29 . 2007-12-03 19:29 d—-c— C:\VundoFix Backups
2007-12-03 14:47 . 2007-12-03 14:54 d—-c— C:\Starcraft
2007-12-02 14:12 . 2007-12-03 19:33 d—-c— C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-02 13:30 . 2007-12-02 13:30 d——– C:\Program Files\Bonjour
2007-12-02 13:18 . 2007-12-02 13:18 d——– C:\Program Files\Common Files\Macrovision Shared
2007-12-02 12:58 . 2004-10-07 13:39 89,088 –a—— C:\WINDOWS\system32\atl71.dll
2007-12-02 12:58 . 2001-03-08 18:30 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-12-02 08:12 . 2007-12-02 08:16 283 –a–c— C:\-1863011324
2007-11-24 10:28 . 2007-11-06 14:31 d——– C:\Program Files\Cheat Engine
2007-11-24 10:28 . 2006-09-04 19:16 1,970,176 –a—— C:\WINDOWS\system32\d3dx9.dll
2007-11-24 10:28 . 2006-09-04 19:16 679,936 –a—— C:\WINDOWS\system32\D3DX81ab.dll
2007-11-06 22:15 . 2007-11-06 22:15 d——– C:\Program Files\Apple Software Update
2007-11-06 22:13 . 2007-11-06 22:13 d——– C:\Program Files\Windows Installer Clean Up
2007-11-06 22:13 . 2007-11-06 22:13 d——– C:\Program Files\MSECACHE
2007-11-06 21:57 . 2007-11-06 21:59 d—-c— C:\tmp
2007-11-06 21:57 . 2007-11-06 22:00 d——– C:\Program Files\Easy FLV Converter
2007-11-06 21:57 . 2007-11-06 21:59 5 –a—— C:\WINDOWS\f2areg32.ocx
2007-11-06 21:53 . 2007-11-06 21:55 d——– C:\Program Files\Total Video Converter
2007-11-06 21:42 . 2007-11-06 21:42 d—-c— C:\Documents and Settings\Ho\Application Data\Moyea

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-08 00:59 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-07 04:07 ——— d—–w C:\Program Files\Steam
2007-12-07 03:11 ——— d—–w C:\Program Files\Lavasoft
2007-12-07 02:39 ——— d—–w C:\Program Files\FlashGet
2007-12-07 02:34 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-04 21:27 ——— dc—-w C:\Documents and Settings\Ho\Application Data\Reno 911 Paintball
2007-12-04 01:24 ——— dc-h–w C:\Documents and Settings\Ho\Application Data\ijjigame
2007-12-03 22:49 94,208 —-a-w C:\WINDOWS\ScUnin.exe
2007-12-03 00:45 ——— dc—-w C:\Documents and Settings\Ho\Application Data\gtk-2.0
2007-12-02 21:30 ——— d—–w C:\Program Files\Common Files\Adobe
2007-11-18 20:17 31 -c–a-w C:\Documents and Settings\Ho\RUNME.bat
2007-11-07 06:17 ——— d—–w C:\Program Files\QuickTime
2007-11-07 01:07 ——— dc—-w C:\Documents and Settings\Ho\Application Data\LimeWire
2007-10-27 22:00 ——— d—–w C:\Program Files\Starcraft
2007-10-24 04:19 ——— d—–w C:\Program Files\Speed Gear 5
2007-10-24 04:17 ——— dc—-w C:\Documents and Settings\Ho\Application Data\GetRightToGo
2007-10-24 04:16 ——— d—–w C:\Program Files\SpeederXP
2007-10-21 04:30 ——— d—–w C:\Program Files\UrbanTerror
2007-10-19 01:56 ——— d—–w C:\Program Files\Softnyx
2007-10-13 03:46 ——— dc–a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-11 01:13 ——— d—–w C:\Program Files\Common Files\Apple
2007-10-09 02:59 ——— d—–w C:\Program Files\Common Files\xing shared
2007-10-09 02:59 ——— d—–w C:\Program Files\Common Files\Real
2007-10-09 02:58 ——— d—–w C:\Program Files\Real
2007-10-08 20:16 ——— d—–w C:\Program Files\Windows Media Connect 2
2004-06-09 23:03 832,728 —-a-w C:\Program Files\NPSWF32.dll
.

((((((((((((((((((((((((((((( snapshot@2007-12-07_16.26.41.96 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-08 01:05:22 29,696 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
+ 2007-12-08 01:05:22 18,944 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2007-12-08 01:05:22 65,024 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
- 2007-12-04 00:55:06 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-12-08 17:05:38 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-12-04 00:55:06 49,152 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-08 17:05:38 49,152 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-08 17:05:37 10,752 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\317571UA\runfile[4].exe
- 2007-12-04 00:55:06 81,920 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-08 17:05:38 81,920 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-11 19:50]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"FreeRAM XP"="C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 00:13]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pccguide.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe" [2003-03-26 05:00]
"PCCClient.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe" [2003-03-26 04:52]
"Pop3trap.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe" [2003-03-26 04:56]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 14:56]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Nintendo Wi-Fi USB Connector Registration Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Run Nintendo Wi-Fi USB Connector Registration Tool.lnk
backup=C:\WINDOWS\pss\Run Nintendo Wi-Fi USB Connector Registration Tool.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ho^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Ho\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-03 14:56 15360 –a—— C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
Logi_MwX.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaKey]
2003-05-21 19:19 180224 –a—— C:\PROGRA~1\MediaKey\MMKeybd.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft ActiveSync]
C:\WINDOWS\twain_32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rtasks]
C:\Program Files\BestsellerAntivirus\rtasks.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SC2]
C:\Program Files\SecCenter\scprot4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Tray]
2003-08-19 13:12 675840 –a—— C:\WINDOWS\system32\sistray.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook]
2003-08-19 13:11 249856 –a—— C:\WINDOWS\system32\keyhook.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]
2002-07-12 02:15 114688 –a—— C:\WINDOWS\SiSUSBrg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp]
2003-05-05 07:57 151552 –a—— C:\Program Files\Analog Devices\SoundMAX\SMTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-03-14 02:43 83608 –a—— C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-08-11 19:50 68856 –a—— C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u

R1 SiSEsc;SISLIB_ESC;C:\WINDOWS\system32\sisesc.sys
R2 PCC_PFW;PC-Cillin Personal Firewall;C:\WINDOWS\system32\Drivers\PCC_PFW.sys
R2 PCCPFW;PC-cillin PersonalFirewall;C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\system32\Drivers\DKbFltr.sys
S3 CEDRIVER53;CEDRIVER53;\??\C:\Program Files\Cheat Engine\dbk32.sys
S3 CrucialSMBusScan;CrucialSMBusScan;\??\C:\WINDOWS\system32\drivers\CrucialSMBusScan.sys
S3 dump_wmimmc;dump_wmimmc;\??\c:\ijji\ENGLISH\Gunbound Revolution\GameGuard\dump_wmimmc.sys
S3 geebers12;geebers12;\??\C:\Documents and Settings\Ho\Desktop\Hax\Exterm\Xterminator Engine 2.0\Xterminator.sys
S3 iCheat1;iCheat1;\??\C:\Program Files\Maple-Fun\iCheat\nvid999.sys
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;\??\C:\Documents and Settings\Ho\Desktop\Hack pack\Moonlight Engine 1059.22\MoonLight Engine_1059.22\IlvMoney1059a.sys
S3 kaspersky1;kaspersky1;\??\C:\Documents and Settings\Ho\Desktop\Folders\Hax\Kaspersky_Engine_3[1][1].2\kaspersky.sys
S3 memxers12;memxers12;\??\C:\Documents and Settings\Ho\Desktop\Hax\vicious 5.1\New Folder\nvid999.sys
S3 muIO;muIO;\??\C:\WINDOWS\system32\muIO.sys
S3 PageFau1t;PageFau1t;\??\C:\Documents and Settings\Ho\Desktop\launcher\bypasss\bypasss\PageFau1t.sys
S3 SiSPort;SIS PORT Driver;\??\C:\WINDOWS\SiSPort.sys
S3 SoRa01;SoRa01;\??\C:\Documents and Settings\Ho\Desktop\T3N_Mini_Hack_Pack\T3N Mini Hack Pack\PedZing_Engin\PedZing Engine\SoRa.sys
S3 WINIO;WINIO;\??\C:\Program Files\QMacro\winio.sys

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Bin\Assetup.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-11-07 06:16:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-06 01:58:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-02 18:43:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
"ImagePath"="\??\C:\Documents and Settings\Ho\Desktop\Folders\Hax\Kaspersky_Engine_3
[1][1].2\kaspersky.sys"

.
Completion time: 2007-12-02 18:47:58 - machine was rebooted
C:\ComboFix2.txt … 2007-12-08 09:42
C:\ComboFix3.txt … 2007-12-07 16:35
.
— E O F —



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:53:53 PM, on 02/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Block this popup - C:\Program Files\Shaw Secure\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?21d93abd64f344d7a98459d0c3ea1d95
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?21d93abd64f344d7a98459d0c3ea1d95
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe

–
End of file - 6599 bytes
Almost there……same as before:

Please open Notepad (Start > Run > in the Open field type: notepad)
Click: OK

Copy/ paste the blue text below to Notepad:

Folder::
C:\Program Files\BestsellerAntivirus
C:\Program Files\SecCenter

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rtasks]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SC2]



Save as CFScript.txt
Change the "Save as type" to "All Files"
Save it to the Desktop.
Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

After reboot, (in case it asks to reboot)……
Please provide the contents of the ComboFix log in your next reply and a fresh HJT log, MrC
ComboFix 07-12-02.7 - Ho 2007-12-09 11:46:28.5 - NTFSx86 DSREPAIR
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Ho\Desktop\CFScript.txt
.

((((((((((((((((((((((((( Files Created from 2007-11-09 to 2007-12-09 )))))))))))))))))))))))))))))))
.

2007-12-19 16:06 . 2007-11-05 20:16 159,298 –a–c— C:\pic.bmp
2007-12-19 16:04 . 2007-12-19 15:56 109,248 –a—— C:\WINDOWS\system\MSWINSCK.OCX
2007-12-19 15:56 . 2007-12-08 10:55 109,248 –a—— C:\WINDOWS\system32\MSWINSCK.OCX
2007-12-09 09:17 . 2007-12-09 09:17 759 –a—— C:\WINDOWS\system32\spupdsvc.inf
2007-12-09 09:13 . 2007-12-09 09:13 d——– C:\WINDOWS\LastGood
2007-12-07 20:04 . 2007-12-07 20:04 d——– C:\Program Files\YourWare Solutions
2007-12-07 17:08 . 2007-12-07 17:08 d—-c— C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-07 17:02 . 2007-12-08 10:37 d——– C:\Program Files\SUPERAntiSpyware
2007-12-07 17:02 . 2007-12-07 17:02 d—-c— C:\Documents and Settings\Ho\Application Data\SUPERAntiSpyware.com
2007-12-06 19:11 . 2007-12-06 19:11 d—-c— C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-05 21:18 . 2007-12-05 21:18 d——– C:\Program Files\AmitySource
2007-12-03 20:36 . 2007-12-06 20:11 d——– C:\Program Files\Trend Micro
2007-12-03 19:29 . 2007-12-03 19:29 d—-c— C:\VundoFix Backups
2007-12-03 14:47 . 2007-12-03 14:54 d—-c— C:\Starcraft
2007-12-02 14:12 . 2007-12-03 19:33 d—-c— C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-02 13:30 . 2007-12-02 13:30 d——– C:\Program Files\Bonjour
2007-12-02 13:18 . 2007-12-02 13:18 d——– C:\Program Files\Common Files\Macrovision Shared
2007-12-02 12:58 . 2004-10-07 13:39 89,088 –a—— C:\WINDOWS\system32\atl71.dll
2007-12-02 12:58 . 2001-03-08 18:30 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-12-02 08:12 . 2007-12-02 08:16 283 –a–c— C:\-1863011324
2007-11-24 10:28 . 2007-11-06 14:31 d——– C:\Program Files\Cheat Engine
2007-11-24 10:28 . 2006-09-04 19:16 1,970,176 –a—— C:\WINDOWS\system32\d3dx9.dll
2007-11-24 10:28 . 2006-09-04 19:16 679,936 –a—— C:\WINDOWS\system32\D3DX81ab.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-09 19:21 ——— dc—-w C:\Documents and Settings\Ho\Application Data\gtk-2.0
2007-12-08 00:59 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-07 04:07 ——— d—–w C:\Program Files\Steam
2007-12-07 03:11 ——— d—–w C:\Program Files\Lavasoft
2007-12-07 02:39 ——— d—–w C:\Program Files\FlashGet
2007-12-07 02:34 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-04 21:27 ——— dc—-w C:\Documents and Settings\Ho\Application Data\Reno 911 Paintball
2007-12-04 01:24 ——— dc-h–w C:\Documents and Settings\Ho\Application Data\ijjigame
2007-12-03 22:49 94,208 —-a-w C:\WINDOWS\ScUnin.exe
2007-12-02 21:30 ——— d—–w C:\Program Files\Common Files\Adobe
2007-11-18 20:17 31 -c–a-w C:\Documents and Settings\Ho\RUNME.bat
2007-11-07 06:17 ——— d—–w C:\Program Files\QuickTime
2007-11-07 06:15 ——— d—–w C:\Program Files\Apple Software Update
2007-11-07 06:13 ——— d—–w C:\Program Files\Windows Installer Clean Up
2007-11-07 06:13 ——— d—–w C:\Program Files\MSECACHE
2007-11-07 06:00 ——— d—–w C:\Program Files\Easy FLV Converter
2007-11-07 05:55 ——— d—–w C:\Program Files\Total Video Converter
2007-11-07 05:42 ——— dc—-w C:\Documents and Settings\Ho\Application Data\Moyea
2007-11-07 01:07 ——— dc—-w C:\Documents and Settings\Ho\Application Data\LimeWire
2007-10-27 22:00 ——— d—–w C:\Program Files\Starcraft
2007-10-24 04:19 ——— d—–w C:\Program Files\Speed Gear 5
2007-10-24 04:17 ——— dc—-w C:\Documents and Settings\Ho\Application Data\GetRightToGo
2007-10-24 04:16 ——— d—–w C:\Program Files\SpeederXP
2007-10-21 04:30 ——— d—–w C:\Program Files\UrbanTerror
2007-10-19 01:56 ——— d—–w C:\Program Files\Softnyx
2007-10-13 03:46 ——— dc–a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-11 01:13 ——— d—–w C:\Program Files\Common Files\Apple
2007-10-09 02:59 ——— d—–w C:\Program Files\Common Files\xing shared
2007-10-09 02:59 ——— d—–w C:\Program Files\Common Files\Real
2007-10-09 02:58 ——— d—–w C:\Program Files\Real
2004-06-09 23:03 832,728 —-a-w C:\Program Files\NPSWF32.dll
.

((((((((((((((((((((((((((((( snapshot@2007-12-07_16.26.41.96 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-03 22:56:42 61,440 -c–a-w C:\WINDOWS\ie7\admparse.dll
+ 2004-08-03 22:56:42 99,840 -c–a-w C:\WINDOWS\ie7\advpack.dll
+ 2004-08-03 22:56:42 1,016,832 -c–a-w C:\WINDOWS\ie7\browseui.dll
+ 2004-08-03 22:56:42 35,328 -c–a-w C:\WINDOWS\ie7\corpol.dll
+ 2004-08-03 22:56:42 28,672 -c–a-w C:\WINDOWS\ie7\custsat.dll
+ 2004-08-03 22:56:44 357,888 -c–a-w C:\WINDOWS\ie7\dxtmsft.dll
+ 2004-08-03 22:56:44 201,728 -c–a-w C:\WINDOWS\ie7\dxtrans.dll
+ 2004-08-03 22:56:44 55,808 -c–a-w C:\WINDOWS\ie7\extmgr.dll
+ 2004-08-03 22:56:44 38,912 -c–a-w C:\WINDOWS\ie7\hmmapi.dll
+ 2004-08-03 22:56:52 34,304 -c–a-w C:\WINDOWS\ie7\ie4uinit.exe
+ 2004-08-03 22:56:44 139,264 -c–a-w C:\WINDOWS\ie7\ieakeng.dll
+ 2004-08-03 22:56:44 216,576 -c–a-w C:\WINDOWS\ie7\ieaksie.dll
+ 2001-08-23 12:00:00 221,184 -c–a-w C:\WINDOWS\ie7\ieakui.dll
+ 2004-08-03 22:56:44 323,584 -c–a-w C:\WINDOWS\ie7\iedkcs32.dll
+ 2004-08-03 22:56:52 18,432 -c–a-w C:\WINDOWS\ie7\iedw.exe
+ 2004-08-03 22:56:44 81,920 -c–a-w C:\WINDOWS\ie7\ieencode.dll
+ 2004-08-03 22:56:44 249,344 -c–a-w C:\WINDOWS\ie7\iepeers.dll
+ 2004-08-03 22:56:44 48,640 -c–a-w C:\WINDOWS\ie7\iernonce.dll
+ 2004-08-03 22:56:44 62,976 -c–a-w C:\WINDOWS\ie7\iesetup.dll
+ 2004-08-03 22:56:52 93,184 -c–a-w C:\WINDOWS\ie7\iexplore.exe
+ 2004-08-03 22:56:44 35,840 -c–a-w C:\WINDOWS\ie7\imgutil.dll
+ 2004-08-03 22:56:44 96,256 -c–a-w C:\WINDOWS\ie7\inseng.dll
+ 2004-08-03 22:56:44 450,560 -c–a-w C:\WINDOWS\ie7\jscript.dll
+ 2004-08-03 22:56:44 15,872 -c–a-w C:\WINDOWS\ie7\jsproxy.dll
+ 2004-08-03 22:56:44 22,016 -c–a-w C:\WINDOWS\ie7\licmgr10.dll
+ 2004-08-03 22:56:54 29,184 -c–a-w C:\WINDOWS\ie7\mshta.exe
+ 2004-08-03 22:56:44 3,003,392 -c–a-w C:\WINDOWS\ie7\mshtml.dll
+ 2004-08-03 22:56:44 448,512 -c–a-w C:\WINDOWS\ie7\mshtmled.dll
+ 2004-08-03 22:56:16 56,832 -c–a-w C:\WINDOWS\ie7\mshtmler.dll
+ 2001-08-23 12:00:00 146,432 -c–a-w C:\WINDOWS\ie7\msls31.dll
+ 2004-08-03 22:56:44 146,432 -c–a-w C:\WINDOWS\ie7\msrating.dll
+ 2004-08-03 22:56:44 530,432 -c–a-w C:\WINDOWS\ie7\mstime.dll
+ 2004-08-03 22:56:46 96,256 -c–a-w C:\WINDOWS\ie7\occache.dll
+ 2004-08-03 22:56:46 39,424 -c–a-w C:\WINDOWS\ie7\pngfilt.dll
+ 2004-08-03 22:56:46 1,483,264 -c–a-w C:\WINDOWS\ie7\shdocvw.dll
+ 2004-08-03 22:56:46 473,600 -c–a-w C:\WINDOWS\ie7\shlwapi.dll
+ 2007-08-14 02:54:42 32,960 -c–a-w C:\WINDOWS\ie7\spuninst\iecustom.dll
+ 2007-08-14 02:52:06 66,048 -c–a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
+ 2006-09-07 01:43:16 213,216 -c–a-w C:\WINDOWS\ie7\spuninst\spuninst.exe
+ 2006-09-07 01:43:18 371,424 -c–a-w C:\WINDOWS\ie7\spuninst\updspapi.dll
+ 2004-08-03 22:56:48 37,888 -c–a-w C:\WINDOWS\ie7\url.dll
+ 2004-08-03 22:56:48 601,088 -c–a-w C:\WINDOWS\ie7\urlmon.dll
+ 2004-08-03 22:56:48 417,792 -c–a-w C:\WINDOWS\ie7\vbscript.dll
+ 2004-08-03 22:56:48 848,384 -c–a-w C:\WINDOWS\ie7\vgx.dll
+ 2004-08-03 22:56:48 276,480 -c–a-w C:\WINDOWS\ie7\webcheck.dll
+ 2004-08-03 22:56:48 656,384 -c–a-w C:\WINDOWS\ie7\wininet.dll
+ 2007-12-08 01:05:22 29,696 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
+ 2007-12-08 01:05:22 18,944 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2007-12-08 01:05:22 65,024 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
- 2007-12-04 00:55:06 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-12-08 17:05:38 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-12-04 00:55:06 49,152 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-08 17:05:38 49,152 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-08 17:05:37 10,752 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\317571UA\runfile[4].exe
- 2007-12-04 00:55:06 81,920 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-08 17:05:38 81,920 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-08-14 02:36:26 61,952 ——w C:\WINDOWS\system32\icardie.dll
+ 2006-06-29 16:05:44 26,112 ——w C:\WINDOWS\system32\idndl.dll
+ 2007-02-13 00:10:12 2,451,312 ——w C:\WINDOWS\system32\ieapfltr.dat
+ 2007-07-11 20:27:48 383,488 ——w C:\WINDOWS\system32\ieapfltr.dll
+ 2007-08-14 02:54:10 6,049,280 ——w C:\WINDOWS\system32\ieframe.dll
+ 2007-08-14 02:34:04 266,752 ——w C:\WINDOWS\system32\iertutil.dll
+ 2007-08-14 02:39:10 13,312 —-a-w C:\WINDOWS\system32\ieudinit.exe
+ 2007-08-14 02:54:10 180,736 ——w C:\WINDOWS\system32\ieui.dll
+ 2007-08-14 02:54:10 458,752 ——w C:\WINDOWS\system32\msfeeds.dll
+ 2007-08-14 02:54:10 50,688 ——w C:\WINDOWS\system32\msfeedsbs.dll
+ 2007-08-14 02:36:40 12,288 ——w C:\WINDOWS\system32\msfeedssync.exe
+ 2006-06-29 01:59:26 24,576 ——w C:\WINDOWS\system32\nlsdl.dll
+ 2006-06-29 16:05:44 23,552 ——w C:\WINDOWS\system32\normaliz.dll
- 2007-12-04 01:18:09 60,020 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-12-09 17:02:28 60,252 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2007-12-04 01:18:09 396,740 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-12-09 17:02:28 397,356 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-08-14 02:45:16 206,336 ——w C:\WINDOWS\system32\WinFXDocObj.exe
+ 2006-07-14 15:51:51 121,856 ——w C:\WINDOWS\system32\xmllite.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-11 19:50]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"FreeRAM XP"="C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 00:13]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pccguide.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe" [2003-03-26 05:00]
"PCCClient.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe" [2003-03-26 04:52]
"Pop3trap.exe"="C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe" [2003-03-26 04:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"NoIE4StubProcessing"="C:\WINDOWS\system32\reg.exe" [2004-08-03 14:56]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 14:56]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Nintendo Wi-Fi USB Connector Registration Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Run Nintendo Wi-Fi USB Connector Registration Tool.lnk
backup=C:\WINDOWS\pss\Run Nintendo Wi-Fi USB Connector Registration Tool.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ho^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Ho\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-03 14:56 15360 –a—— C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
Logi_MwX.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaKey]
2003-05-21 19:19 180224 –a—— C:\PROGRA~1\MediaKey\MMKeybd.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft ActiveSync]
C:\WINDOWS\twain_32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Tray]
2003-08-19 13:12 675840 –a—— C:\WINDOWS\system32\sistray.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook]
2003-08-19 13:11 249856 –a—— C:\WINDOWS\system32\keyhook.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]
2002-07-12 02:15 114688 –a—— C:\WINDOWS\SiSUSBrg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp]
2003-05-05 07:57 151552 –a—— C:\Program Files\Analog Devices\SoundMAX\SMTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-03-14 02:43 83608 –a—— C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-08-11 19:50 68856 –a—— C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Bin\Assetup.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-11-07 06:16:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-09 18:58:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-09 11:50:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
"ImagePath"="\??\C:\Documents and Settings\Ho\Desktop\Folders\Hax\Kaspersky_Engine_3
[1][1].2\kaspersky.sys"

.
Completion time: 2007-12-09 11:51:56
C:\ComboFix2.txt … 2007-12-02 18:47
C:\ComboFix3.txt … 2007-12-08 09:42
.
— E O F —









Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:47:39 PM, on 09/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\GIMP-2.0\lib\gimp\2.0\plug-ins\script-fu.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\RunOnce: [NoIE4StubProcessing] C:\WINDOWS\system32\reg.exe DELETE "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" /v "NoIE4StubProcessing" /f
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Block this popup - C:\Program Files\Shaw Secure\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?21d93abd64f344d7a98459d0c3ea1d95
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?21d93abd64f344d7a98459d0c3ea1d95
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe

–
End of file - 7265 bytes
Great :thumbup:

Click START then RUN
Now type Combofix /u in the runbox and click OK.
Note the space between the X and the U, it needs to be there.

[external image: Posted Image]

When shown the disclaimer, Select "2"

This is what will happen:

These will be deleted:ComboFix and its associated files and folders.
VundoFix backups, if present
The C:\Deckard folder, if present
The C:_OtMoveIt folder, if present

Then these tasks will be performed:Reset the clock settings.
Hide file extensions, if required.
Hide System/Hidden files, if required.
Reset System Restore.

—————————————————–


If you have any questions - please post back

I'll leave you with……..

Some Preventive Maintenance:

Some of the programs you may have run create backups of what was deleted - you can safely delete them now: (delete folders in blue) You can also delete/uninstall the programs themselves.

C:\!KillBox (KillBox)
C:\VundoFix Backups (VundoFix)
C:\QooBox (ComboFix)
C:\SDFix\backups\backups.zip (SDFix)
C:\avenger\backup.zip (Avenger)
C:\_OTMOVEIT folder (OTMoveIt)

RVAXO:
You can use Uninstall.cmd to remove everything from RVAXO, it will be found in the RVAXO-folder on your desktop.

If you used AVG Anti-Spyware and/or SuperAntiSpyware………..

Open up SuperAntiSpyware > Preferences > General and Start-up > Start-up Options > Uncheck > Start SAS when Windows Starts.
"SAS free" provides no real time protection so there's no need for it to be running, I suggest you keep the program and update regularly - you can use it to scan for malware. It's an excellent program. When you want to start it - just double click on the SAS icon.

AVG Anti-Spyware will provide 30 days of real time protection and then after that you can use it to scan for malware - you'll have to manually update it first.


——————Must have or do:—————–

Now that you're clean: <—-Important Step!!!!
Delete your system restore files and create a new restore point (XP only):

Note: This will remove all previous Restore Points!

1. Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Restart your computer,

2. Turn on System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UnCheck Turn off System Restore.
Click Apply, and then click OK.

Visit Windows Update and install all the lastest critical updates.

Install these two free programs, they sit in the backround and protect your system from spy and adware being installed on your system, also from your browser being hijacked.

SpywareBlaster Check for updates weekly.

SpywareGuard

IE-SPYAD
Puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
or try the new ZonedOut

Blocking Unwanted Parasites with a Hosts File
Direct Download - MVPS HOSTS <==> MVPS HOSTS Tutorial

Need a free anti virus?
AVG*free
Avast Free
AntiVir® PersonalEdition Classic
–>Check for updates - daily<—

How about a firewall? The front door to your computer.
Windows firewall is not suffient…install a better one.
Comodo Free Firewall
ZoneAlarm*free
Other free firewalls

Keep those temp files off your system use
ATF Cleaner - hit "select all" then just uncheck "cookies" (uncheck cookies is optional - leave it checked if you want to delete all cookies) then "empty selected"
or
CCleaner
Uncheck "Cookies" under "Internet Explorer".
That will clear out all the temp files on the system.

IMPORTANT!!
Keep your Sun Java up-to-date JRE Version 6 Update 3<–newest version
Delete ALL old versions from add/remove programs if listed first!
Check HERE

Keep the registry backed up - use ERUNT
Print this out and save it
ERUNT Tutorial

Starter Manage you startup programs and services.

———-Free malware removal programs:———-

AVG Anti-Spyware<—VERY GOOD! (XP and 2K only)
SUPERAntiSpyware (free edition)<—Excellent!
AVG Anti-Rootkit Free Edition Run it!!
SpyBot
AD-Aware
CW-Shredder

Please consider using FireFox instead of Internet Explorer. A more secure browser! Easy to make the change!
FireFox Tutorial


Pop-up stoppers:
GoogleToolBar
Pop-upStopperFree

Disable "Windows Messenger Service" XP - 2K (stops pop-up ads -etc):
Shoot The Messenger

Anti-Rootkit Software - Detection, Removal & Protection

Reduce Online Fraud

Slow Computer - Check Here

Don't open e-mail attachments without first scanning them with an up-to-date anti virus program, even after doing that I would be very careful. Don't click on any executables in e-mails or any other links that you're not sure of.
Don't believe e-mails from your bank, financial institution, etc asking for personal informations - they're most likely fraudulent no matter how authentic they look.
Watch your surfing habits, don't click on or download anything you're not sure of. Don't install a program that hasn't been recommended by a reputable organization.

Good luck and thanks for using the forum - MrC
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI