This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] IE Windows popping up sometimes

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey guys,

so yeah, I have IE windows popping up sometimes to random websites even though my default browser is Firefox. Also, two or three times I've ran Ad-Aware and it's shown traces of a trojan virus, but even though I delete it, it comes back. I've followed all the steps in the "Before Posting A Hijackthis Log" topic, so below are the contents of my AVG scan and my hijackthis log. Please let me know if I need to do anything else. I'll also let you know if everything seems to be ok. Thanks!

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 2:59:43 AM 12/20/2007

+ Scan result:



C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned.
:mozilla.204:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.205:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.206:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.207:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.208:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.209:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.210:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.211:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.212:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.213:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.214:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.215:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.216:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.217:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.218:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.219:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.220:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.221:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.222:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.223:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.224:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.225:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.226:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.227:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.228:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.229:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.230:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.231:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.232:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.233:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.234:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.235:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.236:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.237:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.238:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.239:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.240:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.241:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.242:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.243:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.244:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.245:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.246:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.247:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.248:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.249:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.250:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.251:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.252:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.253:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.254:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.374:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.510:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.574:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.642:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.721:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.732:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.766:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.181:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.182:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.183:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.184:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.185:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.535:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.186:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.187:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.188:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.189:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.190:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.191:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.192:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.193:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.683:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.684:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.50:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.51:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.52:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.55:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.56:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.63:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.554:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.557:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.558:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.196:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.197:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.198:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.590:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.591:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.592:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.593:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.594:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.595:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.596:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.27:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.29:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Matt Youn\Cookies\matt_youn@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.526:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.527:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.528:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.533:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.100:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.660:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.93:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.94:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.95:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.96:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.97:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.98:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.99:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.512:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.513:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.348:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.749:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.147:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.148:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.149:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.150:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.152:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.153:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.154:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.155:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.156:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.157:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.158:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.159:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.759:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.760:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.107:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.108:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.109:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.110:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.111:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.112:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.113:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.114:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.643:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.644:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.645:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.646:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.647:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.648:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.649:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.650:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.651:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.652:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.653:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.654:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.655:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.255:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.256:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.257:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.258:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.259:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.260:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.261:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.262:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.263:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.264:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.265:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.266:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.267:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.268:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.269:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.270:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.271:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.272:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.284:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.288:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.289:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.290:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.291:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.292:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.293:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.294:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.618:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.708:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.709:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.710:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.711:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.399:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.400:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.401:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.402:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.403:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.404:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.405:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.551:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.552:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.553:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.199:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.200:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.201:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.202:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.203:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.501:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.503:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.296:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.297:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.298:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.299:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.300:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.502:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.379:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.382:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.383:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.384:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.385:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.386:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.498:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.499:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.500:C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\WINDOWS\system32\wnstssv.exe -> Trojan.Small : Cleaned.


::Report end



Logfile of HijackThis v1.99.1
Scan saved at 3:12:28 AM, on 12/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PccGuide.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iTunes\iTunes.exe
C:\Documents and Settings\Matt Youn\My Documents\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [9c8f2035] rundll32.exe "C:\WINDOWS\system32\vujbfqsw.dll",b
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
Hello, and welcome to the forum.

My name is Simon V., and I'll be glad to help you with your computer problems.

Step 1

Please download ATF Cleaner. Double-click on ATF-Cleaner.exe to start the program.

  • Under the Main tab, put a check next to Select All.
    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)
  • If you use the Firefox browser:
    Click on Firefox at the top and put a check next to Select All.
    If you would like to keep your saved passwords, click No at the prompt.
    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)
  • If you use the Opera browser:
    Click on Opera at the top and put a check next to Select All.
    If you would like to keep your saved passwords, click No at the prompt.
    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)

Step 2

Please download Combofix:

  • From BleepingComputer
  • From InfoSpyware
  • From GeeksToGo

Double-click on combofix.exe and follow the prompts.
When finished, it will produce a log for you. Save it to a convenient location.

Note: Do not mouseclick Combofix's window whilst it's running. That may cause it to stall.

Step 3

Please download and install CCleaner.

  • Open CCleaner. In the Left Pane, click Tools.
  • Verify that Uninstall is highlighted in color, or click on it.
  • In the lower right, click Save to Text File.
  • Pull down the arrow at the top of the Save dialog and choose Desktop as the location.
  • You can leave the filename as install.txt.
  • Click Save.
  • Exit Ccleaner by clicking on the X button in the upper right of the CCleaner window.

Step 4

In your next reply, please post:

  • the Combofix log (C:\Combofix.txt)
  • the CCleaner Uninstall List (install.txt)
  • a new HijackThis log
Hey Simon,

here's the Combofix log:

ComboFix 07-12-21.4 - Matt Youn 2007-12-22 22:17:35.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Matt Youn\Application Data\DOBE~1
C:\WINDOWS\system32\cletiufv.dll
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\gebyw.dll
C:\WINDOWS\system32\hiixroic.dll
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\vfuitelc.ini
C:\WINDOWS\system32\vtuustq.dll
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\system32\wybeg.ini
C:\WINDOWS\system32\wybeg.ini2

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_NPF
——-\DomainService
——-\NPF


((((((((((((((((((((((((( Files Created from 2007-11-23 to 2007-12-23 )))))))))))))))))))))))))))))))
.

2007-12-20 15:28 . 2007-12-22 03:51 992,202 –ahs—- C:\WINDOWS\system32\vuowrqkj.ini
2007-12-20 15:28 . 2007-12-20 15:28 85,568 –a—— C:\WINDOWS\system32\jkqrwouv.dll
2007-12-20 15:25 . 2007-12-20 15:25 80,448 –a—— C:\WINDOWS\system32\gbtbgcxr.dll
2007-12-20 01:09 . 2007-12-20 01:09 d——– C:\Documents and Settings\Matt Youn\Application Data\Grisoft
2007-12-20 01:09 . 2007-12-20 01:09 d——– C:\DOCUME~1\MATTYO~1\APPLIC~1\Grisoft
2007-12-20 01:07 . 2007-12-20 01:07 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
2007-12-20 01:07 . 2007-05-30 07:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-19 23:54 . 2007-12-19 23:55 143 –a—— C:\WINDOWS\system32\mcrh.tmp
2007-12-19 15:18 . 2007-12-20 13:11 993,229 –ahs—- C:\WINDOWS\system32\wsqfbjuv.ini
2007-12-19 15:18 . 2007-12-19 15:18 80,448 –a—— C:\WINDOWS\system32\kbxcxtws.dll
2007-12-19 03:39 . 2007-12-19 03:39 d——– C:\Documents and Settings\Matt Youn\Application Data\Uniblue
2007-12-19 03:39 . 2007-12-19 03:39 d——– C:\DOCUME~1\MATTYO~1\APPLIC~1\Uniblue
2007-12-19 03:38 . 2007-12-19 03:38 d——– C:\Program Files\Uniblue
2007-12-18 17:36 . 2007-12-19 15:16 992,989 –ahs—- C:\WINDOWS\system32\uqmwxjyl.ini
2007-12-18 17:33 . 2007-12-18 17:33 80,448 –a—— C:\WINDOWS\system32\txvnhugx.dll
2007-12-07 04:18 . 2007-12-07 04:19 d——– C:\Program Files\LimeWire

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-20 22:42 ——— d—–w C:\Program Files\Mozilla Thunderbird
2007-12-07 09:05 ——— d—–w C:\Documents and Settings\Matt Youn\Application Data\U3
2007-12-07 09:05 ——— d—–w C:\DOCUME~1\MATTYO~1\APPLIC~1\U3
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-07 06:11 ——— d—–w C:\Documents and Settings\Matt Youn\Application Data\Ruckus Network
2007-11-07 06:11 ——— d—–w C:\DOCUME~1\MATTYO~1\APPLIC~1\Ruckus Network
2007-11-01 01:56 ——— d—–w C:\Program Files\QuickTime
2007-11-01 01:37 ——— d—–w C:\Program Files\Apple Software Update
2007-09-11 06:36 51,176 —-a-w C:\Documents and Settings\Matt Youn\Application Data\GDIPFONTCACHEV1.DAT
2007-09-11 06:36 51,176 —-a-w C:\DOCUME~1\MATTYO~1\APPLIC~1\GDIPFONTCACHEV1.DAT
2005-10-03 02:24 56 -csh–r C:\WINDOWS\system32\B27E7128B5.sys
2005-10-03 02:24 1,682 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE"="C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" [2006-08-18 14:06]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 16:33]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 14:59]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 21:00]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 16:19]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 01:05]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\Quickset.exe" [2005-03-04 11:26]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 09:14]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 16:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Clean Access Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Clean Access Agent.lnk
backup=C:\WINDOWS\pss\Clean Access Agent.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
rundll32.exe C:\PROGRA~1\AIM\\DeadAIM.ocm,ExportedCheckODLs

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
C:\Program Files\DellSupport\DSAgnt.exe /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe -start

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pccguide.exe]
2006-08-25 12:25 3112960 –a—— C:\PROGRA~1\TRENDM~1\INTERN~2\pccguide.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2004-04-11 20:15 290816 ——— C:\Program Files\Dell\Media Experience\PCMService.exe


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09f4a588-5bf1-11da-b240-00123fe24bdd}]
\Shell\AutoRun\command - E:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2e53b156-7d8f-11db-b427-00123fe24bdd}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-22 22:36:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-22 22:40:14 - machine was rebooted
.
2007-12-12 09:13:58 — E O F —




Then the CCleaner log:
Ad-Aware SE Personal
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Help Center 1.0
Adobe InDesign CS
Adobe Photoshop CS2
Adobe Reader 7.0.8
Adobe Stock Photos 1.0
ALPS Touch Pad Driver
AOL Instant Messenger
Apple Mobile Device Support
Apple Software Update
aspi
ATI Control Panel
ATI Display Driver
AudibleManager
AVG Anti-Spyware 7.5
BitLord 1.1
Bonjour Core for Windows
Broadcom Management Programs 2
BSPlayer
CCHelp
CCleaner (remove only)
CCScore
CDex extraction audio
Cisco Clean Access Agent
Conexant D110 MDC V.9x Modem
Creative MediaSource 5
Creative Removable Disk Manager
Creative System Information
Creative ZEN V Series (R2)
DeadAIM
Dell Driver Reset Tool
Dell Media Experience
Dell Picture Studio v3.0
Dell System Restore
DellSupport
Digital Line Detect
DivX Web Player
ESSAdpt
ESSANUP
ESSCAM
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSvpaht
ESSvpot
Google Video Player
GTK+ Runtime 2.6.9 rev a (remove only)
HijackThis 1.99.1
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows XP (KB914440)
Intel® PROSet/Wireless Software
Internal Network Card Power Management
Internet Explorer Default Page
iPod for Windows 2005-09-23
iPod for Windows 2006-01-10
iPod Updater 2004-11-15
iTunes
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 3
J2SE Runtime Environment 5.0 Update 6
Jasc Paint Shop Photo Album 5
Jasc Paint Shop Pro Studio, Dell Editon
Java 2 Runtime Environment, SE v1.4.2_03
Java™ 6 Update 2
Java™ SE Runtime Environment 6 Update 1
jetAudio Basic
Kodak EasyShare software
KSU
Learn2 Player (Uninstall Only)
LimeWire 4.14.10
Macromedia Flash Player
Macromedia Shockwave Player
Magic ISO Maker v5.4 (build 0245)
mCore
mDrWiFi
mHlpDell
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Office XP Professional with FrontPage
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
mIWA
mIWCA
mLogView
mMHouse
Modem Helper
Mozilla Firefox (2.0.0.11)
Mozilla Thunderbird (2.0.0.9)
mPfMgr
mPfWiz
mProSafe
mSSO
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
mToolkit
mWlsSafe
mXML
My Way Search Assistant
myTunes Redux 1.0
mZConfig
NetWaiting
Notifier
On2 VP7 Personal Edition
OTtBP
PDFCreator
PowerDVD 5.5
Qualxserve Service Agreement
QuickSet
QuickTime
RealPlayer
Ruckus Player
SecureW2 TTLS Client 3.3.1 for Windows
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB944653)
SFR
SFR2
Sonic DLA
Sonic MyDVD LE
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Spybot - Search & Destroy 1.4
TMASOEDL
TMASOLDL
Trend Micro PC-cillin Internet Security 2007
Uniblue RegistryBooster 2
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
VobSub v2.23 (Remove Only)
WebCyberCoach 3.2 Dell
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 10 Hotfix - KB895316
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885855
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB888310
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892627
Windows XP Hotfix - KB893056
Windows XP Hotfix - KB893086
WinPcap 3.0
WinRAR archiver
WinZip
WordPerfect Office 12
XviD MPEG-4 Video Codec
ZENcast Organizer


Then the hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 11:00:05 PM, on 12/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PccGuide.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Matt Youn\My Documents\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe



Hope that helps. Thanks for helping me out!
Hi :)

I understand that downloading music and other files may be important to you; however, the Peer-to-Peer programs that you are using to do that, even if they are not infected with malware, will bring malware into your system. Therefore, the chances of you becoming infected again are very high. This obviously can result in disabling your computer and could even lead to someone stealing sensitive personal data from your computer. Beyond the inconvenience this causes you, these programs also tend to use your computer as a server to spread more infection all over the internet, so your computer becomes a part of the malware problem.

Remember that no matter how clean the program you're using for Peer-to-Peer filesharing may be, it offers no guarantees regarding the cleanliness of files you may choose to download. All files available via Peer-to-Peer filesharing carry a high risk, particularly those that offer you illegitimate methods of using legitimate software programs without paying for them. Any program or file that offers you the ability to access non-freeware programs at no cost, e.g., pirated software and/or cracks/key generators for gaining access to legitimate software, is 100% guaranteed to contain malware.

Here is some information that looks at the rates of infection:

http://www.benedelman.org/spyware/p2p/

With that being said, I recommend that you remove the following Peer-to-Peer program(s):

LimeWire 4.14.10

Step 1

Open Notepad (Go to Start > Run, type Notepad and hit Enter), and copy/paste the text in the quotebox below into it:

File::

C:\WINDOWS\system32\vuowrqkj.ini
C:\WINDOWS\system32\jkqrwouv.dll
C:\WINDOWS\system32\gbtbgcxr.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\wsqfbjuv.ini
C:\WINDOWS\system32\kbxcxtws.dll
C:\WINDOWS\system32\uqmwxjyl.ini
C:\WINDOWS\system32\txvnhugx.dll

Click on File > Save as….

In the File Name box, copy/paste CFScript.txt (Note: Do not change the filename!)

Click Save (Save the CFScript in the same location as Combofix.exe)

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe.
It will create a log. Be sure to save it to a convenient location.

Step 2

Click on Start, then Control Panel. Double click on Add or Remove Programs.

Please remove the following program(s):

  • J2SE Runtime Environment 5.0 Update 10
  • J2SE Runtime Environment 5.0 Update 11
  • J2SE Runtime Environment 5.0 Update 3
  • J2SE Runtime Environment 5.0 Update 6
  • Java 2 Runtime Environment, SE v1.4.2_03
  • Java™ 6 Update 2
  • Java™ SE Runtime Environment 6 Update 1
  • My Way Search Assistant

Then download and install Java Runtime Environment (JRE) 6 Update 3.

Step 3

Please do an online scan with Kaspersky WebScanner.

Click on Kaspersky Online Scanner. On the welcome screen, click Accept.

You will be promted to install an ActiveX component from Kaspersky, click Install.

  • The program will launch and then begin downloading the latest definition files.
  • Once the files have been downloaded click on Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:

  • Scan using the following Anti-Virus database:

    Extended (if available, otherwise Standard)

  • Scan Options:

    Scan Archives
    Scan Mail Bases

  • Click OK.
  • Now under Select a Target to Scan:

    Select My Computer.

  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button and save the file to your desktop.

Step 4

In your next reply, please post:

  • the Combofix log (C:\Combofix.txt)
  • the Kaspersky Online Scan report
  • a new HijackThis log
Thanks for the info. I removed Limewire. Also, here are my logs as requested:

ComboFix 07-12-21.4 - Matt Youn 2007-12-24 0:51:15.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.157 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Matt Youn\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\gbtbgcxr.dll
C:\WINDOWS\system32\jkqrwouv.dll
C:\WINDOWS\system32\kbxcxtws.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\txvnhugx.dll
C:\WINDOWS\system32\uqmwxjyl.ini
C:\WINDOWS\system32\vuowrqkj.ini
C:\WINDOWS\system32\wsqfbjuv.ini
.

((((((((((((((((((((((((( Files Created from 2007-11-24 to 2007-12-24 )))))))))))))))))))))))))))))))
.

2007-12-22 22:43 . 2007-12-22 22:43 d——– C:\Program Files\CCleaner
2007-12-20 01:09 . 2007-12-20 01:09 d——– C:\Documents and Settings\Matt Youn\Application Data\Grisoft
2007-12-20 01:07 . 2007-12-20 01:07 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-20 01:07 . 2007-05-30 07:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-19 03:39 . 2007-12-19 03:39 d——– C:\Documents and Settings\Matt Youn\Application Data\Uniblue
2007-12-19 03:38 . 2007-12-19 03:38 d——– C:\Program Files\Uniblue
2007-12-07 04:18 . 2007-12-07 04:19 d——– C:\Program Files\LimeWire

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-20 22:42 ——— d—–w C:\Program Files\Mozilla Thunderbird
2007-12-07 09:05 ——— d—–w C:\Documents and Settings\Matt Youn\Application Data\U3
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-07 06:11 ——— d—–w C:\Documents and Settings\Matt Youn\Application Data\Ruckus Network
2007-11-01 01:56 ——— d—–w C:\Program Files\QuickTime
2007-11-01 01:37 ——— d—–w C:\Program Files\Apple Software Update
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 23:40 227,328 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 23:40 227,328 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 —-a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ——w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-09-11 06:36 51,176 —-a-w C:\Documents and Settings\Matt Youn\Application Data\GDIPFONTCACHEV1.DAT
2005-10-03 02:24 56 -csh–r C:\WINDOWS\system32\B27E7128B5.sys
2005-10-03 02:24 1,682 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE"="C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" [2006-08-18 14:06]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 16:33]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 14:59]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 21:00]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 16:19]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 01:05]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\Quickset.exe" [2005-03-04 11:26]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 09:14]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 16:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Clean Access Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Clean Access Agent.lnk
backup=C:\WINDOWS\pss\Clean Access Agent.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
rundll32.exe C:\PROGRA~1\AIM\\DeadAIM.ocm,ExportedCheckODLs

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
C:\Program Files\DellSupport\DSAgnt.exe /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe -start

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pccguide.exe]
2006-08-25 12:25 3112960 –a—— C:\PROGRA~1\TRENDM~1\INTERN~2\pccguide.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2004-04-11 20:15 290816 ——— C:\Program Files\Dell\Media Experience\PCMService.exe


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09f4a588-5bf1-11da-b240-00123fe24bdd}]
\Shell\AutoRun\command - E:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2e53b156-7d8f-11db-b427-00123fe24bdd}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2007-12-21 04:15:32 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-24 00:55:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-24 0:55:43
C:\ComboFix2.txt … 2007-12-24 00:48
C:\ComboFix3.txt … 2007-12-22 22:40
.
2007-12-12 09:13:58 — E O F —





——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Monday, December 24, 2007 3:37:25 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 24/12/2007
Kaspersky Anti-Virus database records: 492724
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 69122
Number of viruses found: 3
Number of infected objects: 5
Number of suspicious objects: 0
Duration of the scan process: 01:20:19

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\cert8.db Object is locked skipped
C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\history.dat Object is locked skipped
C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\key3.db Object is locked skipped
C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\parent.lock Object is locked skipped
C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Matt Youn\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\webappsstore.sqlite Object is locked skipped
C:\Documents and Settings\Matt Youn\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Matt Youn\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Matt Youn\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Matt Youn\Local Settings\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Matt Youn\Local Settings\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Matt Youn\Local Settings\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Matt Youn\Local Settings\Application Data\Mozilla\Firefox\Profiles\f72v090a.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Matt Youn\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Matt Youn\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Matt Youn\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Matt Youn\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Matt Youn\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\D.tmp Infected: Backdoor.Win32.Agent.dbm skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\gbtbgcxr.dll.vir Object is locked skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\jkqrwouv.dll.vir Object is locked skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\kbxcxtws.dll.vir Object is locked skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\txvnhugx.dll.vir Object is locked skipped
C:\qoobox\Quarantine\catchme2007-12-22_223630.65.zip/vtuustq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bxg skipped
C:\qoobox\Quarantine\catchme2007-12-22_223630.65.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP714\A0201923.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP717\A0202138.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0203197.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP720\A0203336.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bxg skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP721\A0203441.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP721\A0203442.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP721\A0203443.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP721\A0203444.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP730\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{AFB89925-E491-4132-99DF-84F40D35C086}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd1165.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TEMP\Perflib_Perfdata_314.dat Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.



Logfile of HijackThis v1.99.1
Scan saved at 3:42:32 AM, on 12/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PccGuide.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Matt Youn\My Documents\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
Hi :)

Delete everything inside of this folder: C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\

Empty your Recycle Bin.

Click Start then Run….

  • Type Combofix /u in the runbox and click OK. (Note: The space between the x and the /u needs to be there)

    [external image: Posted Image]

  • When shown the disclaimer, select 2.

In your next reply, please let me know how your computer is currently running.
I did the following. I'm confused though, was the Run command just supposed to Uninstall ComboFix, because that's what happened, and I wasn't prompted with anything such as a 2 or whatever. The computer does seem to be working as it should be though, I believe.

I did the following. I'm confused though, was the Run command just supposed to Uninstall ComboFix, because that's what happened, and I wasn't prompted with anything such as a 2 or whatever. The computer does seem to be working as it should be though, I believe.

Yes, that's what was supposed to happen :)

Congratulations, your logs look clean. Please advise of any problems you are still experiencing, or follow these simple steps to keep your computer clean in the future:

Disable and Enable System Restore - If you are using Windows ME or XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

Step 1: Turn off System Restore:

  • On the desktop, right-click My Computer
  • Click Properties
  • Click the System Restore tab
  • Check Turn off System Restore
  • Click Apply, and then click OK

Step 2: Reboot your computer.

Step 3: Turn on System Restore:

  • On the desktop, right-click My Computer
  • Click Properties
  • Click the System Restore tab
  • Uncheck Turn off System Restore
  • Click Apply, and then click OK

Note: Only do this once, NOT on a regular basis!

Make your Internet Explorer More Secure

  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

  • Change the Download signed ActiveX controls to Prompt.
  • Change the Download unsigned ActiveX controls to Disable.
  • Change the Initialise and script ActiveX controls not marked as safe to Disable.
  • Change the Installation of desktop items to Prompt.
  • Change the Launching programs and files in an IFRAME to Prompt.
  • Change the Navigate sub-frames across different domains to Prompt.
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.

  • Next press the Apply button and then the OK to exit the Internet Properties page.

Visit Microsoft's Update Site Frequently - It is important that you visit http://update.microsoft.com/ regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. An article on anti-malware products with links for this program and others can be found here:
Computer Safety on line - Anti-Malware

Update all your security programs regularly - Make sure you update all your security programs regularly (about once a week). Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Stand Up and Be Counted! - Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints: Malware Complaints. You have to be registered to post. After registering just find your country room and register your complaint. The infection you had was Vundo.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI