This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] not-a-virus:AdWare.Win32.Virtumonde.bjc Removal

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I left my computer on at my house while i was at a freinds house. I came home and realized my sisters name was logged on to aol and she had downloaded something from her friend and computer was running unusually slow…I knew i had some sort of virus and/or spyware. I have since downloaded zone alarm and it keeps telling me that I have not-a-virus:AdWare.Win32.Virtumonde.bjc and it gives me the option to delete and or quarintine ive done both and it keeps coming back and my computer is super super slow. I've tried just about everyting i know and was wondering if there is any1 out there who could help me remove this. I also get alot of pop ups and its annoying me

Logfile of HijackThis v1.99.1
Scan saved at 2:43:05 PM, on 12/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\FrostWire\FrostWire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=2070828
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=ab…NYMeO1_sAug4Kh4
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: E404Helper - {164a7474-8ff8-4003-baea-5b00dcf21ff2} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\xxsypxiv.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
Hello and Welcome to the forum.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.

Open the HijackThis Folder. Find the file HijackThis.exe, Right Click on the file and Select Rename. Rename Hijackthis.exe to Spyware.exe.

Post a new HijackThis Log.
I believe this is what you want, and also when i go to sites with adveritising on it the ad's are replaced with ur Computer is infected ad's and this also includes Youtube.com


Logfile of HijackThis v1.99.1
Scan saved at 3:48:45 PM, on 12/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\MoFo\Desktop\hijackthis\spyware.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=2070828
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=ab…NYMeO1_sAug4Kh4
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {AF97DA8E-91A8-41B3-B25D-B268F3A113D6} - C:\WINDOWS\system32\awtqq.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: ddccccb - ddccccb.dll (file missing)
O20 - Winlogon Notify: winfon32 - winfon32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: E404Helper - {164a7474-8ff8-4003-baea-5b00dcf21ff2} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\xxsypxiv.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
ComboFix 07-12-21.4 - MoFo 2007-12-22 19:22:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.529 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\crosof~1
C:\Program Files\Helper
C:\Program Files\mantec~1
C:\Program Files\mantec~1\??mantec\
C:\WINDOWS\system32\awtqq.dll
C:\WINDOWS\system32\qqtwa.bak2
C:\WINDOWS\system32\qqtwa.ini
C:\WINDOWS\system32\wnsintsv32.exe
C:\WINDOWS\system32\xpdx.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE
——-\DomainService
——-\xpdx


((((((((((((((((((((((((( Files Created from 2007-11-23 to 2007-12-23 )))))))))))))))))))))))))))))))
.

2007-12-21 07:48 . 2007-12-21 10:36 143 –a—— C:\WINDOWS\system32\mcrh.tmp
2007-12-17 09:16 . 2007-03-29 04:42 29,704 –a—— C:\WINDOWS\system32\uxtuneup.dll
2007-12-15 08:25 . 2007-12-15 08:25 59 –a—— C:\WINDOWS\LTDLG13N.INI
2007-12-13 05:11 . 2007-12-15 13:58 d——– C:\Program Files\Alt WAV MP3 WMA OGG Converter
2007-12-13 03:32 . 2007-12-13 03:32 d——– C:\OUT_MEDIA_FILES
2007-12-13 03:32 . 2001-03-17 20:34 22,528 –a—— C:\WINDOWS\system32\WNASPI32.DLL
2007-12-13 03:32 . 2002-07-17 08:05 16,512 –a—— C:\WINDOWS\system32\drivers\ASPI32.SYS
2007-12-13 01:46 . 2007-12-13 01:46 d——– C:\Program Files\Illustrate
2007-12-13 01:46 . 2007-12-13 01:46 d——– C:\Documents and Settings\MoFo\Application Data\AccurateRip
2007-12-13 01:46 . 2007-12-13 01:45 4,229,496 –a—— C:\WINDOWS\system32\SpoonUninstall.exe
2007-12-13 01:27 . 2007-12-13 01:39 d——– C:\Documents and Settings\MoFo\Application Data\Winamp
2007-12-13 01:05 . 2007-12-13 01:27 d——– C:\Program Files\Winamp
2007-12-12 08:34 . 2007-12-12 08:34 d——– C:\Documents and Settings\All Users\Application Data\PC Suite
2007-12-12 08:33 . 2007-12-12 08:33 d——– C:\Program Files\DIFX
2007-12-12 08:33 . 2007-12-12 08:34 d——– C:\Documents and Settings\MoFo\Application Data\Nokia
2007-12-12 08:31 . 2007-12-12 08:34 d——– C:\Documents and Settings\MoFo\Application Data\PC Suite
2007-12-12 08:30 . 2007-12-12 08:30 d——– C:\Program Files\PC Connectivity Solution
2007-12-12 08:30 . 2007-02-22 10:15 90,624 –a—— C:\WINDOWS\system32\nmwcdcls.dll
2007-12-12 08:29 . 2007-12-12 08:29 d——– C:\Documents and Settings\All Users\Application Data\Installations
2007-12-11 05:12 . 2007-12-11 05:12 dr-h—– C:\MSOCache
2007-12-11 05:12 . 2007-12-11 05:18 d——– C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-10 19:43 . 2007-12-10 20:07 d——– C:\Documents and Settings\MoFo\Application Data\DivX
2007-12-10 19:38 . 2007-11-29 17:30 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2007-12-10 19:13 . 2007-12-11 05:20 d——– C:\Program Files\DivX
2007-12-10 19:07 . 2004-03-29 16:23 90,112 –a—— C:\WINDOWS\unvise32.exe
2007-12-10 18:55 . 2007-12-10 18:56 d——– C:\Program Files\The Rosetta Stone
2007-12-10 17:35 . 2006-12-19 16:53 24,072 –a—— C:\WINDOWS\system32\uxt17C.tmp
2007-12-10 17:34 . 2007-12-17 09:16 d——– C:\Program Files\TuneUp Utilities 2007
2007-12-10 17:34 . 2007-12-10 17:34 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-12-10 17:34 . 2007-12-10 17:34 d——– C:\Documents and Settings\MoFo\Application Data\TuneUp Software
2007-12-10 17:34 . 2007-12-10 17:34 d——– C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-12-10 15:24 . 2007-12-22 19:30 8,899,104 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-10 15:24 . 2007-12-22 19:30 125,780 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-10 15:20 . 2007-12-10 17:01 d——– C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-12-10 15:20 . 2007-11-14 16:05 1,086,952 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-12-10 15:15 . 2007-12-21 10:28 d——– C:\Documents and Settings\MoFo\Application Data\MailFrontier
2007-12-10 15:07 . 2006-03-16 11:13 657,184 –a—— C:\WINDOWS\system32\imsinstall.dll
2007-12-10 15:07 . 2007-11-14 16:05 75,248 –a—— C:\WINDOWS\zllsputility.exe
2007-12-10 15:07 . 2004-04-27 04:40 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2007-12-10 15:06 . 2007-12-22 19:32 355,090 –ah—– C:\WINDOWS\system32\vsconfig.xml
2007-12-10 14:59 . 2007-12-10 14:59 4,128 –a—— C:\INFCACHE.1
2007-12-10 12:57 . 2007-12-22 18:42 959 –a—— C:\rollback.ini
2007-12-10 06:35 . 2007-12-10 15:25 841,914 –ahs—- C:\WINDOWS\system32\byvdprac.ini
2007-12-10 05:25 . 2007-12-10 05:25 d——– C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Spyware
2007-12-10 04:44 . 2007-12-10 04:49 524 –a—— C:\WINDOWS\system32\tmp.reg
2007-12-10 03:29 . 2007-12-19 21:22 d—s—- C:\WINDOWS\Downloaded Program Files
2007-12-10 03:29 . 2007-12-10 03:32 d——– C:\Program Files\Windows Live Safety Center
2007-12-09 20:35 . 2007-12-10 17:12 d——– C:\Program Files\RegVac Registry Cleaner
2007-12-09 20:17 . 2007-12-09 20:17 0 –a—— C:\WINDOWS\LogMeIn_uninstall_reboot
2007-12-09 16:51 . 2007-12-10 17:13 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-09 10:30 . 2007-12-09 10:30 d——– C:\Documents and Settings\MoFo\Application Data\Symantec
2007-12-09 10:07 . 2007-12-09 10:07 d——– C:\Documents and Settings\All Users\Application Data\Prevx
2007-12-09 10:06 . 2007-12-09 10:08 d——– C:\Documents and Settings\MoFo\Application Data\PrevxCSI
2007-12-09 06:34 . 2007-12-22 19:30 d——– C:\WINDOWS\system32\ZoneLabs
2007-12-09 06:34 . 2007-12-22 15:29 4,212 –ah—– C:\WINDOWS\system32\zllictbl.dat
2007-12-09 06:33 . 2007-12-22 19:31 d——– C:\WINDOWS\Internet Logs
2007-12-09 06:24 . 2007-12-09 06:25 d——– C:\Documents and Settings\Administrator\Application Data\U3
2007-12-09 05:57 . 2007-12-09 05:57 d——– C:\Program Files\Lavasoft
2007-12-09 05:57 . 2007-12-09 05:57 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-07 22:50 . 2007-12-07 22:50 d——– C:\Program Files\Common Files\Adobe Systems Shared
2007-12-07 22:50 . 2007-12-07 22:50 d——– C:\Documents and Settings\All Users\Application Data\Adobe Systems
2007-12-03 20:33 . 2007-12-03 20:33 823,296 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2007-12-03 20:33 . 2007-12-03 20:33 823,296 –a—— C:\WINDOWS\system32\divx_xx07.dll
2007-12-03 20:33 . 2007-12-03 20:33 802,816 –a—— C:\WINDOWS\system32\divx_xx11.dll
2007-12-03 20:33 . 2007-12-03 20:33 682,496 –a—— C:\WINDOWS\system32\DivX.dll
2007-12-03 00:23 . 2004-08-04 00:56 16,384 –a—— C:\WINDOWS\system32\ipsink.ax
2007-12-03 00:23 . 2004-08-04 00:56 16,384 –a—— C:\WINDOWS\system32\dllcache\ipsink.ax
2007-12-03 00:23 . 2004-08-03 23:10 15,360 –a—— C:\WINDOWS\system32\drivers\StreamIP.sys
2007-12-03 00:23 . 2004-08-03 23:10 15,360 –a—— C:\WINDOWS\system32\dllcache\streamip.sys
2007-12-03 00:23 . 2004-08-03 23:10 10,880 –a—— C:\WINDOWS\system32\drivers\NdisIP.sys
2007-12-03 00:23 . 2004-08-03 23:10 10,880 –a—— C:\WINDOWS\system32\dllcache\ndisip.sys
2007-12-03 00:23 . 2004-08-03 22:58 5,504 –a—— C:\WINDOWS\system32\drivers\MSTEE.sys
2007-12-03 00:23 . 2004-08-03 22:58 5,504 –a—— C:\WINDOWS\system32\dllcache\mstee.sys
2007-12-03 00:20 . 2007-12-03 00:20 d——– C:\WINDOWS\EffectResources
2007-12-03 00:20 . 2007-12-03 00:20 d——– C:\WINDOWS\CatRoot
2007-12-03 00:20 . 2007-12-03 00:20 d——– C:\Program Files\Vimicro
2007-12-03 00:20 . 2006-06-10 17:51 389,585 –a—— C:\WINDOWS\system32\drivers\usbVM302.sys
2007-12-03 00:20 . 2000-10-31 12:00 307,200 –a—— C:\WINDOWS\vidcap32.Exe
2007-12-03 00:20 . 2006-06-12 11:12 188,540 –a—— C:\WINDOWS\system32\VM302Prp.Ax
2007-12-03 00:20 . 2005-04-30 18:46 102,400 –a—— C:\WINDOWS\VM302Cap.exe
2007-12-03 00:20 . 2005-04-30 18:46 81,920 –a—— C:\WINDOWS\system32\VM302STI.dll
2007-12-03 00:20 . 2005-04-30 18:46 53,248 –a—— C:\WINDOWS\Sti302.exe
2007-12-03 00:20 . 2005-04-30 18:46 49,152 –a—— C:\WINDOWS\Volumeset.exe
2007-12-03 00:20 . 2005-04-30 18:46 49,152 –a—— C:\WINDOWS\VM_STI.EXE
2007-12-03 00:20 . 2002-10-16 09:29 49,152 –a—— C:\WINDOWS\amcap.exe
2007-12-01 21:00 . 2007-12-11 05:15 d——– C:\Program Files\Microsoft.NET
2007-12-01 04:40 . 2007-12-10 16:35 d——– C:\Program Files\RealVNC
2007-12-01 02:24 . 2007-11-15 18:46 87,352 –a—— C:\WINDOWS\system32\LMIinit.dll
2007-12-01 02:24 . 2007-11-15 18:46 83,288 –a—— C:\WINDOWS\system32\LMIRfsClientNP.dll.000.bak
2007-12-01 02:24 . 2007-11-15 18:46 21,496 –a—— C:\WINDOWS\system32\LMIport.dll
2007-11-29 17:30 . 2007-11-29 17:30 3,596,288 –a—— C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 17:30 . 2007-11-29 17:30 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-11-29 17:30 . 2007-11-29 17:30 524,288 –a—— C:\WINDOWS\system32\DivXsm.exe
2007-11-29 17:30 . 2007-11-29 17:30 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-11-29 17:30 . 2007-11-29 17:30 4,816 –a—— C:\WINDOWS\system32\divxsm.tlb
2007-11-29 17:28 . 2007-11-29 17:28 196,608 –a—— C:\WINDOWS\system32\dtu100.dll
2007-11-29 17:28 . 2007-11-29 17:28 81,920 –a—— C:\WINDOWS\system32\dpl100.dll
2007-11-29 17:28 . 2007-11-29 17:28 416 –a—— C:\WINDOWS\system32\dtu100.dll.manifest
2007-11-29 17:28 . 2007-11-29 17:28 416 –a—— C:\WINDOWS\system32\dpl100.dll.manifest
2007-11-28 16:55 . 2007-11-28 16:55 156,992 –a—— C:\WINDOWS\system32\DivXCodecVersionChecker.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-22 06:20 ——— d—–w C:\Program Files\DsNET Corp
2007-12-21 01:16 ——— d—–w C:\Program Files\FrostWire
2007-12-20 02:23 ——— d—–w C:\Program Files\AIM6
2007-12-20 02:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-12-15 13:49 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-12 16:18 ——— d—–w C:\Program Files\Microsoft ActiveSync
2007-12-11 10:16 ——— d—–w C:\Program Files\Microsoft Works
2007-12-10 20:12 ——— d—–w C:\Program Files\Google
2007-12-10 01:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-10 01:29 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-09 13:26 ——— d—–w C:\Program Files\DIGStream
2007-12-08 03:53 ——— d—–w C:\Program Files\Common Files\Adobe
2007-12-03 23:58 ——— d—–w C:\Documents and Settings\MoFo\Application Data\FrostWire
2007-11-29 22:30 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-11-21 07:21 ——— d—–w C:\Documents and Settings\MoFo\Application Data\U3
2007-11-17 22:59 ——— d—–w C:\Documents and Settings\MoFo\Application Data\CyberLink
2007-11-14 03:16 ——— d—–w C:\Documents and Settings\MoFo\Application Data\Ahead
2007-11-14 03:00 ——— d—–w C:\Program Files\Ahead
2007-11-14 02:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\Ahead
2007-11-14 02:57 ——— d—–w C:\Program Files\Common Files\Ahead
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-13 07:21 ——— d—–w C:\Program Files\Java
2007-11-13 07:20 ——— d—–w C:\Program Files\LimeWire
2007-11-12 23:09 ——— d—–w C:\Documents and Settings\MoFo\Application Data\LimeWire
2007-11-10 07:09 ——— d—–w C:\Program Files\Common Files\SWF Studio
2007-11-10 07:08 ——— d—–w C:\Documents and Settings\MoFo\Application Data\Morpheus Software
2007-10-29 04:46 ——— d—–w C:\Program Files\Viewpoint
2007-10-29 04:46 ——— d—–w C:\Program Files\Common Files\AOL
2007-10-29 04:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-09-24 22:01 737,280 —-a-w C:\WINDOWS\iun6002.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 05:00]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 12:39]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-12-18 14:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddccccb]
ddccccb.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winfon32]
winfon32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^MoFo^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\MoFo\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
C:\Program Files\AIM6\aim6.exe /d locale=en-US ee://aol/imApp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe runtime -Delay

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDog302]
C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera 302

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU]
2004-02-19 05:23 61440 –a—— c:\dell\bldbubg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-10 05:00 15360 –a—— C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
C:\Program Files\Dell Support\DSAgnt.exe /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2004-12-06 01:05 127035 –a—— C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-09-29 14:01 67584 –a—— C:\WINDOWS\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gdlvvf]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 12:39 1289000 –a—— C:\Program Files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
2006-10-18 18:04 802816 –a—— C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe -start

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ModemOnHold]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 11:50 155648 –a—— C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2007-05-02 18:16 184320 ——— C:\Program Files\Dell\MediaDirect\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
mgrs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-07-12 04:00 132496 –a—— C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2006-03-08 11:48 761947 –a—— C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tunmfkbq]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uaol]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows update loader]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Aim6"="C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs []
R2 windrvNT;windrvNT;C:\WINDOWS\system32\windrvNT.sys [2007-12-20 10:40]
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 08:05]
S3 lmimirr;lmimirr;C:\WINDOWS\system32\DRIVERS\lmimirr.sys []
S3 ZSMC302;VIMICRO USB PC Camera 302;C:\WINDOWS\system32\Drivers\usbVM302.sys [2006-06-10 17:51]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

.
Contents of the 'Scheduled Tasks' folder
"2007-12-14 23:26:04 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-22 19:32:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

disk error: C:\WINDOWS\

**************************************************************************
.
Completion time: 2007-12-22 19:35:30 - machine was rebooted
.
2007-12-12 12:14:54 — E O F —
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\iun6002.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

Folder::
C:\Program Files\Viewpoint
C:\Program Files\Google\Google Desktop Search

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddccccb]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winfon32]


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.

Also please describe how your computer behaves at the moment.
This is the combo Fix log
ComboFix 07-12-21.4 - MoFo 2007-12-22 20:23:32.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.573 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\MoFo\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\iun6002.exe
C:\WINDOWS\system32\mcrh.tmp
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Viewpoint
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Common\VistaBoot.sdll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\ClassIDs.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\ComponentMgr.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\ComponentMgr_0305001C.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\ComponentRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\AOLArt.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\AOLShell.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\AOLUserShell.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\Cursors.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\DataTracking.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\GifReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\JpegReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\LensFlares.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\Mts3Reader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\ObjectMovie.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\SceneComponent.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\ServiceComponent.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\SreeDMMX.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\SWFView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VectorView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VETScriptInterpreter.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPAudio.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPExtras.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPSpeech.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPVideo.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPVideo2.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\WaveletReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\ZoomView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\DownLoadHist.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\HostRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\MtsAxInstaller.exe
C:\Program Files\Viewpoint\Viewpoint Experience Technology\MTSDownloadSites.txt
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\AOLUserShell.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\Cursors.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\JpegReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\Mts3Reader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\SceneComponent.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\SreeDMMX.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\SWFView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\VETScriptInterpreter.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMPSpeech.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMPVideo2.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.xpt
C:\WINDOWS\iun6002.exe
C:\WINDOWS\system32\mcrh.tmp

.
((((((((((((((((((((((((( Files Created from 2007-11-23 to 2007-12-23 )))))))))))))))))))))))))))))))
.

2007-12-17 09:16 . 2007-03-29 04:42 29,704 –a—— C:\WINDOWS\system32\uxtuneup.dll
2007-12-15 08:25 . 2007-12-15 08:25 59 –a—— C:\WINDOWS\LTDLG13N.INI
2007-12-13 05:11 . 2007-12-15 13:58 d——– C:\Program Files\Alt WAV MP3 WMA OGG Converter
2007-12-13 03:32 . 2007-12-13 03:32 d——– C:\OUT_MEDIA_FILES
2007-12-13 03:32 . 2001-03-17 20:34 22,528 –a—— C:\WINDOWS\system32\WNASPI32.DLL
2007-12-13 03:32 . 2002-07-17 08:05 16,512 –a—— C:\WINDOWS\system32\drivers\ASPI32.SYS
2007-12-13 01:46 . 2007-12-13 01:46 d——– C:\Program Files\Illustrate
2007-12-13 01:46 . 2007-12-13 01:46 d——– C:\Documents and Settings\MoFo\Application Data\AccurateRip
2007-12-13 01:46 . 2007-12-13 01:45 4,229,496 –a—— C:\WINDOWS\system32\SpoonUninstall.exe
2007-12-13 01:27 . 2007-12-13 01:39 d——– C:\Documents and Settings\MoFo\Application Data\Winamp
2007-12-13 01:05 . 2007-12-13 01:27 d——– C:\Program Files\Winamp
2007-12-12 08:34 . 2007-12-12 08:34 d——– C:\Documents and Settings\All Users\Application Data\PC Suite
2007-12-12 08:33 . 2007-12-12 08:33 d——– C:\Program Files\DIFX
2007-12-12 08:33 . 2007-12-12 08:34 d——– C:\Documents and Settings\MoFo\Application Data\Nokia
2007-12-12 08:31 . 2007-12-12 08:34 d——– C:\Documents and Settings\MoFo\Application Data\PC Suite
2007-12-12 08:30 . 2007-12-12 08:30 d——– C:\Program Files\PC Connectivity Solution
2007-12-12 08:30 . 2007-02-22 10:15 90,624 –a—— C:\WINDOWS\system32\nmwcdcls.dll
2007-12-12 08:29 . 2007-12-12 08:29 d——– C:\Documents and Settings\All Users\Application Data\Installations
2007-12-11 05:12 . 2007-12-11 05:12 dr-h—– C:\MSOCache
2007-12-11 05:12 . 2007-12-11 05:18 d——– C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-10 19:43 . 2007-12-10 20:07 d——– C:\Documents and Settings\MoFo\Application Data\DivX
2007-12-10 19:38 . 2007-11-29 17:30 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2007-12-10 19:13 . 2007-12-11 05:20 d——– C:\Program Files\DivX
2007-12-10 19:07 . 2004-03-29 16:23 90,112 –a—— C:\WINDOWS\unvise32.exe
2007-12-10 18:55 . 2007-12-10 18:56 d——– C:\Program Files\The Rosetta Stone
2007-12-10 17:35 . 2006-12-19 16:53 24,072 –a—— C:\WINDOWS\system32\uxt17C.tmp
2007-12-10 17:34 . 2007-12-17 09:16 d——– C:\Program Files\TuneUp Utilities 2007
2007-12-10 17:34 . 2007-12-10 17:34 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-12-10 17:34 . 2007-12-10 17:34 d——– C:\Documents and Settings\MoFo\Application Data\TuneUp Software
2007-12-10 17:34 . 2007-12-10 17:34 d——– C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-12-10 15:24 . 2007-12-22 19:30 8,899,104 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-10 15:24 . 2007-12-22 19:30 125,780 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-10 15:20 . 2007-12-10 17:01 d——– C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-12-10 15:20 . 2007-11-14 16:05 1,086,952 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-12-10 15:15 . 2007-12-21 10:28 d——– C:\Documents and Settings\MoFo\Application Data\MailFrontier
2007-12-10 15:07 . 2006-03-16 11:13 657,184 –a—— C:\WINDOWS\system32\imsinstall.dll
2007-12-10 15:07 . 2007-11-14 16:05 75,248 –a—— C:\WINDOWS\zllsputility.exe
2007-12-10 15:07 . 2004-04-27 04:40 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2007-12-10 15:06 . 2007-12-22 19:32 355,090 –ah—– C:\WINDOWS\system32\vsconfig.xml
2007-12-10 14:59 . 2007-12-10 14:59 4,128 –a—— C:\INFCACHE.1
2007-12-10 12:57 . 2007-12-22 18:42 959 –a—— C:\rollback.ini
2007-12-10 06:35 . 2007-12-10 15:25 841,914 –ahs—- C:\WINDOWS\system32\byvdprac.ini
2007-12-10 05:25 . 2007-12-10 05:25 d——– C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Spyware
2007-12-10 04:44 . 2007-12-10 04:49 524 –a—— C:\WINDOWS\system32\tmp.reg
2007-12-10 03:29 . 2007-12-19 21:22 d—s—- C:\WINDOWS\Downloaded Program Files
2007-12-10 03:29 . 2007-12-10 03:32 d——– C:\Program Files\Windows Live Safety Center
2007-12-09 20:35 . 2007-12-10 17:12 d——– C:\Program Files\RegVac Registry Cleaner
2007-12-09 20:17 . 2007-12-09 20:17 0 –a—— C:\WINDOWS\LogMeIn_uninstall_reboot
2007-12-09 16:51 . 2007-12-10 17:13 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-09 10:30 . 2007-12-09 10:30 d——– C:\Documents and Settings\MoFo\Application Data\Symantec
2007-12-09 10:07 . 2007-12-09 10:07 d——– C:\Documents and Settings\All Users\Application Data\Prevx
2007-12-09 10:06 . 2007-12-09 10:08 d——– C:\Documents and Settings\MoFo\Application Data\PrevxCSI
2007-12-09 06:34 . 2007-12-22 19:30 d——– C:\WINDOWS\system32\ZoneLabs
2007-12-09 06:34 . 2007-12-22 19:37 4,212 —h—– C:\WINDOWS\system32\zllictbl.dat
2007-12-09 06:33 . 2007-12-22 20:17 d——– C:\WINDOWS\Internet Logs
2007-12-09 06:24 . 2007-12-09 06:25 d——– C:\Documents and Settings\Administrator\Application Data\U3
2007-12-09 05:57 . 2007-12-09 05:57 d——– C:\Program Files\Lavasoft
2007-12-09 05:57 . 2007-12-09 05:57 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-07 22:50 . 2007-12-07 22:50 d——– C:\Program Files\Common Files\Adobe Systems Shared
2007-12-07 22:50 . 2007-12-07 22:50 d——– C:\Documents and Settings\All Users\Application Data\Adobe Systems
2007-12-03 20:33 . 2007-12-03 20:33 823,296 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2007-12-03 20:33 . 2007-12-03 20:33 823,296 –a—— C:\WINDOWS\system32\divx_xx07.dll
2007-12-03 20:33 . 2007-12-03 20:33 802,816 –a—— C:\WINDOWS\system32\divx_xx11.dll
2007-12-03 20:33 . 2007-12-03 20:33 682,496 –a—— C:\WINDOWS\system32\DivX.dll
2007-12-03 00:23 . 2004-08-04 00:56 16,384 –a—— C:\WINDOWS\system32\ipsink.ax
2007-12-03 00:23 . 2004-08-04 00:56 16,384 –a—— C:\WINDOWS\system32\dllcache\ipsink.ax
2007-12-03 00:23 . 2004-08-03 23:10 15,360 –a—— C:\WINDOWS\system32\drivers\StreamIP.sys
2007-12-03 00:23 . 2004-08-03 23:10 15,360 –a—— C:\WINDOWS\system32\dllcache\streamip.sys
2007-12-03 00:23 . 2004-08-03 23:10 10,880 –a—— C:\WINDOWS\system32\drivers\NdisIP.sys
2007-12-03 00:23 . 2004-08-03 23:10 10,880 –a—— C:\WINDOWS\system32\dllcache\ndisip.sys
2007-12-03 00:23 . 2004-08-03 22:58 5,504 –a—— C:\WINDOWS\system32\drivers\MSTEE.sys
2007-12-03 00:23 . 2004-08-03 22:58 5,504 –a—— C:\WINDOWS\system32\dllcache\mstee.sys
2007-12-03 00:20 . 2007-12-03 00:20 d——– C:\WINDOWS\EffectResources
2007-12-03 00:20 . 2007-12-03 00:20 d——– C:\WINDOWS\CatRoot
2007-12-03 00:20 . 2007-12-03 00:20 d——– C:\Program Files\Vimicro
2007-12-03 00:20 . 2006-06-10 17:51 389,585 –a—— C:\WINDOWS\system32\drivers\usbVM302.sys
2007-12-03 00:20 . 2000-10-31 12:00 307,200 –a—— C:\WINDOWS\vidcap32.Exe
2007-12-03 00:20 . 2006-06-12 11:12 188,540 –a—— C:\WINDOWS\system32\VM302Prp.Ax
2007-12-03 00:20 . 2005-04-30 18:46 102,400 –a—— C:\WINDOWS\VM302Cap.exe
2007-12-03 00:20 . 2005-04-30 18:46 81,920 –a—— C:\WINDOWS\system32\VM302STI.dll
2007-12-03 00:20 . 2005-04-30 18:46 53,248 –a—— C:\WINDOWS\Sti302.exe
2007-12-03 00:20 . 2005-04-30 18:46 49,152 –a—— C:\WINDOWS\Volumeset.exe
2007-12-03 00:20 . 2005-04-30 18:46 49,152 –a—— C:\WINDOWS\VM_STI.EXE
2007-12-03 00:20 . 2002-10-16 09:29 49,152 –a—— C:\WINDOWS\amcap.exe
2007-12-01 21:00 . 2007-12-11 05:15 d——– C:\Program Files\Microsoft.NET
2007-12-01 04:40 . 2007-12-10 16:35 d——– C:\Program Files\RealVNC
2007-12-01 02:24 . 2007-11-15 18:46 87,352 –a—— C:\WINDOWS\system32\LMIinit.dll
2007-12-01 02:24 . 2007-11-15 18:46 83,288 –a—— C:\WINDOWS\system32\LMIRfsClientNP.dll.000.bak
2007-12-01 02:24 . 2007-11-15 18:46 21,496 –a—— C:\WINDOWS\system32\LMIport.dll
2007-11-29 17:30 . 2007-11-29 17:30 3,596,288 –a—— C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 17:30 . 2007-11-29 17:30 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-11-29 17:30 . 2007-11-29 17:30 524,288 –a—— C:\WINDOWS\system32\DivXsm.exe
2007-11-29 17:30 . 2007-11-29 17:30 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-11-29 17:30 . 2007-11-29 17:30 4,816 –a—— C:\WINDOWS\system32\divxsm.tlb
2007-11-29 17:28 . 2007-11-29 17:28 196,608 –a—— C:\WINDOWS\system32\dtu100.dll
2007-11-29 17:28 . 2007-11-29 17:28 81,920 –a—— C:\WINDOWS\system32\dpl100.dll
2007-11-29 17:28 . 2007-11-29 17:28 416 –a—— C:\WINDOWS\system32\dtu100.dll.manifest
2007-11-29 17:28 . 2007-11-29 17:28 416 –a—— C:\WINDOWS\system32\dpl100.dll.manifest
2007-11-28 16:55 . 2007-11-28 16:55 156,992 –a—— C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-11-28 16:53 . 2007-11-28 16:53 593,920 –a—— C:\WINDOWS\system32\dpuGUI11.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-22 06:20 ——— d—–w C:\Program Files\DsNET Corp
2007-12-21 01:16 ——— d—–w C:\Program Files\FrostWire
2007-12-20 02:23 ——— d—–w C:\Program Files\AIM6
2007-12-20 02:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-12-15 13:49 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-12 16:18 ——— d—–w C:\Program Files\Microsoft ActiveSync
2007-12-11 10:16 ——— d—–w C:\Program Files\Microsoft Works
2007-12-10 20:12 ——— d—–w C:\Program Files\Google
2007-12-10 01:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-10 01:29 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-09 13:26 ——— d—–w C:\Program Files\DIGStream
2007-12-08 03:53 ——— d—–w C:\Program Files\Common Files\Adobe
2007-12-03 23:58 ——— d—–w C:\Documents and Settings\MoFo\Application Data\FrostWire
2007-11-29 22:30 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-11-29 22:30 120,056 —-a-w C:\WINDOWS\system32\pxcpyi64.exe
2007-11-29 22:30 118,520 —-a-w C:\WINDOWS\system32\pxinsi64.exe
2007-11-21 07:21 ——— d—–w C:\Documents and Settings\MoFo\Application Data\U3
2007-11-17 22:59 ——— d—–w C:\Documents and Settings\MoFo\Application Data\CyberLink
2007-11-15 23:46 10,040 —-a-w C:\WINDOWS\system32\lmimirr2.dll
2007-11-14 03:16 ——— d—–w C:\Documents and Settings\MoFo\Application Data\Ahead
2007-11-14 03:00 ——— d—–w C:\Program Files\Ahead
2007-11-14 02:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\Ahead
2007-11-14 02:57 ——— d—–w C:\Program Files\Common Files\Ahead
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-13 07:21 ——— d—–w C:\Program Files\Java
2007-11-13 07:20 ——— d—–w C:\Program Files\LimeWire
2007-11-12 23:09 ——— d—–w C:\Documents and Settings\MoFo\Application Data\LimeWire
2007-11-10 07:09 ——— d—–w C:\Program Files\Common Files\SWF Studio
2007-11-10 07:08 ——— d—–w C:\Documents and Settings\MoFo\Application Data\Morpheus Software
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:35 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-29 04:46 ——— d—–w C:\Program Files\Common Files\AOL
2007-10-29 04:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 222,720 ——w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ——w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ——w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
.

((((((((((((((((((((((((((((( snapshot@2007-12-22_19.33.50.42 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-23 00:33:46 379,188 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2007-12-23 00:33:49 379,188 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 05:00]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 12:39]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-12-18 14:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^MoFo^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\MoFo\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
C:\Program Files\AIM6\aim6.exe /d locale=en-US ee://aol/imApp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe runtime -Delay

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDog302]
C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera 302

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU]
2004-02-19 05:23 61440 –a—— c:\dell\bldbubg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-10 05:00 15360 –a—— C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
C:\Program Files\Dell Support\DSAgnt.exe /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2004-12-06 01:05 127035 –a—— C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-09-29 14:01 67584 –a—— C:\WINDOWS\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gdlvvf]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 12:39 1289000 –a—— C:\Program Files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
2006-10-18 18:04 802816 –a—— C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe -start

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ModemOnHold]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 11:50 155648 –a—— C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2007-05-02 18:16 184320 ——— C:\Program Files\Dell\MediaDirect\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
mgrs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-07-12 04:00 132496 –a—— C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2006-03-08 11:48 761947 –a—— C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tunmfkbq]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uaol]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows update loader]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Aim6"="C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs []
R2 windrvNT;windrvNT;C:\WINDOWS\system32\windrvNT.sys [2007-12-20 10:40]
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 08:05]
S3 lmimirr;lmimirr;C:\WINDOWS\system32\DRIVERS\lmimirr.sys []
S3 ZSMC302;VIMICRO USB PC Camera 302;C:\WINDOWS\system32\Drivers\usbVM302.sys [2006-06-10 17:51]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

.
Contents of the 'Scheduled Tasks' folder
"2007-12-14 23:26:04 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-22 20:27:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

disk error: C:\WINDOWS\

**************************************************************************
.
Completion time: 2007-12-22 20:29:06
C:\ComboFix2.txt … 2007-12-22 19:35
.
2007-12-12 12:14:54 — E O F —


And this is the new Hijack this log
Logfile of HijackThis v1.99.1
Scan saved at 8:29:58 PM, on 12/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\AIM6\aim6.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\MoFo\Desktop\hijackthis\spyware.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=2070828
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=ab…NYMeO1_sAug4Kh4
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: E404Helper - {164a7474-8ff8-4003-baea-5b00dcf21ff2} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Before you started helpinig my Computer was running aggrivating slow…Now at this present moment it has returned to running smoothly and is now running the way it was running before the event started.
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=2070828
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=ab…NYMeO1_sAug4Kh4
O21 - SSODL: E404Helper - {164a7474-8ff8-4003-baea-5b00dcf21ff2} - (no file)
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)

Close ALL windows and browsers except HijackThis and click "Fix checked"


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Logfile of HijackThis v1.99.1
Scan saved at 9:00:49 AM, on 12/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Documents and Settings\MoFo\Desktop\hijackthis\spyware.exe.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Well Computer is running really really good right now my computer loading up is fast and everything i do on the net is done really fast. The day the problem started my computer was just inching along and i did everything i could to do to get my computer running as good as i could get it, but it was still running slow and everytime i did anything i had alot of pop ups and what not. Since uve started helping me my computer has been improving exponentially. So once again things are running smoothly right now
Good job :thumbup:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]
  • If shown the disclaimer, Select "2"


Here's my usual all clean post

Log looks good :D


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide realtime spyware & hijacker protection on your computer alongside your virus protection.
    You should also scan your computer with this program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers
  • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
    settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

    Using IE-SPYAD to help block unwanted sites and activities

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI