This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] pop ups everywhere and can't be deleted

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ComboFix 07-12-09.1 - sadie adams 2007-12-11 18:07:25.10 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.244 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\sadie adams\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\Documents and Settings\sadie adams\Application Data\Macromedia\Shockwave Player\xtras\download\TheGrooveAlliance\3DGrooveXtrav181\Groove.x32
c:\windows\system32\sysfile.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\backups\HKCU_Domains.reg
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\backups\HKCU_Ranges.reg
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\backups\HKLM_Domains.reg
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\backups\HKLM_Ranges.reg
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\cleanup.reg
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\dumphive.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\exit.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\GenericRenosFix.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\HostsChk.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\Process.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\restart.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\SmitfraudFix.cmd
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\SmiUpdate.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\SrchSTS.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\swreg.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\swsc.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\swxcacls.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\unzip.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\VCCLSID.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\WS2Fix.exe
c:\windows\system32\sysfile.dll

.
((((((((((((((((((((((((( Files Created from 2007-11-12 to 2007-12-12 )))))))))))))))))))))))))))))))
.

2007-12-10 17:24 . 2007-12-10 19:05 d——– C:\WINDOWS\SYSTEM32\ActiveScan
2007-12-10 17:24 . 2007-12-10 17:24 30,590 –a—— C:\WINDOWS\SYSTEM32\pavas.ico
2007-12-10 17:24 . 2007-12-10 17:24 2,550 –a—— C:\WINDOWS\SYSTEM32\Uninstall.ico
2007-12-10 17:24 . 2007-12-10 17:24 1,406 –a—— C:\WINDOWS\SYSTEM32\Help.ico
2007-12-09 17:40 . 2007-12-09 17:40 d—-c— C:\Documents and Settings\sadie adams\Application Data\AdwareAlert
2007-12-09 07:16 . 2007-12-09 17:31 3,642 –a—— C:\WINDOWS\SYSTEM32\tmp.reg
2007-12-09 06:47 . 2003-09-02 15:03 d—-c— C:\Documents and Settings\Administrator.D14HKF31\WINDOWS
2007-12-09 06:47 . 2005-05-20 22:59 d—-c— C:\Documents and Settings\Administrator.D14HKF31\Application Data\Gtek
2007-12-09 06:42 . 2007-12-09 06:42 d—-c— C:\Documents and Settings\sadie adams\Application Data\Grisoft
2007-12-09 06:39 . 2007-12-09 06:39 d—-c— C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 06:39 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-12-08 16:50 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\SYSTEM32\msvcr80.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-11 00:31 ——— d—–w C:\Program Files\iTunes
2007-12-11 00:26 ——— d—–w C:\Program Files\Digital Line Detect
2007-12-10 20:41 ——— dc—-w C:\Documents and Settings\sadie adams\Application Data\LimeWire
2007-12-08 18:20 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-05 06:00 ——— dc—-w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-11-22 15:24 ——— d—–w C:\Program Files\McAfee
2007-11-14 21:39 ——— dc—-w C:\Documents and Settings\sadie adams\Application Data\SiteAdvisor
2007-11-11 14:21 ——— d—–w C:\Program Files\DivX
2007-11-11 14:11 ——— d—–w C:\Program Files\QUICKENW
2007-11-11 14:10 ——— d—–w C:\Program Files\PhotoParade
2007-11-11 14:09 ——— d—–w C:\Program Files\Common Files\Intuit
2007-11-11 14:05 ——— d—–w C:\Program Files\Java
2007-11-11 14:01 ——— d—–w C:\Program Files\Common Files\Java
2007-11-11 13:38 ——— d—–w C:\Program Files\eGames
2007-11-11 13:36 ——— dc-ha-w C:\Documents and Settings\All Users\Application Data\GTek
2007-11-11 13:36 ——— dc-h–w C:\Documents and Settings\sadie adams\Application Data\GTek
2007-11-11 13:35 ——— d—–w C:\Program Files\Dell
2007-11-11 13:33 ——— d—–w C:\Program Files\Britannica
2007-11-11 13:32 ——— d—–w C:\Program Files\Apple Software Update
2007-11-10 13:20 ——— d—–w C:\Program Files\iPod
2007-11-10 13:17 ——— d—–w C:\Program Files\QuickTime
2007-11-07 23:15 ——— dc—-w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-11-07 23:15 ——— dc—-w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-07 23:15 ——— d—–w C:\Program Files\Yahoo!
2007-11-06 00:00 ——— dc—-w C:\Documents and Settings\sadie adams\Application Data\Apple Computer
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2007-10-20 18:11 ——— d—–w C:\Program Files\Google
2007-10-18 09:06 156,992 —-a-w C:\WINDOWS\SYSTEM32\DivXCodecVersionChecker.exe
2007-10-12 23:13 ——— d—–w C:\Program Files\Common Files\Adobe
.

((((((((((((((((((((((((((((( snapshot@2007-12-09_ 6.14.55.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-08-24 14:28:54 141,424 —-a-w C:\WINDOWS\Downloaded Program Files\asinst.dll
+ 2007-03-29 15:20:50 110,592 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\as.dll
+ 2006-10-05 22:15:26 233,472 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\ascontrol.dll
+ 2005-06-03 20:03:18 96,256 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\asmdat.dll
+ 2003-08-01 17:00:16 36,864 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\certdll.dll
+ 2005-05-20 19:42:44 86,016 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\instlsp.dll
+ 2006-02-17 00:20:20 4,608 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\memvfile.dll
+ 2005-10-26 00:08:32 348,160 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\msvcr71.dll
+ 2004-05-04 21:01:02 139,264 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavaleas.dll
+ 2006-07-14 19:04:10 45,056 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavdr.exe
+ 2006-04-10 16:50:02 159,832 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavexcom.dll
+ 2006-02-14 19:05:38 94,208 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavinas.dll
+ 2006-02-17 00:35:38 180,224 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavoe.dll
+ 2006-10-05 22:15:38 122,880 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavpz.dll
+ 2006-06-30 20:13:38 8,704 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pfdnnt.exe
+ 2004-02-04 20:08:42 49,152 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\port32.dll
+ 2006-08-01 19:23:10 69,632 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pscpu.dll
+ 2006-08-23 19:06:08 1,388,544 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskahk.dll
+ 2006-08-17 17:38:14 10,752 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskalloc.dll
+ 2006-09-04 17:49:54 61,440 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskas.dll
+ 2006-08-18 14:46:18 779,264 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskavs.dll
+ 2007-03-26 20:25:34 417,792 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskcmp.dll
+ 2006-08-09 16:42:24 90,112 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskfss.dll
+ 2006-07-19 16:55:58 208,896 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskhtml.dll
+ 2006-01-20 22:57:00 9,728 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskmas.dll
+ 2006-05-17 15:50:12 14,336 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskmdfs.dll
+ 2006-08-16 16:58:12 33,280 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskpack.dll
+ 2006-06-30 20:42:36 266,240 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskscs.dll
+ 2006-08-17 20:33:14 62,976 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskutil.dll
+ 2006-08-08 19:13:10 13,312 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskvfile.dll
+ 2006-08-18 14:53:08 69,632 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskvfs.dll
+ 2006-08-18 14:49:50 167,936 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskvm.dll
+ 2007-04-18 23:16:04 353,840 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\psscan.dll
+ 2007-01-22 20:42:48 35,328 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\rawvfile.dll
+ 1997-09-18 12:12:32 9,488 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\sporder.dll
+ 2006-02-28 23:23:40 69,632 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\tcpvfile.dll
+ 2006-08-02 18:39:06 73,728 —-a-w C:\WINDOWS\SYSTEM32\asuninst.exe
- 2007-12-09 11:13:12 32,768 -c–a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2007-12-11 23:45:07 32,768 -c–a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
- 2007-12-09 11:13:12 32,768 -c–a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2007-12-11 23:45:07 32,768 -c–a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
- 2007-12-09 11:13:12 32,768 -c–a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT
+ 2007-12-11 23:45:07 32,768 –sha-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2003-03-26 00:53:50 11,776 —-a-w C:\WINDOWS\SYSTEM32\ZPORT4AS.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 08:59]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-23 20:31]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-02-02 16:32]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 08:59]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 01:56 C:\WINDOWS\SYSTEM32\rundll32.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 11:50 C:\WINDOWS\LOGI_MWX.EXE]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-06-21 11:40]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-08-14 17:22]
"DeviceDiscovery"="C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 17:37]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 10:09]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 11:28]
"!AVG Anti-Spyware"="C:\Documents and Settings\sadie adams\Desktop\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 01:56]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-03-06 23:06]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2003-09-02 15:00:53]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=C:\WINDOWS\pss\HotSync Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^sadie adams^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\sadie adams\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AccuWeatherDesktopAlerts]
C:\Program Files\AccuWeatherDesktopAlerts\AccuWeatherDesktopAlerts.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-02 18:36 267048 –a—— C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagent_exe]
C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
2007-03-06 23:06 5181440 –a—— C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor]
2007-01-17 13:24 36904 –a—— C:\Program Files\SiteAdvisor\6172\SiteAdv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_8

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE -quiet

S3 cdrmkaun;cdrmkaun;\??\C:\DOCUME~1\SADIEA~1\LOCALS~1\Temp\cdrmkaun.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-12-11 09:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
"2007-12-06 05:14:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-15 07:15:34 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2007-12-01 07:00:17 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2005-03-27 23:23:50 C:\WINDOWS\Tasks\WebReg 20050327172350.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqwrg.exe
.
**************************************************************************

catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-11 18:10:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-11 18:11:35
C:\ComboFix2.txt … 2007-12-09 20:08
C:\ComboFix3.txt … 2007-12-09 17:25
.
— E O F —
Logfile of HijackThis v1.99.1
Scan saved at 6:12:21 PM, on 12/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Documents and Settings\sadie adams\Desktop\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Documents and Settings\sadie adams\Desktop\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Digital Line Detect\DLG.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\McAfee\MSC\mcuimgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cm.my.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\sadie adams\Desktop\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…76/mcinsctl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase9602.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1125787560953
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4058/ftp…tle/Coupons.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,16/mcgdmgr.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://128.206.143.98/activex/AMC.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Documents and Settings\sadie adams\Desktop\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe






ComboFix 07-12-09.1 - sadie adams 2007-12-11 18:07:25.10 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.244 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\sadie adams\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\Documents and Settings\sadie adams\Application Data\Macromedia\Shockwave Player\xtras\download\TheGrooveAlliance\3DGrooveXtrav181\Groove.x32
c:\windows\system32\sysfile.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\backups\HKCU_Domains.reg
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\backups\HKCU_Ranges.reg
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\backups\HKLM_Domains.reg
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\backups\HKLM_Ranges.reg
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\cleanup.reg
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\dumphive.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\exit.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\GenericRenosFix.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\HostsChk.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\Process.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\restart.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\SmitfraudFix.cmd
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\SmiUpdate.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\SrchSTS.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\swreg.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\swsc.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\swxcacls.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\unzip.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\VCCLSID.exe
C:\Documents and Settings\sadie adams\Desktop\SmitfraudFix\SmitfraudFix\WS2Fix.exe
c:\windows\system32\sysfile.dll

.
((((((((((((((((((((((((( Files Created from 2007-11-12 to 2007-12-12 )))))))))))))))))))))))))))))))
.

2007-12-10 17:24 . 2007-12-10 19:05 d——– C:\WINDOWS\SYSTEM32\ActiveScan
2007-12-10 17:24 . 2007-12-10 17:24 30,590 –a—— C:\WINDOWS\SYSTEM32\pavas.ico
2007-12-10 17:24 . 2007-12-10 17:24 2,550 –a—— C:\WINDOWS\SYSTEM32\Uninstall.ico
2007-12-10 17:24 . 2007-12-10 17:24 1,406 –a—— C:\WINDOWS\SYSTEM32\Help.ico
2007-12-09 17:40 . 2007-12-09 17:40 d—-c— C:\Documents and Settings\sadie adams\Application Data\AdwareAlert
2007-12-09 07:16 . 2007-12-09 17:31 3,642 –a—— C:\WINDOWS\SYSTEM32\tmp.reg
2007-12-09 06:47 . 2003-09-02 15:03 d—-c— C:\Documents and Settings\Administrator.D14HKF31\WINDOWS
2007-12-09 06:47 . 2005-05-20 22:59 d—-c— C:\Documents and Settings\Administrator.D14HKF31\Application Data\Gtek
2007-12-09 06:42 . 2007-12-09 06:42 d—-c— C:\Documents and Settings\sadie adams\Application Data\Grisoft
2007-12-09 06:39 . 2007-12-09 06:39 d—-c— C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 06:39 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-12-08 16:50 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\SYSTEM32\msvcr80.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-11 00:31 ——— d—–w C:\Program Files\iTunes
2007-12-11 00:26 ——— d—–w C:\Program Files\Digital Line Detect
2007-12-10 20:41 ——— dc—-w C:\Documents and Settings\sadie adams\Application Data\LimeWire
2007-12-08 18:20 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-05 06:00 ——— dc—-w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-11-22 15:24 ——— d—–w C:\Program Files\McAfee
2007-11-14 21:39 ——— dc—-w C:\Documents and Settings\sadie adams\Application Data\SiteAdvisor
2007-11-11 14:21 ——— d—–w C:\Program Files\DivX
2007-11-11 14:11 ——— d—–w C:\Program Files\QUICKENW
2007-11-11 14:10 ——— d—–w C:\Program Files\PhotoParade
2007-11-11 14:09 ——— d—–w C:\Program Files\Common Files\Intuit
2007-11-11 14:05 ——— d—–w C:\Program Files\Java
2007-11-11 14:01 ——— d—–w C:\Program Files\Common Files\Java
2007-11-11 13:38 ——— d—–w C:\Program Files\eGames
2007-11-11 13:36 ——— dc-ha-w C:\Documents and Settings\All Users\Application Data\GTek
2007-11-11 13:36 ——— dc-h–w C:\Documents and Settings\sadie adams\Application Data\GTek
2007-11-11 13:35 ——— d—–w C:\Program Files\Dell
2007-11-11 13:33 ——— d—–w C:\Program Files\Britannica
2007-11-11 13:32 ——— d—–w C:\Program Files\Apple Software Update
2007-11-10 13:20 ——— d—–w C:\Program Files\iPod
2007-11-10 13:17 ——— d—–w C:\Program Files\QuickTime
2007-11-07 23:15 ——— dc—-w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-11-07 23:15 ——— dc—-w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-07 23:15 ——— d—–w C:\Program Files\Yahoo!
2007-11-06 00:00 ——— dc—-w C:\Documents and Settings\sadie adams\Application Data\Apple Computer
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2007-10-20 18:11 ——— d—–w C:\Program Files\Google
2007-10-18 09:06 156,992 —-a-w C:\WINDOWS\SYSTEM32\DivXCodecVersionChecker.exe
2007-10-12 23:13 ——— d—–w C:\Program Files\Common Files\Adobe
.

((((((((((((((((((((((((((((( snapshot@2007-12-09_ 6.14.55.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-08-24 14:28:54 141,424 —-a-w C:\WINDOWS\Downloaded Program Files\asinst.dll
+ 2007-03-29 15:20:50 110,592 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\as.dll
+ 2006-10-05 22:15:26 233,472 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\ascontrol.dll
+ 2005-06-03 20:03:18 96,256 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\asmdat.dll
+ 2003-08-01 17:00:16 36,864 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\certdll.dll
+ 2005-05-20 19:42:44 86,016 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\instlsp.dll
+ 2006-02-17 00:20:20 4,608 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\memvfile.dll
+ 2005-10-26 00:08:32 348,160 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\msvcr71.dll
+ 2004-05-04 21:01:02 139,264 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavaleas.dll
+ 2006-07-14 19:04:10 45,056 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavdr.exe
+ 2006-04-10 16:50:02 159,832 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavexcom.dll
+ 2006-02-14 19:05:38 94,208 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavinas.dll
+ 2006-02-17 00:35:38 180,224 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavoe.dll
+ 2006-10-05 22:15:38 122,880 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavpz.dll
+ 2006-06-30 20:13:38 8,704 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pfdnnt.exe
+ 2004-02-04 20:08:42 49,152 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\port32.dll
+ 2006-08-01 19:23:10 69,632 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pscpu.dll
+ 2006-08-23 19:06:08 1,388,544 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskahk.dll
+ 2006-08-17 17:38:14 10,752 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskalloc.dll
+ 2006-09-04 17:49:54 61,440 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskas.dll
+ 2006-08-18 14:46:18 779,264 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskavs.dll
+ 2007-03-26 20:25:34 417,792 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskcmp.dll
+ 2006-08-09 16:42:24 90,112 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskfss.dll
+ 2006-07-19 16:55:58 208,896 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskhtml.dll
+ 2006-01-20 22:57:00 9,728 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskmas.dll
+ 2006-05-17 15:50:12 14,336 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskmdfs.dll
+ 2006-08-16 16:58:12 33,280 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskpack.dll
+ 2006-06-30 20:42:36 266,240 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskscs.dll
+ 2006-08-17 20:33:14 62,976 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskutil.dll
+ 2006-08-08 19:13:10 13,312 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskvfile.dll
+ 2006-08-18 14:53:08 69,632 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskvfs.dll
+ 2006-08-18 14:49:50 167,936 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskvm.dll
+ 2007-04-18 23:16:04 353,840 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\psscan.dll
+ 2007-01-22 20:42:48 35,328 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\rawvfile.dll
+ 1997-09-18 12:12:32 9,488 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\sporder.dll
+ 2006-02-28 23:23:40 69,632 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\tcpvfile.dll
+ 2006-08-02 18:39:06 73,728 —-a-w C:\WINDOWS\SYSTEM32\asuninst.exe
- 2007-12-09 11:13:12 32,768 -c–a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2007-12-11 23:45:07 32,768 -c–a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
- 2007-12-09 11:13:12 32,768 -c–a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2007-12-11 23:45:07 32,768 -c–a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
- 2007-12-09 11:13:12 32,768 -c–a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT
+ 2007-12-11 23:45:07 32,768 –sha-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2003-03-26 00:53:50 11,776 —-a-w C:\WINDOWS\SYSTEM32\ZPORT4AS.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 08:59]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-23 20:31]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-02-02 16:32]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 08:59]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 01:56 C:\WINDOWS\SYSTEM32\rundll32.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 11:50 C:\WINDOWS\LOGI_MWX.EXE]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-06-21 11:40]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-08-14 17:22]
"DeviceDiscovery"="C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 17:37]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 10:09]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 11:28]
"!AVG Anti-Spyware"="C:\Documents and Settings\sadie adams\Desktop\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 01:56]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-03-06 23:06]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2003-09-02 15:00:53]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=C:\WINDOWS\pss\HotSync Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^sadie adams^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\sadie adams\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AccuWeatherDesktopAlerts]
C:\Program Files\AccuWeatherDesktopAlerts\AccuWeatherDesktopAlerts.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-02 18:36 267048 –a—— C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagent_exe]
C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
2007-03-06 23:06 5181440 –a—— C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor]
2007-01-17 13:24 36904 –a—— C:\Program Files\SiteAdvisor\6172\SiteAdv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_8

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE -quiet

S3 cdrmkaun;cdrmkaun;\??\C:\DOCUME~1\SADIEA~1\LOCALS~1\Temp\cdrmkaun.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-12-11 09:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
"2007-12-06 05:14:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-15 07:15:34 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2007-12-01 07:00:17 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2005-03-27 23:23:50 C:\WINDOWS\Tasks\WebReg 20050327172350.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqwrg.exe
.
**************************************************************************

catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-11 18:10:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0





Thanks Scotty :D
**************************************************************************
.
Completion time: 2007-12-11 18:11:35
C:\ComboFix2.txt … 2007-12-09 20:08
C:\ComboFix3.txt … 2007-12-09 17:25
.
— E O F —
Hello Sadie

Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):

O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4058/ftp…tle/Coupons.cab


WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit HijackThis.


Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job
C:\DOCUME~1\SADIEA~1\LOCALS~1\Temp\cdrmkaun.sys 

Folder::
C:\Program Files\AdwareAlert

Driver::
cdrmkaun

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run
Hello Scotty

ComboFix 07-12-12.3 - sadie adams 2007-12-11 20:05:56.11 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.227 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\sadie adams\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\DOCUME~1\SADIEA~1\LOCALS~1\Temp\cdrmkaun.sys
C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CDRMKAUN
——-\cdrmkaun


((((((((((((((((((((((((( Files Created from 2007-11-12 to 2007-12-12 )))))))))))))))))))))))))))))))
.

2007-12-10 17:24 . 2007-12-10 19:05 d——– C:\WINDOWS\SYSTEM32\ActiveScan
2007-12-10 17:24 . 2007-12-10 17:24 30,590 –a—— C:\WINDOWS\SYSTEM32\pavas.ico
2007-12-10 17:24 . 2007-12-10 17:24 2,550 –a—— C:\WINDOWS\SYSTEM32\Uninstall.ico
2007-12-10 17:24 . 2007-12-10 17:24 1,406 –a—— C:\WINDOWS\SYSTEM32\Help.ico
2007-12-09 17:40 . 2007-12-09 17:40 d—-c— C:\Documents and Settings\sadie adams\Application Data\AdwareAlert
2007-12-09 07:16 . 2007-12-09 17:31 3,642 –a—— C:\WINDOWS\SYSTEM32\tmp.reg
2007-12-09 06:47 . 2003-09-02 15:03 d—-c— C:\Documents and Settings\Administrator.D14HKF31\WINDOWS
2007-12-09 06:47 . 2005-05-20 22:59 d—-c— C:\Documents and Settings\Administrator.D14HKF31\Application Data\Gtek
2007-12-09 06:42 . 2007-12-09 06:42 d—-c— C:\Documents and Settings\sadie adams\Application Data\Grisoft
2007-12-09 06:39 . 2007-12-09 06:39 d—-c— C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 06:39 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-12-08 16:50 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\SYSTEM32\msvcr80.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-11 00:31 ——— d—–w C:\Program Files\iTunes
2007-12-11 00:26 ——— d—–w C:\Program Files\Digital Line Detect
2007-12-10 20:41 ——— dc—-w C:\Documents and Settings\sadie adams\Application Data\LimeWire
2007-12-08 18:20 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-05 06:00 ——— dc—-w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-11-22 15:24 ——— d—–w C:\Program Files\McAfee
2007-11-14 21:39 ——— dc—-w C:\Documents and Settings\sadie adams\Application Data\SiteAdvisor
2007-11-11 14:21 ——— d—–w C:\Program Files\DivX
2007-11-11 14:11 ——— d—–w C:\Program Files\QUICKENW
2007-11-11 14:10 ——— d—–w C:\Program Files\PhotoParade
2007-11-11 14:09 ——— d—–w C:\Program Files\Common Files\Intuit
2007-11-11 14:05 ——— d—–w C:\Program Files\Java
2007-11-11 14:01 ——— d—–w C:\Program Files\Common Files\Java
2007-11-11 13:38 ——— d—–w C:\Program Files\eGames
2007-11-11 13:36 ——— dc-ha-w C:\Documents and Settings\All Users\Application Data\GTek
2007-11-11 13:36 ——— dc-h–w C:\Documents and Settings\sadie adams\Application Data\GTek
2007-11-11 13:35 ——— d—–w C:\Program Files\Dell
2007-11-11 13:33 ——— d—–w C:\Program Files\Britannica
2007-11-11 13:32 ——— d—–w C:\Program Files\Apple Software Update
2007-11-10 13:20 ——— d—–w C:\Program Files\iPod
2007-11-10 13:17 ——— d—–w C:\Program Files\QuickTime
2007-11-07 23:15 ——— dc—-w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-11-07 23:15 ——— dc—-w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-07 23:15 ——— d—–w C:\Program Files\Yahoo!
2007-11-06 00:00 ——— dc—-w C:\Documents and Settings\sadie adams\Application Data\Apple Computer
2007-10-20 18:11 ——— d—–w C:\Program Files\Google
2007-10-12 23:13 ——— d—–w C:\Program Files\Common Files\Adobe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 08:59]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-23 20:31]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-02-02 16:32]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 08:59]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 01:56 C:\WINDOWS\SYSTEM32\rundll32.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 11:50 C:\WINDOWS\LOGI_MWX.EXE]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-06-21 11:40]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-08-14 17:22]
"DeviceDiscovery"="C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 17:37]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 10:09]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 11:28]
"!AVG Anti-Spyware"="C:\Documents and Settings\sadie adams\Desktop\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-03-06 23:06]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2003-09-02 15:00:53]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=C:\WINDOWS\pss\HotSync Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^sadie adams^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\sadie adams\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AccuWeatherDesktopAlerts]
C:\Program Files\AccuWeatherDesktopAlerts\AccuWeatherDesktopAlerts.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-02 18:36 267048 –a—— C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagent_exe]
C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
2007-03-06 23:06 5181440 –a—— C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor]
2007-01-17 13:24 36904 –a—— C:\Program Files\SiteAdvisor\6172\SiteAdv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_8

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE -quiet


.
Contents of the 'Scheduled Tasks' folder
"2007-12-06 05:14:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-15 07:15:34 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2007-12-01 07:00:17 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2005-03-27 23:23:50 C:\WINDOWS\Tasks\WebReg 20050327172350.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqwrg.exeX/TaskName 20050327172350 /N
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-11 20:11:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-11 20:14:42 - machine was rebooted
C:\ComboFix2.txt … 2007-12-11 18:11
C:\ComboFix3.txt … 2007-12-09 20:08
.
2007-11-14 12:25:24 — E O F —











Logfile of HijackThis v1.99.1
Scan saved at 8:17:51 PM, on 12/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\sadie adams\Desktop\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Documents and Settings\sadie adams\Desktop\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cm.my.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\sadie adams\Desktop\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…76/mcinsctl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase9602.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1125787560953
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,16/mcgdmgr.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://128.206.143.98/activex/AMC.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Documents and Settings\sadie adams\Desktop\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Hi

Congratulations, you appear to be malware free.

You may wish to keep hold of the Panda Online Scan as an extra on-demand virus-scanner.
If not you can uninstall it through Start>Control Panel>Add/Remove Programs


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the x and the /u, it needs to be there.

    [external image: Posted Image]
  • When shown the disclaimer, Select "2"


Here are some free programs I recommend, although you will not need them all, or may have them already.

Spybot Search and Destroy
Download it from here . Just choose a mirror and off you go.
Find here the tutorial on how to use Spybot properly here

Install Spyware Guard
Download it from here
Find here the tutorial on how to use Spyware Guard here

Install SpyWare Blaster
Download it from here
Find here the tutorial on how to use Spyware Blaster here

Install WinPatrol
Download it from here
Here you can find information about how WinPatrol works here


Make sure your Windows is ALWAYS up to date!

An unpatched Windows is vulnerable and even with the "best" Antivirus and Firewall installed, malware will find its way through.
So visit http://windowsupdate.microsoft.com/ to download and install the latest updates.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Please check out Tony Klein's article "How did I get infected in the first place?"


Follow this list and your potential for being infected again will reduce dramatically.

I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can be closed.
Hi Scotty! Thank you so much for your help..When I try to run the combo fix like you said it uninstalls it. And do you think it's safe for me to donate to this site online? Thanks, Sadie
Hello Sadie That was the uninstall combofix command I had you run. :) I guess you would need a Paypal account or you can mail something. Click on Donate at the top of the page and the details are there. Good luck. :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI