This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] pls help with hijack this logfile

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 6:32:54 PM, on 12/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\COMMON~1\AOL\118188~1\EE\AOLHOS~1.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\mrofinu72.exe
C:\PROGRA~1\COMMON~1\AOL\118188~1\EE\AOLServiceHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe
C:\Program Files\Router\Router.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch…DTP&M=T6542
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1181880268\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [c6186] C:\Program Files\Vzabrchultnpa\xjnopfq.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu72.exe 61A847B5BBF72815308B2B27128065E9C084320161C4661227A755E9C2933154389A28452DA545E9
B1894E754BE54C29159A7DBE80DC744B6CDE3F546CAC59B6
O4 - HKLM\..\Run: [403cff8c] rundll32.exe "C:\WINDOWS\system32\ptvjyion.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [ProStoresStoreMonitor] C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe
O4 - HKCU\..\Run: [c6186] C:\Program Files\Vzabrchultnpa\xjnopfq.exe
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKCU\..\Run: [Router] C:\Program Files\Router\Router.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: svchost.exe
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/share…GamesLoader.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F73BE1F4-82AA-4405-AB81-FAFB5A122359} (SiteBuilderEditor Class) - http://store01.prostores.com/storeadmin/ut…es/pssbedit.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcccoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Rename HijackThis
There is a possibility an infection which is hiding part of the HijackThis log because it's called hijackthis.exe.
Using Windows Explore by right-clicking the Start button and left clicking Explore navigate to: C:\Program Files\HijackThis\HijackThis.exe

Right-click on HijackThis.exe & select Rename to iseeu.exe and post back a new Hijackthis log.



Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.


Upload a File to Jotti
Please visit http://virusscan.jotti.org/
Click on Browse… and navigate to the following file: C:\Program Files\Router\Router.exe
Click Open and submit the file.
Please let me know the results.
Logfile of HijackThis v1.99.1
Scan saved at 11:12:47 PM, on 12/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\COMMON~1\AOL\118188~1\EE\AOLHOS~1.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\mrofinu72.exe
C:\PROGRA~1\COMMON~1\AOL\118188~1\EE\AOLServiceHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe
C:\Program Files\Router\Router.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\iseeu.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch…DTP&M=T6542
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {A9A26194-3328-4A0A-90F7-65B11E3CED1A} - C:\WINDOWS\system32\vturp.dll
O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\system32\byxxvuu.dll
O2 - BHO: {17097898-e408-83b8-5724-afa86788b60c} - {c06b8876-8afa-4275-8b38-804e89879071} - C:\WINDOWS\system32\bwcayira.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1181880268\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [c6186] C:\Program Files\Vzabrchultnpa\xjnopfq.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu72.exe 61A847B5BBF72815308B2B27128065E9C084320161C4661227A755E9C2933154389A28452DA545E9
B1894E754BE54C29159A7DBE80DC744B6CDE3F546CAC59B6
O4 - HKLM\..\Run: [403cff8c] rundll32.exe "C:\WINDOWS\system32\ptvjyion.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [ProStoresStoreMonitor] C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe
O4 - HKCU\..\Run: [c6186] C:\Program Files\Vzabrchultnpa\xjnopfq.exe
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKCU\..\Run: [Router] C:\Program Files\Router\Router.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: svchost.exe
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/share…GamesLoader.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F73BE1F4-82AA-4405-AB81-FAFB5A122359} (SiteBuilderEditor Class) - http://store01.prostores.com/storeadmin/ut…es/pssbedit.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: byxxvuu - C:\WINDOWS\SYSTEM32\byxxvuu.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcccoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS


this is the config uninstall list

ABBYY FineReader 6.0 Sprint
Ad-Aware 2007
Adobe Flash Player 9 ActiveX
Adobe Reader 7.0
Agere Systems PCI-SV92PP Soft Modem
All In One
ALOT Toolbar
America Online (Choose which version to remove)
AOL Coach Version 2.0(Build:20041026.5 en)
AOL Connectivity Services
AOL Spyware Protection
AOL You've Got Pictures Screensaver
Bejeweled 2 Deluxe
Bejeweled 2 Deluxe
Belkin 54g USB Network Adapter
Big Fish Games Client
BigFix
Blackhawk Striker 2
Blasterball 2 Revolution
BoontyBox 2.1
CEP - Color Enable Package
Digital Media Reader
Dino Crisis 2
Download Manager 2.3.6
DRIV3R DEMO
DVD Solution
Family Feud (remove only)
FATE
FrostWire 4.13.3
Gateway Game Console
Google Desktop
High Definition Audio Driver Package - KB888111
High Quality Photo Resizer 4.0
Hijackthis 1.99.1
HijackThis 1.99.1
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB888795)
Hotfix for Windows XP (KB891593)
Hotfix for Windows XP (KB895961)
Hotfix for Windows XP (KB896256)
Hotfix for Windows XP (KB899337)
Hotfix for Windows XP (KB899510)
Hotfix for Windows XP (KB902841)
Hotfix for Windows XP (KB906569)
Hotfix for Windows XP (KB909095)
Hotfix for Windows XP (KB910728)
Hotfix for Windows XP (KB912024)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB914906)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB935448)
J2SE Runtime Environment 5.0 Update 2
Java™ 6 Update 2
Java™ 6 Update 3
Lexmark 3300 Series
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.0 Hotfix (KB930494)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Away Mode
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Digital Image Starter Edition 2006
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2006
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft Office XP Professional with FrontPage
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Works
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
Napster
Napster Burn Engine
Nero 7 Ultra Edition
neroxml
NVIDIA Drivers
PC Tutor Learn Office Windows & More Deluxe
Penguins!
Photo Merge and Rename
Polar Bowler
Polar Golfer
Power2Go 4.0
PowerDVD
ProStores Store Monitor (remove only)
Pure Networks Port Magic
QuickTime
RealPlayer Basic
REALTEK GbE & FE Ethernet PCI NIC Driver
Realtek High Definition Audio Driver
Scrabble
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913433)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917537)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB944653)
Shadowgrounds Downloader en
Shanghai Street Racer en
Sonic Encoders
The Sims 2 Open For Business
The Sims 2 University
The Sims™ 2 Deluxe
Tradewinds
Trivia Pursuit Bring on the 90 s Edition en
Trivial Pursuit Bring On The 90's Edition
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB912945)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update Rollup 2 for Windows XP Media Center Edition 2005
UseNeXT
Viewpoint Media Player
Wedding Dash (remove only)
WG111v2 Configuration Utility
WildTangent Web Driver
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Media Center Edition 2005 KB925766
Yahoo! Anti-Spy
Yahoo! Toolbar


This is the jotti virusscan

Service load: 0% 100%

File: Router.exe
Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5: 8370b8b13edf9afbed150a1658707385
Packers detected: -
Bit9 reports: File not found

Scanner results
Scan taken on 20 Dec 2007 04:17:29 (GMT)
A-Squared Found nothing
AntiVir Found TR/Dldr.Textrec
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found Downloader.Agent.WPG
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found Trojan-Downloader.Win32.Agent.gdi
Fortinet Found nothing
Ikarus Found Trojan-Downloader.Win32.Agent.gdi
Kaspersky Anti-Virus Found Trojan-Downloader.Win32.Agent.gdi
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found Mal/Generic-A
VirusBuster Found nothing
VBA32 Found nothing
Zoner Antivirus Found nothing
Hello

Go to Start>Control Panel>Add/Remove Programs and remove these two.
J2SE Runtime Environment 5.0 Update 2
Java™ 6 Update 2


Leave Java Update 3 though. That is the latest version.

I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto‑updating for the Viewpoint Manager ‑‑ the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.

Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware.
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight Viewpoint Media Player, click Remove.


I see you are using Wild Tangent. It is not malware, but is sometimes thought to bring malware along. Wild Tangent is a video game software company specializing in online games. It has even made a partnership with AOL to include itself as part of the AOL Instant Messenger for their AIM games section. The WildTangent Web Driver is their technology that allows you to play 3D games over the Internet. Although it’s not technically considered spyware, it does have built in components to update itself and gather information about the computer system including
  • Operating System Version
  • CPU Type and Speed
  • Memory Amount
    Video Card type and Driver Version
  • Sound Card type and Driver Version
  • DirectX Version
    Location that the Web Driver was installed from
  • It is also a MAJOR resource hog.
For more information, see WildTangent Removal Instructions and Help and Inside Wild Tangent-Delivering High-End 3-D Content To A Web Site Near You.
Unless you are an extremely avid games player, I recommend you uninstall Wild Tangent: To uninstall Wild Tangent:
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight Wild Tangent, click Remove.
  • Close the Add or Remove Programs and the Control Panel windows.


Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.


If you already have Combofix, please delete this copy and download it again as it's being updated regularly.

Please Download and Save Combofix from Bleeping Computer. Save it to your desktop.

If you can't download it, please try these 2 alternative sites:

Forospyware
Geeks to Go
  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Click Start>Run copy/paste or type "%userprofile%\desktop\combofix.exe" /killall into the Run box and click OK.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
vundofix.txt
ComboFix.txt
New HijackThis log taken after the above scan has run
Logfile of HijackThis v1.99.1
Scan saved at 5:12:15 PM, on 12/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\WINDOWS\system32\qwxcqryg.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\mrofinu72.exe
C:\PROGRA~1\COMMON~1\AOL\118188~1\EE\AOLHOS~1.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\COMMON~1\AOL\118188~1\EE\AOLServiceHost.exe
C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Words\Words.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch…DTP&M=T6542
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {42146199-BE92-417A-A5BC-F358D739C175} - C:\WINDOWS\system32\vturp.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\wlyuyarj.dll
O2 - BHO: {f51296d9-4cd9-3c0a-58a4-bc6852d3233c} - {c3323d25-86cb-4a85-a0c3-9dc49d69215f} - C:\WINDOWS\system32\jsoblgby.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1181880268\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [c6186] C:\Program Files\Vzabrchultnpa\xjnopfq.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu72.exe 61A847B5BBF72815308B2B27128065E9C084320161C4661227A755E9C2933154389A284662EA4EBF
968951185EFC412806867680AEDE604D64C2661375FB0FB68AD6
O4 - HKLM\..\Run: [403cff8c] rundll32.exe "C:\WINDOWS\system32\ditdlall.dll",b
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [ProStoresStoreMonitor] C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe
O4 - HKCU\..\Run: [c6186] C:\Program Files\Vzabrchultnpa\xjnopfq.exe
O4 - HKCU\..\Run: [Words] C:\Program Files\Words\Words.exe
O4 - HKCU\..\Run: [irii] C:\PROGRA~1\COMMON~1\irii\iriim.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: svchost.exe
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/share…GamesLoader.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://www.king.com/ctl/kingcomie.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {F73BE1F4-82AA-4405-AB81-FAFB5A122359} (SiteBuilderEditor Class) - http://store01.prostores.com/storeadmin/ut…es/pssbedit.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: wlyuyarj - C:\WINDOWS\SYSTEM32\wlyuyarj.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\qwxcqryg.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcccoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
No, this is the same computer. the combofix did not work a little box came up saying wrong or incorrect handle something and so i did a system restore and it's still messed up.
Hi

I merged both topics.

First of all, System restore wouldnt have worked, as malware nearly always infects the restore points to make sure you stay infected. When Combofix failed, what you should have done was make a note of the message and tell me.

So let's start over.

Let's make sure Combofix has gone, then after you have run SDFix, we will try the Beta version of Combofix. If you have any problems, please tell me.
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the x and the /u, it needs to be there.

    [external image: Posted Image]
  • When shown the disclaimer, Select "2"



Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back in your next reply.



Download and Save ComboFix
  • Download this file from below:

    Here
  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Click Start>Run copy/paste or type "%userprofile%\desktop\combofix.exe" /killall into the Run box and click OK.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
Report.txt
ComboFix.txt
New HijackThis log taken after the above scan has run
SDFix: Version 1.119

Run by [removed] on Sat 12/22/2007 at 11:27 AM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\DOCUME~1\OWNER~2.YOU\Desktop\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\PROGRA~1\COMMON~1\RTEJEG~1.HTM - Deleted
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Shared\_\WinAntiVirus Pro 2006 2.1.245.1.exe - Deleted
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Shared\_\WinAntiVirus Pro 2007 ver. 3.0.257.3.exe - Deleted
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Shared\_\Winantivirus Pro 2007 Ver. 5.0.277.4.exe - Deleted
C:\Program Files\RichVideoCodec\imex.bat - Deleted
C:\Program Files\RichVideoCodec\install.ico - Deleted
C:\Program Files\RichVideoCodec\RichVideoCodec.ocx - Deleted
C:\Program Files\RichVideoCodec\ttvbonpwl.exe - Deleted
C:\Program Files\RichVideoCodec\Uninstall.exe - Deleted
C:\Program Files\Temporary\wininstall.exe - Deleted
C:\Program Files\WinAble\winable.exe - Deleted
C:\Program Files\Words\list.txt - Deleted
C:\Program Files\Words\UnInstall.exe - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe - Deleted
C:\WINDOWS\b103.exe - Deleted
C:\WINDOWS\b122.exe - Deleted
C:\WINDOWS\b128.exe - Deleted
C:\WINDOWS\b143.exe - Deleted
C:\WINDOWS\mrofinu72.exe - Deleted



Folder C:\Program Files\InetGet2 - Removed
Folder C:\Program Files\Network Monitor - Removed
Folder C:\Program Files\RichVideoCodec - Removed
Folder C:\Program Files\Temporary - Removed
Folder C:\Program Files\WinAble - Removed
Folder C:\Program Files\Words - Removed

Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-22 15:49:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Application Loader"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe:*:Enabled:AOLTsMon"
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe:*:Enabled:AOLTopSpeed"
"C:\\Program Files\\Common Files\\AOL\\1181880268\\EE\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1181880268\\EE\\AOLServiceHost.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"="C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"="C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe:*:Enabled:AOL"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\PopCap Games\\BookWorm Deluxe\\BookWorm.exe"="C:\\Program Files\\PopCap Games\\BookWorm Deluxe\\BookWorm.exe:*:Enabled:BookWorm"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Yahoo! Games\\Scrabble\\Scrabble.exe"="C:\\Program Files\\Yahoo! Games\\Scrabble\\Scrabble.exe:*:Enabled:SCRABBLE r"
"C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"="C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe:*:Enabled:Nero ProductSetup"
"C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"="C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe:*:Enabled:Nero ShowTime Essentials"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Disabled:Internet Explorer"
"C:\\Documents and Settings\\Owner.YOUR-9EFB86816C\\Local Settings\\Temp\\Nero Web\\SetupXu.exe"="C:\\Documents and Settings\\Owner.YOUR-9EFB86816C\\Local Settings\\Temp\\Nero Web\\SetupXu.exe:*:Enabled:Nero ProductSetup"
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"="C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe:*:Enabled:Nero Home"
"C:\\Program Files\\Pilot Group Ltd\\Newsletter 2007\\apache\\Apache.exe"="C:\\Program Files\\Pilot Group Ltd\\Newsletter 2007\\apache\\Apache.exe:*:Enabled:Apache"
"C:\\WINDOWS\\system32\\qwxcqryg.exe"="C:\\WINDOWS\\system32\\qwx"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files:
—————

File Backups: - C:\DOCUME~1\OWNER~2.YOU\Desktop\SDFix\backups\backups.zip

Files with Hidden Attributes:

Thu 23 Jun 2005 54,872 A..H. — "C:\Program Files\America Online 9.0\AOLphx.exe"
Thu 23 Jun 2005 31,832 A..H. — "C:\Program Files\America Online 9.0\rbm.exe"
Fri 4 May 2007 1,347,584 …H. — "C:\Program Files\Family Feud\Family Feud.exe"
Tue 4 Sep 2007 2,389,320 …H. — "C:\Program Files\Wedding Dash\Wedding Dash.exe"
Sat 22 Dec 2007 19,070 ..SH. — "C:\WINDOWS\system32\wlyuyarj.dllbox"
Sun 22 Jul 2007 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 4 Jul 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Thu 13 Sep 2007 35,840 …H. — "C:\Documents and Settings\Owner.YOUR-9EFB86816C\My Documents\Documents\~WRL0002.tmp"
Thu 1 Nov 2007 230,400 ..SHR — "C:\Documents and Settings\Owner.YOUR-9EFB86816C\My Documents\??stem\r?ndll32.exe"
Fri 19 Oct 2007 444 …HR — "C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\SecuROM\UserData\securom_v7_01.bak"
Mon 12 Feb 2007 3,096,576 A..H. — "C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\U3\temp\Launchpad Removal.exe"

Finished!


combofix Log file

ComboFix 07-12-23.1 - Owner 2007-12-22 16:34:46.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.194 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\Owner.YOUR-9EFB86816C\My Documents\ICROSO~1.NET
C:\Documents and Settings\Owner.YOUR-9EFB86816C\My Documents\SKS~1
C:\Documents and Settings\Owner.YOUR-9EFB86816C\My Documents\STEM~1
C:\Documents and Settings\Owner.YOUR-9EFB86816C\My Documents\STEM~1\r?ndll32.exe
C:\Program Files\akl
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\unsetup.dat
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\winam.dat
C:\Program Files\QdrDrive
C:\WINDOWS\aconti.log
C:\WINDOWS\acontidialer.txt
C:\WINDOWS\b.exe
C:\WINDOWS\b151.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\default.htm
C:\WINDOWS\system32\byxxvuu.dll
C:\WINDOWS\system32\crosof~1
C:\WINDOWS\system32\ditdlall.dll
C:\WINDOWS\system32\dpqaqlqx.bin
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\kfpopngn.ini
C:\WINDOWS\system32\lccwywiu.ini
C:\WINDOWS\system32\llaldtid.ini
C:\WINDOWS\system32\sznf.ascii
C:\WINDOWS\system32\tsuninst.exe
C:\WINDOWS\system32\wlyuyarj.dllbox
C:\WINDOWS\system32\wtsisvit32.exe
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-11-23 to 2007-12-23 )))))))))))))))))))))))))))))))
.

2007-12-22 16:20 . 2007-12-22 16:20 14,033 –a—— C:\pos251D.tmp
2007-12-22 16:19 . 2007-12-22 16:19 14,033 –a—— C:\pos237C.tmp
2007-12-22 15:48 . 2007-12-22 15:48 14,033 –a—— C:\pos2317.tmp
2007-12-22 15:47 . 2007-12-22 15:48 14,033 –a—— C:\pos2137.tmp
2007-12-22 15:47 . 2007-12-22 15:48 12,033 –a—— C:\pos2135.tmp
2007-12-22 15:47 . 2007-12-22 15:48 8,033 –a—— C:\pos2136.tmp
2007-12-22 15:47 . 2007-12-22 15:48 5,033 –a—— C:\pos2138.tmp
2007-12-22 09:24 . 2007-12-22 09:24 d——– C:\WINDOWS\ERUNT
2007-12-22 09:13 . 2007-12-22 09:13 14,033 –a—— C:\pos1BC2.tmp
2007-12-22 08:59 . 2007-12-22 08:59 14,033 –a—— C:\pos1B58.tmp
2007-12-22 08:58 . 2007-12-22 08:59 14,033 –a—— C:\pos1AA4.tmp
2007-12-22 08:45 . 2007-12-22 08:45 14,033 –a—— C:\pos1962.tmp
2007-12-22 08:44 . 2007-12-22 08:45 14,033 –a—— C:\pos1936.tmp
2007-12-22 08:43 . 2007-12-22 08:43 14,033 –a—— C:\pos1795.tmp
2007-12-22 08:40 . 2007-12-22 16:07 7,168 –a—— C:\WINDOWS\system32\windows
2007-12-21 20:07 . 2007-12-21 20:07 14,033 –a—— C:\pos1718.tmp
2007-12-21 07:34 . 2007-12-21 07:34 14,033 –a—— C:\pos1580.tmp
2007-12-21 07:33 . 2007-12-21 07:33 14,033 –a—— C:\pos13FA.tmp
2007-12-21 03:11 . 2007-12-21 03:11 14,033 –a—— C:\pos138D.tmp
2007-12-21 03:10 . 2007-12-21 03:11 14,033 –a—— C:\pos1304.tmp
2007-12-20 18:28 . 2007-12-20 18:28 14,033 –a—— C:\posFFA.tmp
2007-12-20 18:27 . 2007-12-20 18:28 14,033 –a—— C:\posFED.tmp
2007-12-20 17:35 . 2007-12-20 17:35 d——– C:\Program Files\Router
2007-12-20 17:10 . 2007-12-20 17:10 14,033 –a—— C:\posFA4.tmp
2007-12-20 17:09 . 2007-12-20 17:10 14,033 –a—— C:\posEE0.tmp
2007-12-20 16:55 . 2007-12-20 16:55 14,033 –a—— C:\posB88.tmp
2007-12-20 16:54 . 2007-12-20 16:55 14,033 –a—— C:\posAF1.tmp
2007-12-20 16:25 . 2007-12-20 16:25 14,033 –a—— C:\posE29.tmp
2007-12-20 16:24 . 2007-12-20 16:25 14,033 –a—— C:\posCAB.tmp
2007-12-20 15:51 . 2007-12-20 15:51 165,472 ——— C:\WINDOWS\system32\wlyuyarj.dll
2007-12-20 15:28 . 2007-12-20 15:28 d——– C:\Program Files\Viewpoint
2007-12-20 15:28 . 2007-12-20 15:28 d——– C:\Program Files\Adssite Advanced Toolbar
2007-12-20 15:28 . 2007-12-20 15:28 d——– C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-12-20 15:28 . 2007-12-20 15:28 d——– C:\Documents and Settings\All Users\Application Data\PopCap
2007-12-20 15:01 . 2007-12-20 15:01 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-20 15:01 . 2007-12-20 15:01 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-20 10:55 . 2007-12-20 16:25 d——– C:\VundoFix Backups
2007-12-20 10:45 . 2007-12-20 10:46 14,033 –a—— C:\pos60A.tmp
2007-12-20 10:18 . 2007-12-20 10:19 14,033 –a—— C:\pos524.tmp
2007-12-20 10:07 . 2007-12-20 10:07 14,033 –a—— C:\pos3D7.tmp
2007-12-20 10:06 . 2007-12-20 10:06 14,033 –a—— C:\pos6.tmp
2007-12-20 09:35 . 2007-12-20 09:35 14,033 –a—— C:\pos26D.tmp
2007-12-20 09:34 . 2007-12-20 09:34 14,033 –a—— C:\posFB.tmp
2007-12-19 23:04 . 2007-12-20 15:08 d——– C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot
2007-12-13 03:31 . 2007-12-20 15:31 d——– C:\Program Files\QdrPack(3)
2007-12-13 03:31 . 2007-12-20 15:31 d——– C:\Program Files\QdrModule(3)
2007-12-12 04:28 . 2007-12-20 15:34 d——– C:\Program Files\Outerinfo(2)
2007-12-06 17:36 . 2007-12-20 15:35 d——– C:\Program Files\QdrPack(2)
2007-12-06 17:36 . 2007-12-20 15:35 d——– C:\Program Files\QdrModule(2)
2007-12-05 01:21 . 2007-12-05 01:21 d——– C:\WINDOWS\lahtgfws
2007-11-28 14:58 . 2007-12-20 17:08 d——– C:\Program Files\Common Files\irii
2007-11-27 15:07 . 2007-12-20 16:24 143 –a—— C:\WINDOWS\system32\mcrh.tmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-23 21:43 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-20 22:06 ——— d—–w C:\Program Files\Java
2007-12-20 20:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-20 20:34 ——— d—–w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\AdobeUM
2007-12-20 00:01 ——— d—–w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\UseNeXT
2007-12-05 14:56 ——— d—–w C:\Program Files\Yahoo!
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-10 13:11 ——— d—–w C:\Program Files\BoontyGames
2007-11-10 13:08 ——— d—–w C:\Program Files\GameFiesta
2007-11-10 13:07 ——— d—–w C:\Program Files\Gateway Games
2007-11-10 12:39 ——— d—–w C:\Program Files\High Quality Photo Resizer
2007-11-10 03:44 41,712 —-a-w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\GDIPFONTCACHEV1.DAT
2007-11-07 21:28 ——— d—–w C:\Program Files\Photo Merge and Rename
2007-11-07 20:48 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-07 20:48 ——— d—–w C:\Program Files\PhotoBuilder
2007-11-07 20:20 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-07 20:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-10-28 23:16 ——— d—–w C:\Program Files\Pilot Group Ltd
2007-10-24 00:30 ——— d—–w C:\Program Files\Microsoft Money 2006
2007-10-23 18:31 ——— d—–w C:\Program Files\ProStores
2007-10-19 01:57 2,223 —-a-w C:\Program Files\iSpy Full.lnk
2007-10-15 19:53 720,896 -c–a-w C:\WINDOWS\iun6002ev.exe
2007-08-05 13:57 576 -c–a-w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{42146199-BE92-417A-A5BC-F358D739C175}]
C:\WINDOWS\system32\vturp.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-12-20 15:51 165472 ——— C:\WINDOWS\system32\wlyuyarj.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c3323d25-86cb-4a85-a0c3-9dc49d69215f}]
C:\WINDOWS\system32\jsoblgby.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 14:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24]
"Power2GoExpress"="NA" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 18:03]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 16:57]
"ProStoresStoreMonitor"="C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe" [2005-09-22 20:15]
"c6186"="C:\Program Files\Vzabrchultnpa\xjnopfq.exe" [2006-04-26 07:56]
"irii"="C:\PROGRA~1\COMMON~1\irii\iriim.exe" []
"Router"="C:\Program Files\Router\Router.exe" [2007-12-20 17:35]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 22:56]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-06-14 22:50]
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [2005-12-09 20:44]
"RTHDCPL"="RTHDCPL.EXE" [2005-11-09 07:14 C:\WINDOWS\RTHDCPL.exe]
"HostManager"="C:\Program Files\Common Files\AOL\1181880268\EE\AOLHostManager.exe" [2004-11-03 16:03]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-18 19:42]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-10 14:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2005-11-30 06:02 C:\WINDOWS\system32\nwiz.exe]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 18:19 C:\WINDOWS\arpwrmsg.exe]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 18:16]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-10 14:00 C:\WINDOWS\system32\rundll32.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-14 23:05]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 14:57]
"c6186"="C:\Program Files\Vzabrchultnpa\xjnopfq.exe" [2006-04-26 07:56]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2007-10-13 13:47:24]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]
WG111v2 Smart Wizard Wireless Setting.lnk - C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2007-08-22 17:25:59]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlyuyarj]
wlyuyarj.dll 2007-12-20 15:51 165472 C:\WINDOWS\system32\wlyuyarj.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

R2 Belkin Wireless USB Network Adapter Service;Belkin Wireless USB Network Adapter;C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe [2004-03-29 15:08]
R2 EAPPkt;Realtek EAPPkt Protocol;C:\WINDOWS\system32\DRIVERS\EAPPkt.sys [2005-04-01 10:43]
S3 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe" [2007-09-20 21:16]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2006-03-27 16:53]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c87c5be5-62f5-11dc-a80e-001150c173cc}]
\Shell\AutoRun\command - J:\PortableVault.exe

.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-23 16:42:19
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

C:\Program Files\Vzabrchultnpa\xjnopfq.exe [3800] 0x824D1BE0
C:\Program Files\Vzabrchultnpa\xjnopfq.exe [3892] 0x823287A8
scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\wlyuyarj.dll

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\wlyuyarj.dll
-> C:\WINDOWS\system32\msuuncerb.dll
.
Completion time: 2007-12-23 16:45:20 - machine was rebooted [Owner]
.
2007-12-21 08:02:47 — E O F —


hijackthis logfile

Logfile of HijackThis v1.99.1
Scan saved at 4:50:01 PM, on 12/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\PROGRA~1\COMMON~1\AOL\118188~1\EE\AOLHOS~1.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\PROGRA~1\COMMON~1\AOL\118188~1\EE\AOLServiceHost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe
C:\Program Files\Router\Router.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {42146199-BE92-417A-A5BC-F358D739C175} - C:\WINDOWS\system32\vturp.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\wlyuyarj.dll
O2 - BHO: {f51296d9-4cd9-3c0a-58a4-bc6852d3233c} - {c3323d25-86cb-4a85-a0c3-9dc49d69215f} - C:\WINDOWS\system32\jsoblgby.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1181880268\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [c6186] C:\Program Files\Vzabrchultnpa\xjnopfq.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [ProStoresStoreMonitor] C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe
O4 - HKCU\..\Run: [c6186] C:\Program Files\Vzabrchultnpa\xjnopfq.exe
O4 - HKCU\..\Run: [irii] C:\PROGRA~1\COMMON~1\irii\iriim.exe
O4 - HKCU\..\Run: [Router] C:\Program Files\Router\Router.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/share…GamesLoader.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://www.king.com/ctl/kingcomie.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {F73BE1F4-82AA-4405-AB81-FAFB5A122359} (SiteBuilderEditor Class) - http://store01.prostores.com/storeadmin/ut…es/pssbedit.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: wlyuyarj - C:\WINDOWS\SYSTEM32\wlyuyarj.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcccoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
Hi

Go to http://www.virustotal.com/en/indexf.html
Copy the following line into the white textbox:
C:\WINDOWS\system32\windows
Click Send.
Please post the results of this scan to this thread.

Do the same for the following.
C:\Program Files\Vzabrchultnpa\xjnopfq.exe



Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\pos251D.tmp
C:\pos237C.tmp
C:\pos2317.tmp
C:\pos2137.tmp
C:\pos2135.tmp
C:\pos2136.tmp
C:\pos2138.tmp 
C:\pos1BC2.tmp
C:\pos1B58.tmp
C:\pos1AA4.tmp
C:\pos1962.tmp
C:\pos1936.tmp
C:\pos1795.tmp
C:\pos1718.tmp
C:\pos1580.tmp
C:\pos13FA.tmp
C:\pos138D.tmp
C:\pos1304.tmp
C:\posFFA.tmp
C:\posFED.tmp
C:\posFA4.tmp
C:\posEE0.tmp
C:\posB88.tmp
C:\posAF1.tmp
C:\posE29.tmp
C:\posCAB.tmp
C:\WINDOWS\system32\wlyuyarj.dll
C:\pos60A.tmp
C:\pos524.tmp
C:\pos3D7.tmp
C:\pos6.tmp
C:\pos26D.tmp
C:\posFB.tmp
C:\WINDOWS\system32\mcrh.tmp
C:\Program Files\iSpy Full.lnk
C:\WINDOWS\iun6002ev.exe
C:\WINDOWS\system32\msuuncerb.dll

Folder::
C:\Program Files\Router
C:\Program Files\Viewpoint
C:\Program Files\Adssite Advanced Toolbar
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\VundoFix Backups
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot
C:\WINDOWS\lahtgfws
C:\Program Files\Common Files\irii

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{42146199-BE92-417A-A5BC-F358D739C175}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c3323d25-86cb-4a85-a0c3-9dc49d69215f}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"c6186"=-
"irii"=-
"Router"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"c6186"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlyuyarj]

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
Virustotal results
ComboFix.txt
New HJT log taken after the above scan has run
File has already been analysed:
MD5: c23f378e5fb6f61370c6d03ccce6d731
Date: 12.22.2007 14:45:37 (CET) [<1D]
Results: 1/32
Permalink: resultado.html?54b71cc4382133ccbeaa83d76f40974b


File windows_ received on 12.22.2007 14:45:37 (CET)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED


Result: 1/32 (3.13%)
Loading server information…
Your file is queued in position: ___.
Estimated start time is between ___ and ___ .
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:


Antivirus Version Last Update Result
AhnLab-V3 - - -
AntiVir - - -
Authentium - - -
Avast - - -
AVG - - -
BitDefender - - -
CAT-QuickHeal - - -
ClamAV - - -
DrWeb - - -
eSafe - - -
eTrust-Vet - - -
Ewido - - -
FileAdvisor - - -
Fortinet - - -
F-Prot - - -
F-Secure - - -
Ikarus - - -
Kaspersky - - -
McAfee - - -
Microsoft - - -
NOD32v2 - - -
Norman - - -
Panda - - -
Prevx1 - - Heuristic: Suspicious File With Outbound Communications
Rising - - -
Sophos - - -
Sunbelt - - -
Symantec - - -
TheHacker - - -
VBA32 - - -
VirusBuster - - -
Webwasher-Gateway - - -
Additional information
MD5: c23f378e5fb6f61370c6d03ccce6d731


ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.



File xjnopfq.exe received on 12.23.2007 01:28:47 (CET)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED


Result: 2/32 (6.25%)
Loading server information…
Your file is queued in position: ___.
Estimated start time is between ___ and ___ .
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:


Antivirus Version Last Update Result
AhnLab-V3 - - -
AntiVir - - -
Authentium - - -
Avast - - -
AVG - - -
BitDefender - - -
CAT-QuickHeal - - -
ClamAV - - -
DrWeb - - -
eSafe - - -
eTrust-Vet - - -
Ewido - - -
FileAdvisor - - -
Fortinet - - -
F-Prot - - -
F-Secure - - -
Ikarus - - -
Kaspersky - - -
McAfee - - -
Microsoft - - -
NOD32v2 - - -
Norman - - -
Panda - - -
Prevx1 - - Heuristic: Suspicious Self Modifying EXE
Rising - - -
Sophos - - -
Sunbelt - - -
Symantec - - -
TheHacker - - -
VBA32 - - -
VirusBuster - - -
Webwasher-Gateway - - Virus.Win32.FileInfector.gen (suspicious)
Additional information
MD5: f8ad1eed879f42a4629daf4655c67007


ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.



ComboFix 07-12-23.1 - Owner 2007-12-23 19:35:25.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.142 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner.YOUR-9EFB86816C\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\pos1304.tmp
C:\pos138D.tmp
C:\pos13FA.tmp
C:\pos1580.tmp
C:\pos1718.tmp
C:\pos1795.tmp
C:\pos1936.tmp
C:\pos1962.tmp
C:\pos1AA4.tmp
C:\pos1B58.tmp
C:\pos1BC2.tmp
C:\pos2135.tmp
C:\pos2136.tmp
C:\pos2137.tmp
C:\pos2138.tmp
C:\pos2317.tmp
C:\pos237C.tmp
C:\pos251D.tmp
C:\pos26D.tmp
C:\pos3D7.tmp
C:\pos524.tmp
C:\pos6.tmp
C:\pos60A.tmp
C:\posAF1.tmp
C:\posB88.tmp
C:\posCAB.tmp
C:\posE29.tmp
C:\posEE0.tmp
C:\posFA4.tmp
C:\posFB.tmp
C:\posFED.tmp
C:\posFFA.tmp
C:\Program Files\iSpy Full.lnk
C:\WINDOWS\iun6002ev.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\msuuncerb.dll
C:\WINDOWS\system32\wlyuyarj.dll
.
The following files were disabled during the run:
C:\WINDOWS\system32\msuuncerb.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\ComponentRegistry.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\HostRegistry.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\MetaStreamConfig.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00\URLCache.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\URLCache.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\URLCache.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\URLCache.ini
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_0\Button_0.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_0\Button_0.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_1\Button_1.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_1\Button_1.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_10\Button_10.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_10\Button_10.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_11\Button_11.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_11\Button_11.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_2\Button_2.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_2\Button_2.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_3\Button_3.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_3\Button_3.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_4\Button_4.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_4\Button_4.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_5\Button_5.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_5\Button_5.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_6\Button_6.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_6\Button_6.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_7\Button_7.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_7\Button_7.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_8\Button_8.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_8\Button_8.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_9\Button_9.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_9\Button_9.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\configurator\configurator.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\configurator\configurator.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\ErrorSearch\ErrorSearch.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\ErrorSearch\ErrorSearch.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\postInstallLayout\postInstallLayout.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\postInstallLayout\postInstallLayout.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\products\products.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\products\products.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Button_0\images\alot_icon_35x16.bmp
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Button_1\images\alot_search_24x16.bmp
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Button_2\images\default_285_alot_celeb_search.bmp
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Button_3\images\active_default_286_alot_celeb_news.bmp
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Button_3\images\default_286_alot_celeb_news.bmp
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Button_4\images\default_287_alot_celeb_center.bmp
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Button_5\images\default_288_alot_mrkt_bang.bmp
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Shared\images\alot_brand.png
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\TimerManager\TimerManager.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\TimerManager\TimerManager.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\toolbar.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\ToolbarSearch\ToolbarSearch.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Updater\Updater.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Updater\Updater.xml.backup
C:\pos1304.tmp
C:\pos138D.tmp
C:\pos13FA.tmp
C:\pos1580.tmp
C:\pos1718.tmp
C:\pos1795.tmp
C:\pos1936.tmp
C:\pos1962.tmp
C:\pos1AA4.tmp
C:\pos1B58.tmp
C:\pos1BC2.tmp
C:\pos2135.tmp
C:\pos2136.tmp
C:\pos2137.tmp
C:\pos2138.tmp
C:\pos2317.tmp
C:\pos237C.tmp
C:\pos251D.tmp
C:\pos26D.tmp
C:\pos3D7.tmp
C:\pos524.tmp
C:\pos6.tmp
C:\pos60A.tmp
C:\posAF1.tmp
C:\posB88.tmp
C:\posCAB.tmp
C:\posE29.tmp
C:\posEE0.tmp
C:\posFA4.tmp
C:\posFB.tmp
C:\posFED.tmp
C:\posFFA.tmp
C:\Program Files\Adssite Advanced Toolbar
C:\Program Files\Common Files\irii
C:\Program Files\iSpy Full.lnk
C:\Program Files\Router
C:\Program Files\Router\Router.exe
C:\Program Files\Router\UnInstall.exe
C:\Program Files\Viewpoint
C:\Program Files\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\ClassIDs.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\ComponentMgr.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\AOLArt.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\AOLShell.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\AOLUserShell.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\Cursors.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\DataTracking.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\GifReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\JpegReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\LensFlares.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\Mts3Reader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\ObjectMovie.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\SceneComponent.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\ServiceComponent.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\SreeDMMX.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\SWFView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VectorView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPAudio.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPExtras.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPSpeech.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPVideo.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\WaveletReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\ZoomView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\MtsAxInstaller.exe
C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
C:\VundoFix Backups
C:\VundoFix Backups\addmorefiles.txt
C:\VundoFix Backups\bfcwkfxx.exe.bad
C:\VundoFix Backups\bwcayira.dll.bad
C:\VundoFix Backups\byxxvuu.dll.bad
C:\VundoFix Backups\codjqbys.dll.bad
C:\VundoFix Backups\ditdlall.dll.bad
C:\VundoFix Backups\dloupqgw.dll.bad
C:\VundoFix Backups\dohtnsgl.exe.bad
C:\VundoFix Backups\dumoneef.exe.bad
C:\VundoFix Backups\gbonusds.dll.bad
C:\VundoFix Backups\jsoblgby.dll.bad
C:\VundoFix Backups\kuqiqfyc.exe.bad
C:\VundoFix Backups\kuveyyip.exe.bad
C:\VundoFix Backups\ldicoqsl.exe.bad
C:\VundoFix Backups\llaldtid.ini.bad
C:\VundoFix Backups\llygamwf.dll.bad
C:\VundoFix Backups\lrjcbdhp.dll.bad
C:\VundoFix Backups\mcauecac.exe.bad
C:\VundoFix Backups\mplmfana.exe.bad
C:\VundoFix Backups\npqcdqyx.dll.bad
C:\VundoFix Backups\okgheliu.dll.bad
C:\VundoFix Backups\olbrrwgv.exe.bad
C:\VundoFix Backups\prutv.bak1.bad
C:\VundoFix Backups\prutv.bak2.bad
C:\VundoFix Backups\prutv.ini.bad
C:\VundoFix Backups\qwxcqryg.exe.bad
C:\VundoFix Backups\riiyyqeh.exe.bad
C:\VundoFix Backups\rmjbsthx.dll.bad
C:\VundoFix Backups\spxkhucl.dll.bad
C:\VundoFix Backups\sybqjdoc.ini.bad
C:\VundoFix Backups\tdlythah.dll.bad
C:\VundoFix Backups\thufremu.exe.bad
C:\VundoFix Backups\urootcle.dll.bad
C:\VundoFix Backups\vturp.dll.bad
C:\VundoFix Backups\wgqpuold.ini.bad
C:\VundoFix Backups\wlyuyarj.dll.bad
C:\VundoFix Backups\wlyuyarj.dllbox.bad
C:\VundoFix Backups\wwrttvfu.dll.bad
C:\VundoFix Backups\xhtsbjmr.ini.bad
C:\VundoFix Backups\xvdxowgi.dll.bad
C:\VundoFix Backups\xyqdcqpn.ini.bad
C:\VundoFix Backups\xzrxgdpu.dll.bad
C:\VundoFix Backups\xzrxgdpu.dllbox.bad
C:\VundoFix Backups\ycljrhip.exe.bad
C:\VundoFix Backups\ytkdetcb.dll.bad
C:\WINDOWS\iun6002ev.exe
C:\WINDOWS\lahtgfws
C:\WINDOWS\lahtgfws\1.png
C:\WINDOWS\lahtgfws\2.png
C:\WINDOWS\lahtgfws\3.png
C:\WINDOWS\lahtgfws\4.png
C:\WINDOWS\lahtgfws\5.png
C:\WINDOWS\lahtgfws\6.png
C:\WINDOWS\lahtgfws\7.png
C:\WINDOWS\lahtgfws\8.png
C:\WINDOWS\lahtgfws\9.png
C:\WINDOWS\lahtgfws\bottom-rc.gif
C:\WINDOWS\lahtgfws\config.png
C:\WINDOWS\lahtgfws\content.png
C:\WINDOWS\lahtgfws\download.gif
C:\WINDOWS\lahtgfws\frame-bg.gif
C:\WINDOWS\lahtgfws\frame-bottom-left.gif
C:\WINDOWS\lahtgfws\frame-h1bg.gif
C:\WINDOWS\lahtgfws\head.png
C:\WINDOWS\lahtgfws\icon.png
C:\WINDOWS\lahtgfws\index.html
C:\WINDOWS\lahtgfws\main.css
C:\WINDOWS\lahtgfws\memory-prots.png
C:\WINDOWS\lahtgfws\net.png
C:\WINDOWS\lahtgfws\pc-mag.gif
C:\WINDOWS\lahtgfws\pc.gif
C:\WINDOWS\lahtgfws\poloska1.png
C:\WINDOWS\lahtgfws\poloska2.png
C:\WINDOWS\lahtgfws\poloska3.png
C:\WINDOWS\lahtgfws\promo1.html
C:\WINDOWS\lahtgfws\promo10.html
C:\WINDOWS\lahtgfws\promo11.html
C:\WINDOWS\lahtgfws\promo12.html
C:\WINDOWS\lahtgfws\promo13.html
C:\WINDOWS\lahtgfws\promo14.html
C:\WINDOWS\lahtgfws\promo15.html
C:\WINDOWS\lahtgfws\promo16.html
C:\WINDOWS\lahtgfws\promo17.html
C:\WINDOWS\lahtgfws\promo18.html
C:\WINDOWS\lahtgfws\promo2.html
C:\WINDOWS\lahtgfws\promo3.html
C:\WINDOWS\lahtgfws\promo4.html
C:\WINDOWS\lahtgfws\promo5.html
C:\WINDOWS\lahtgfws\promo6.html
C:\WINDOWS\lahtgfws\promo7.html
C:\WINDOWS\lahtgfws\promo8.html
C:\WINDOWS\lahtgfws\promo9.html
C:\WINDOWS\lahtgfws\reg.png
C:\WINDOWS\lahtgfws\repair.png
C:\WINDOWS\lahtgfws\scr-1.png
C:\WINDOWS\lahtgfws\scr-2.png
C:\WINDOWS\lahtgfws\start.png
C:\WINDOWS\lahtgfws\styles.css
C:\WINDOWS\lahtgfws\top-rc.gif
C:\WINDOWS\lahtgfws\vline.gif
C:\WINDOWS\lahtgfws\wp.png
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\wlyuyarj.dll
C:\WINDOWS\system32\wlyuyarj.dllbox

.
((((((((((((((((((((((((( Files Created from 2007-11-24 to 2007-12-24 )))))))))))))))))))))))))))))))
.

2007-12-23 19:10 . 2007-12-23 19:31 7,168 –a—— C:\WINDOWS\system32\windows
2007-12-23 18:28 . 2007-12-23 18:28 14,033 –a—— C:\pos290F.tmp
2007-12-23 17:44 . 2007-12-23 17:44 14,033 –a—— C:\pos2903.tmp
2007-12-22 16:20 . 2007-12-22 16:20 14,033 –a—— C:\pos24FB.tmp
2007-12-22 16:19 . 2007-12-22 16:19 14,033 –a—— C:\pos237A.tmp
2007-12-22 15:48 . 2007-12-22 15:48 14,033 –a—— C:\pos2315.tmp
2007-12-22 11:22 . 2007-12-22 11:23 14,033 –a—— C:\pos212C.tmp
2007-12-22 09:24 . 2007-12-22 09:24 d——– C:\WINDOWS\ERUNT
2007-12-22 09:13 . 2007-12-22 09:13 14,033 –a—— C:\pos1BBF.tmp
2007-12-22 08:59 . 2007-12-22 08:59 14,033 –a—— C:\pos1B4D.tmp
2007-12-22 08:58 . 2007-12-22 08:58 14,033 –a—— C:\pos1A9A.tmp
2007-12-22 08:45 . 2007-12-22 08:45 14,033 –a—— C:\pos195D.tmp
2007-12-22 08:44 . 2007-12-22 08:44 14,033 –a—— C:\pos192B.tmp
2007-12-22 08:43 . 2007-12-22 08:43 14,033 –a—— C:\pos1785.tmp
2007-12-21 20:08 . 2007-12-21 20:08 14,033 –a—— C:\pos175B.tmp
2007-12-21 20:07 . 2007-12-21 20:08 14,033 –a—— C:\pos1716.tmp
2007-12-21 07:34 . 2007-12-21 07:34 14,033 –a—— C:\pos156F.tmp
2007-12-21 07:33 . 2007-12-21 07:33 14,033 –a—— C:\pos13F5.tmp
2007-12-21 03:11 . 2007-12-21 03:11 14,033 –a—— C:\pos138B.tmp
2007-12-21 03:10 . 2007-12-21 03:10 14,033 –a—— C:\pos12FE.tmp
2007-12-20 18:28 . 2007-12-20 18:28 14,033 –a—— C:\posFF9.tmp
2007-12-20 18:27 . 2007-12-20 18:28 14,033 –a—— C:\posFE5.tmp
2007-12-20 17:10 . 2007-12-20 17:10 14,033 –a—— C:\posF8B.tmp
2007-12-20 17:09 . 2007-12-20 17:10 14,033 –a—— C:\posEDB.tmp
2007-12-20 16:55 . 2007-12-20 16:55 14,033 –a—— C:\posB7B.tmp
2007-12-20 16:54 . 2007-12-20 16:55 14,033 –a—— C:\posAE7.tmp
2007-12-20 16:25 . 2007-12-20 16:25 14,033 –a—— C:\posE27.tmp
2007-12-20 16:24 . 2007-12-20 16:24 14,033 –a—— C:\posC96.tmp
2007-12-20 15:51 . 2007-12-20 15:51 165,472 –a—— C:\WINDOWS\system32\gwytgksv.dll
2007-12-20 15:28 . 2007-12-20 15:28 d——– C:\Documents and Settings\All Users\Application Data\PopCap
2007-12-20 15:01 . 2007-12-20 15:01 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-20 15:01 . 2007-12-20 15:01 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-20 10:45 . 2007-12-20 10:46 14,033 –a—— C:\pos608.tmp
2007-12-20 10:18 . 2007-12-20 10:19 14,033 –a—— C:\pos50A.tmp
2007-12-20 10:07 . 2007-12-20 10:07 14,033 –a—— C:\pos3C5.tmp
2007-12-20 10:06 . 2007-12-20 10:06 14,033 –a—— C:\pos54.tmp
2007-12-20 09:35 . 2007-12-20 09:35 14,033 –a—— C:\pos26B.tmp
2007-12-20 09:34 . 2007-12-20 09:34 14,033 –a—— C:\posF9.tmp
2007-12-13 03:31 . 2007-12-20 15:31 d——– C:\Program Files\QdrPack(3)
2007-12-13 03:31 . 2007-12-20 15:31 d——– C:\Program Files\QdrModule(3)
2007-12-12 04:28 . 2007-12-20 15:34 d——– C:\Program Files\Outerinfo(2)
2007-12-06 17:36 . 2007-12-20 15:35 d——– C:\Program Files\QdrPack(2)
2007-12-06 17:36 . 2007-12-20 15:35 d——– C:\Program Files\QdrModule(2)

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-23 23:30 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-20 22:06 ——— d—–w C:\Program Files\Java
2007-12-20 20:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-20 20:34 ——— d—–w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\AdobeUM
2007-12-20 00:01 ——— d—–w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\UseNeXT
2007-12-05 14:56 ——— d—–w C:\Program Files\Yahoo!
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-10 13:11 ——— d—–w C:\Program Files\BoontyGames
2007-11-10 13:08 ——— d—–w C:\Program Files\GameFiesta
2007-11-10 13:07 ——— d—–w C:\Program Files\Gateway Games
2007-11-10 12:39 ——— d—–w C:\Program Files\High Quality Photo Resizer
2007-11-10 03:44 41,712 —-a-w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\GDIPFONTCACHEV1.DAT
2007-11-07 21:28 ——— d—–w C:\Program Files\Photo Merge and Rename
2007-11-07 20:48 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-07 20:48 ——— d—–w C:\Program Files\PhotoBuilder
2007-11-07 20:20 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-07 20:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-10-28 23:16 ——— d—–w C:\Program Files\Pilot Group Ltd
2007-10-24 00:30 ——— d—–w C:\Program Files\Microsoft Money 2006
2007-08-05 13:57 576 -c–a-w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((( snapshot@2007-12-23_16.44.04.93 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-03-29 21:27:02 9,845 -c–a-w C:\WINDOWS\system32\mswrn9ofe.dll
+ 2007-02-07 00:41:13 9,845 -c–a-w C:\WINDOWS\system32\mswrn9ofe.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 14:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24]
"Power2GoExpress"="NA" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 18:03]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 16:57]
"ProStoresStoreMonitor"="C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe" [2005-09-22 20:15]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 22:56]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-06-14 22:50]
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [2005-12-09 20:44]
"RTHDCPL"="RTHDCPL.EXE" [2005-11-09 07:14 C:\WINDOWS\RTHDCPL.exe]
"HostManager"="C:\Program Files\Common Files\AOL\1181880268\EE\AOLHostManager.exe" [2004-11-03 16:03]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-18 19:42]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-10 14:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2005-11-30 06:02 C:\WINDOWS\system32\nwiz.exe]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 18:19 C:\WINDOWS\arpwrmsg.exe]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 18:16]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-10 14:00 C:\WINDOWS\system32\rundll32.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-14 23:05]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 14:57]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2007-10-13 13:47:24]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]
WG111v2 Smart Wizard Wireless Setting.lnk - C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2007-08-22 17:25:59]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

R2 Belkin Wireless USB Network Adapter Service;Belkin Wireless USB Network Adapter;C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe [2004-03-29 15:08]
R2 EAPPkt;Realtek EAPPkt Protocol;C:\WINDOWS\system32\DRIVERS\EAPPkt.sys [2005-04-01 10:43]
S3 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe" [2007-09-20 21:16]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2006-03-27 16:53]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c87c5be5-62f5-11dc-a80e-001150c173cc}]
\Shell\AutoRun\command - J:\PortableVault.exe

.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-23 19:43:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-23 19:46:31 - machine was rebooted
C:\ComboFix2.txt … 2007-12-23 16:45
.
2007-12-21 08:02:47 — E O F —



Logfile of HijackThis v1.99.1
Scan saved at 7:55:32 PM, on 12/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe
C:\PROGRA~1\COMMON~1\AOL\118188~1\EE\AOLHOS~1.EXE
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\PROGRA~1\COMMON~1\AOL\118188~1\EE\AOLServiceHost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1181880268\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [ProStoresStoreMonitor] C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/share…GamesLoader.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://www.king.com/ctl/kingcomie.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {F73BE1F4-82AA-4405-AB81-FAFB5A122359} (SiteBuilderEditor Class) - http://store01.prostores.com/storeadmin/ut…es/pssbedit.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcccoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
Hi

There is a lot of those tmp files!


You need to remain connected to the Internet this time, but still disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus when Combofix has finished.


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

Collect::
C:\WINDOWS\system32\windows
C:\pos290F.tmp
C:\Program Files\Vzabrchultnpa\xjnopfq.exe

File::
C:\pos290F.tmp
C:\pos2903.tmp
C:\pos24FB.tmp
C:\pos237A.tmp
C:\pos2315.tmp
C:\pos212C.tmp
C:\pos1BBF.tmp
C:\pos1B4D.tmp
C:\pos1A9A.tmp
C:\pos195D.tmp
C:\pos192B.tmp
C:\pos1785.tmp
C:\pos175B.tmp
C:\pos1716.tmp
C:\pos156F.tmp
C:\pos13F5.tmp
C:\pos138B.tmp
C:\pos12FE.tmp
C:\posFF9.tmp
C:\posFE5.tmp
C:\posF8B.tmp
C:\posEDB.tmp
C:\posB7B.tmp
C:\posAE7.tmp
C:\posE27.tmp
C:\posC96.tmp
C:\WINDOWS\system32\gwytgksv.dll
C:\pos608.tmp
C:\pos50A.tmp
C:\pos3C5.tmp
C:\pos54.tmp
C:\pos26B.tmp
C:\posF9.tmp 

Folder::
C:\Program Files\Vzabrchultnpa

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run
bleeping computer results

Malware Submission
Your file was successfully submitted. Please let the user helping you know that you have submitted the file.

ComboFix 07-12-23.1 - Owner 2007-12-24 9:15:39.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.89 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner.YOUR-9EFB86816C\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\pos12FE.tmp
C:\pos138B.tmp
C:\pos13F5.tmp
C:\pos156F.tmp
C:\pos1716.tmp
C:\pos175B.tmp
C:\pos1785.tmp
C:\pos192B.tmp
C:\pos195D.tmp
C:\pos1A9A.tmp
C:\pos1B4D.tmp
C:\pos1BBF.tmp
C:\pos212C.tmp
C:\pos2315.tmp
C:\pos237A.tmp
C:\pos24FB.tmp
C:\pos26B.tmp
C:\pos2903.tmp
C:\pos290F.tmp
C:\pos3C5.tmp
C:\pos50A.tmp
C:\pos54.tmp
C:\pos608.tmp
C:\posAE7.tmp
C:\posB7B.tmp
C:\posC96.tmp
C:\posE27.tmp
C:\posEDB.tmp
C:\posF8B.tmp
C:\posF9.tmp
C:\posFE5.tmp
C:\posFF9.tmp
C:\WINDOWS\system32\gwytgksv.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\pos12FE.tmp
C:\pos138B.tmp
C:\pos13F5.tmp
C:\pos156F.tmp
C:\pos1716.tmp
C:\pos175B.tmp
C:\pos1785.tmp
C:\pos192B.tmp
C:\pos195D.tmp
C:\pos1A9A.tmp
C:\pos1B4D.tmp
C:\pos1BBF.tmp
C:\pos212C.tmp
C:\pos2315.tmp
C:\pos237A.tmp
C:\pos24FB.tmp
C:\pos26B.tmp
C:\pos2903.tmp
C:\pos290F.tmp
C:\pos3C5.tmp
C:\pos50A.tmp
C:\pos54.tmp
C:\pos608.tmp
C:\posAE7.tmp
C:\posB7B.tmp
C:\posC96.tmp
C:\posE27.tmp
C:\posEDB.tmp
C:\posF8B.tmp
C:\posF9.tmp
C:\posFE5.tmp
C:\posFF9.tmp
C:\Program Files\Vzabrchultnpa
C:\Program Files\Vzabrchultnpa\help.chm
C:\Program Files\Vzabrchultnpa\Log\Text\aiotxt.dat
C:\Program Files\Vzabrchultnpa\Log\Text\aioweb.dat
C:\Program Files\Vzabrchultnpa\Log\Visual\11032007.dat
C:\Program Files\Vzabrchultnpa\Log\Visual\11042007.dat
C:\Program Files\Vzabrchultnpa\Log\Visual\11052007.dat
C:\Program Files\Vzabrchultnpa\Log\Visual\11062007.dat
C:\Program Files\Vzabrchultnpa\tips
C:\Program Files\Vzabrchultnpa\unins000.dat
C:\Program Files\Vzabrchultnpa\unins000.exe
C:\Program Files\Vzabrchultnpa\xjnopfq.exe
C:\WINDOWS\system32\gwytgksv.dll
C:\WINDOWS\system32\windows

.
((((((((((((((((((((((((( Files Created from 2007-11-24 to 2007-12-24 )))))))))))))))))))))))))))))))
.

2007-12-23 18:28 . 2007-12-23 18:28 12,033 –a—— C:\pos2914.tmp
2007-12-23 17:44 . 2007-12-23 17:44 14,033 –a—— C:\pos28F2.tmp
2007-12-22 16:20 . 2007-12-22 16:20 14,033 –a—— C:\pos24D5.tmp
2007-12-22 16:19 . 2007-12-22 16:27 14,033 –a—— C:\pos2354.tmp
2007-12-22 15:48 . 2007-12-22 15:48 14,033 –a—— C:\pos230C.tmp
2007-12-22 11:22 . 2007-12-22 11:23 14,033 –a—— C:\pos2124.tmp
2007-12-22 09:24 . 2007-12-22 09:24 d——– C:\WINDOWS\ERUNT
2007-12-22 09:13 . 2007-12-22 09:13 14,033 –a—— C:\pos1BBB.tmp
2007-12-22 08:59 . 2007-12-22 08:59 14,033 –a—— C:\pos1B41.tmp
2007-12-22 08:58 . 2007-12-22 08:58 14,033 –a—— C:\pos1A93.tmp
2007-12-22 08:45 . 2007-12-22 08:45 14,033 –a—— C:\pos1955.tmp
2007-12-22 08:44 . 2007-12-22 08:44 14,033 –a—— C:\pos190D.tmp
2007-12-22 08:43 . 2007-12-22 08:43 14,033 –a—— C:\pos1784.tmp
2007-12-21 20:08 . 2007-12-21 20:08 14,033 –a—— C:\pos1746.tmp
2007-12-21 20:07 . 2007-12-21 20:07 14,033 –a—— C:\pos1710.tmp
2007-12-21 07:34 . 2007-12-21 07:34 14,033 –a—— C:\pos1565.tmp
2007-12-21 07:33 . 2007-12-21 20:05 14,033 –a—— C:\pos13DE.tmp
2007-12-21 03:11 . 2007-12-21 03:11 14,033 –a—— C:\pos1382.tmp
2007-12-21 03:10 . 2007-12-21 03:10 14,033 –a—— C:\pos12F7.tmp
2007-12-20 18:28 . 2007-12-20 18:28 14,033 –a—— C:\pos1198.tmp
2007-12-20 18:27 . 2007-12-20 18:28 14,033 –a—— C:\posFE4.tmp
2007-12-20 17:10 . 2007-12-20 17:10 14,033 –a—— C:\posF88.tmp
2007-12-20 17:09 . 2007-12-20 17:09 14,033 –a—— C:\posED8.tmp
2007-12-20 16:55 . 2007-12-20 16:55 14,033 –a—— C:\posB76.tmp
2007-12-20 16:54 . 2007-12-20 16:55 14,033 –a—— C:\posADD.tmp
2007-12-20 16:25 . 2007-12-20 16:25 14,033 –a—— C:\posE24.tmp
2007-12-20 16:24 . 2007-12-20 16:24 14,033 –a—— C:\posC94.tmp
2007-12-20 15:51 . 2007-12-20 15:51 14,033 –a—— C:\pos9C5.tmp
2007-12-20 15:28 . 2007-12-20 15:28 d——– C:\Documents and Settings\All Users\Application Data\PopCap
2007-12-20 15:01 . 2007-12-20 15:01 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-20 15:01 . 2007-12-20 15:01 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-20 10:45 . 2007-12-20 10:46 14,033 –a—— C:\pos604.tmp
2007-12-20 10:18 . 2007-12-20 10:19 14,033 –a—— C:\pos4DC.tmp
2007-12-20 10:07 . 2007-12-20 10:07 14,033 –a—— C:\pos3C3.tmp
2007-12-20 10:06 . 2007-12-20 10:06 14,033 –a—— C:\pos4C.tmp
2007-12-20 09:35 . 2007-12-20 09:35 14,033 –a—— C:\pos260.tmp
2007-12-20 09:34 . 2007-12-20 09:34 14,033 –a—— C:\posF4.tmp
2007-12-13 03:31 . 2007-12-20 15:31 d——– C:\Program Files\QdrPack(3)
2007-12-13 03:31 . 2007-12-20 15:31 d——– C:\Program Files\QdrModule(3)
2007-12-12 04:28 . 2007-12-20 15:34 d——– C:\Program Files\Outerinfo(2)
2007-12-06 17:36 . 2007-12-20 15:35 d——– C:\Program Files\QdrPack(2)
2007-12-06 17:36 . 2007-12-20 15:35 d——– C:\Program Files\QdrModule(2)

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-24 04:38 ——— d—–w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\UseNeXT
2007-12-23 23:30 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-20 22:06 ——— d—–w C:\Program Files\Java
2007-12-20 20:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-20 20:34 ——— d—–w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\AdobeUM
2007-12-05 14:56 ——— d—–w C:\Program Files\Yahoo!
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-10 13:11 ——— d—–w C:\Program Files\BoontyGames
2007-11-10 13:08 ——— d—–w C:\Program Files\GameFiesta
2007-11-10 13:07 ——— d—–w C:\Program Files\Gateway Games
2007-11-10 12:39 ——— d—–w C:\Program Files\High Quality Photo Resizer
2007-11-10 03:44 41,712 —-a-w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\GDIPFONTCACHEV1.DAT
2007-11-07 21:28 ——— d—–w C:\Program Files\Photo Merge and Rename
2007-11-07 20:48 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-07 20:48 ——— d—–w C:\Program Files\PhotoBuilder
2007-11-07 20:20 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-07 20:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-28 23:16 ——— d—–w C:\Program Files\Pilot Group Ltd
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-24 00:30 ——— d—–w C:\Program Files\Microsoft Money 2006
2007-10-19 22:49 107,888 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-10-11 20:47 245,408 —-a-w C:\WINDOWS\system32\unicows.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\wininet(3)(2).dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\urlmon(3)(2).dll
2007-10-10 23:55 267,776 —-a-w C:\WINDOWS\system32\iertutil(2)(2).dll
2007-10-10 23:55 105,984 —-a-w C:\WINDOWS\system32\url(3)(2).dll
2007-08-05 13:57 576 -c–a-w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((( snapshot@2007-12-23_16.44.04.93 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-07-16 21:43:24 118,784 —-a-w C:\WINDOWS\system32\msuuncerb.dll
+ 2007-01-11 23:30:00 118,784 —-a-w C:\WINDOWS\system32\msuuncerb.dll
- 2007-03-29 21:27:02 9,845 -c–a-w C:\WINDOWS\system32\mswrn9ofe.dll
+ 2007-02-07 00:41:13 9,845 -c–a-w C:\WINDOWS\system32\mswrn9ofe.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 14:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24]
"Power2GoExpress"="NA" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 18:03]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 16:57]
"ProStoresStoreMonitor"="C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe" [2005-09-22 20:15]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 22:56]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-06-14 22:50]
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [2005-12-09 20:44]
"RTHDCPL"="RTHDCPL.EXE" [2005-11-09 07:14 C:\WINDOWS\RTHDCPL.exe]
"HostManager"="C:\Program Files\Common Files\AOL\1181880268\EE\AOLHostManager.exe" [2004-11-03 16:03]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-18 19:42]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-10 14:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2005-11-30 06:02 C:\WINDOWS\system32\nwiz.exe]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 18:19 C:\WINDOWS\arpwrmsg.exe]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 18:16]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-10 14:00 C:\WINDOWS\system32\rundll32.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-14 23:05]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 14:57]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2007-10-13 13:47:24]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]
WG111v2 Smart Wizard Wireless Setting.lnk - C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2007-08-22 17:25:59]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

R2 Belkin Wireless USB Network Adapter Service;Belkin Wireless USB Network Adapter;C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe [2004-03-29 15:08]
R2 EAPPkt;Realtek EAPPkt Protocol;C:\WINDOWS\system32\DRIVERS\EAPPkt.sys [2005-04-01 10:43]
S3 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe" [2007-09-20 21:16]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2006-03-27 16:53]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c87c5be5-62f5-11dc-a80e-001150c173cc}]
\Shell\AutoRun\command - J:\PortableVault.exe

.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-24 09:20:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

**************************************************************************
.
Completion time: 2007-12-24 9:22:20
C:\ComboFix2.txt … 2007-12-23 19:46
C:\ComboFix3.txt … 2007-12-23 16:45
.
2007-12-21 08:02:47 — E O F —



ComboFix 07-12-23.1 - Owner 2007-12-24 9:15:39.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.89 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner.YOUR-9EFB86816C\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\pos12FE.tmp
C:\pos138B.tmp
C:\pos13F5.tmp
C:\pos156F.tmp
C:\pos1716.tmp
C:\pos175B.tmp
C:\pos1785.tmp
C:\pos192B.tmp
C:\pos195D.tmp
C:\pos1A9A.tmp
C:\pos1B4D.tmp
C:\pos1BBF.tmp
C:\pos212C.tmp
C:\pos2315.tmp
C:\pos237A.tmp
C:\pos24FB.tmp
C:\pos26B.tmp
C:\pos2903.tmp
C:\pos290F.tmp
C:\pos3C5.tmp
C:\pos50A.tmp
C:\pos54.tmp
C:\pos608.tmp
C:\posAE7.tmp
C:\posB7B.tmp
C:\posC96.tmp
C:\posE27.tmp
C:\posEDB.tmp
C:\posF8B.tmp
C:\posF9.tmp
C:\posFE5.tmp
C:\posFF9.tmp
C:\WINDOWS\system32\gwytgksv.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\pos12FE.tmp
C:\pos138B.tmp
C:\pos13F5.tmp
C:\pos156F.tmp
C:\pos1716.tmp
C:\pos175B.tmp
C:\pos1785.tmp
C:\pos192B.tmp
C:\pos195D.tmp
C:\pos1A9A.tmp
C:\pos1B4D.tmp
C:\pos1BBF.tmp
C:\pos212C.tmp
C:\pos2315.tmp
C:\pos237A.tmp
C:\pos24FB.tmp
C:\pos26B.tmp
C:\pos2903.tmp
C:\pos290F.tmp
C:\pos3C5.tmp
C:\pos50A.tmp
C:\pos54.tmp
C:\pos608.tmp
C:\posAE7.tmp
C:\posB7B.tmp
C:\posC96.tmp
C:\posE27.tmp
C:\posEDB.tmp
C:\posF8B.tmp
C:\posF9.tmp
C:\posFE5.tmp
C:\posFF9.tmp
C:\Program Files\Vzabrchultnpa
C:\Program Files\Vzabrchultnpa\help.chm
C:\Program Files\Vzabrchultnpa\Log\Text\aiotxt.dat
C:\Program Files\Vzabrchultnpa\Log\Text\aioweb.dat
C:\Program Files\Vzabrchultnpa\Log\Visual\11032007.dat
C:\Program Files\Vzabrchultnpa\Log\Visual\11042007.dat
C:\Program Files\Vzabrchultnpa\Log\Visual\11052007.dat
C:\Program Files\Vzabrchultnpa\Log\Visual\11062007.dat
C:\Program Files\Vzabrchultnpa\tips
C:\Program Files\Vzabrchultnpa\unins000.dat
C:\Program Files\Vzabrchultnpa\unins000.exe
C:\Program Files\Vzabrchultnpa\xjnopfq.exe
C:\WINDOWS\system32\gwytgksv.dll
C:\WINDOWS\system32\windows

.
((((((((((((((((((((((((( Files Created from 2007-11-24 to 2007-12-24 )))))))))))))))))))))))))))))))
.

2007-12-23 18:28 . 2007-12-23 18:28 12,033 –a—— C:\pos2914.tmp
2007-12-23 17:44 . 2007-12-23 17:44 14,033 –a—— C:\pos28F2.tmp
2007-12-22 16:20 . 2007-12-22 16:20 14,033 –a—— C:\pos24D5.tmp
2007-12-22 16:19 . 2007-12-22 16:27 14,033 –a—— C:\pos2354.tmp
2007-12-22 15:48 . 2007-12-22 15:48 14,033 –a—— C:\pos230C.tmp
2007-12-22 11:22 . 2007-12-22 11:23 14,033 –a—— C:\pos2124.tmp
2007-12-22 09:24 . 2007-12-22 09:24 d——– C:\WINDOWS\ERUNT
2007-12-22 09:13 . 2007-12-22 09:13 14,033 –a—— C:\pos1BBB.tmp
2007-12-22 08:59 . 2007-12-22 08:59 14,033 –a—— C:\pos1B41.tmp
2007-12-22 08:58 . 2007-12-22 08:58 14,033 –a—— C:\pos1A93.tmp
2007-12-22 08:45 . 2007-12-22 08:45 14,033 –a—— C:\pos1955.tmp
2007-12-22 08:44 . 2007-12-22 08:44 14,033 –a—— C:\pos190D.tmp
2007-12-22 08:43 . 2007-12-22 08:43 14,033 –a—— C:\pos1784.tmp
2007-12-21 20:08 . 2007-12-21 20:08 14,033 –a—— C:\pos1746.tmp
2007-12-21 20:07 . 2007-12-21 20:07 14,033 –a—— C:\pos1710.tmp
2007-12-21 07:34 . 2007-12-21 07:34 14,033 –a—— C:\pos1565.tmp
2007-12-21 07:33 . 2007-12-21 20:05 14,033 –a—— C:\pos13DE.tmp
2007-12-21 03:11 . 2007-12-21 03:11 14,033 –a—— C:\pos1382.tmp
2007-12-21 03:10 . 2007-12-21 03:10 14,033 –a—— C:\pos12F7.tmp
2007-12-20 18:28 . 2007-12-20 18:28 14,033 –a—— C:\pos1198.tmp
2007-12-20 18:27 . 2007-12-20 18:28 14,033 –a—— C:\posFE4.tmp
2007-12-20 17:10 . 2007-12-20 17:10 14,033 –a—— C:\posF88.tmp
2007-12-20 17:09 . 2007-12-20 17:09 14,033 –a—— C:\posED8.tmp
2007-12-20 16:55 . 2007-12-20 16:55 14,033 –a—— C:\posB76.tmp
2007-12-20 16:54 . 2007-12-20 16:55 14,033 –a—— C:\posADD.tmp
2007-12-20 16:25 . 2007-12-20 16:25 14,033 –a—— C:\posE24.tmp
2007-12-20 16:24 . 2007-12-20 16:24 14,033 –a—— C:\posC94.tmp
2007-12-20 15:51 . 2007-12-20 15:51 14,033 –a—— C:\pos9C5.tmp
2007-12-20 15:28 . 2007-12-20 15:28 d——– C:\Documents and Settings\All Users\Application Data\PopCap
2007-12-20 15:01 . 2007-12-20 15:01 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-20 15:01 . 2007-12-20 15:01 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-20 10:45 . 2007-12-20 10:46 14,033 –a—— C:\pos604.tmp
2007-12-20 10:18 . 2007-12-20 10:19 14,033 –a—— C:\pos4DC.tmp
2007-12-20 10:07 . 2007-12-20 10:07 14,033 –a—— C:\pos3C3.tmp
2007-12-20 10:06 . 2007-12-20 10:06 14,033 –a—— C:\pos4C.tmp
2007-12-20 09:35 . 2007-12-20 09:35 14,033 –a—— C:\pos260.tmp
2007-12-20 09:34 . 2007-12-20 09:34 14,033 –a—— C:\posF4.tmp
2007-12-13 03:31 . 2007-12-20 15:31 d——– C:\Program Files\QdrPack(3)
2007-12-13 03:31 . 2007-12-20 15:31 d——– C:\Program Files\QdrModule(3)
2007-12-12 04:28 . 2007-12-20 15:34 d——– C:\Program Files\Outerinfo(2)
2007-12-06 17:36 . 2007-12-20 15:35 d——– C:\Program Files\QdrPack(2)
2007-12-06 17:36 . 2007-12-20 15:35 d——– C:\Program Files\QdrModule(2)

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-24 04:38 ——— d—–w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\UseNeXT
2007-12-23 23:30 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-20 22:06 ——— d—–w C:\Program Files\Java
2007-12-20 20:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-20 20:34 ——— d—–w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\AdobeUM
2007-12-05 14:56 ——— d—–w C:\Program Files\Yahoo!
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-10 13:11 ——— d—–w C:\Program Files\BoontyGames
2007-11-10 13:08 ——— d—–w C:\Program Files\GameFiesta
2007-11-10 13:07 ——— d—–w C:\Program Files\Gateway Games
2007-11-10 12:39 ——— d—–w C:\Program Files\High Quality Photo Resizer
2007-11-10 03:44 41,712 —-a-w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\GDIPFONTCACHEV1.DAT
2007-11-07 21:28 ——— d—–w C:\Program Files\Photo Merge and Rename
2007-11-07 20:48 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-07 20:48 ——— d—–w C:\Program Files\PhotoBuilder
2007-11-07 20:20 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-07 20:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-28 23:16 ——— d—–w C:\Program Files\Pilot Group Ltd
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-24 00:30 ——— d—–w C:\Program Files\Microsoft Money 2006
2007-10-19 22:49 107,888 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-10-11 20:47 245,408 —-a-w C:\WINDOWS\system32\unicows.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\wininet(3)(2).dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\urlmon(3)(2).dll
2007-10-10 23:55 267,776 —-a-w C:\WINDOWS\system32\iertutil(2)(2).dll
2007-10-10 23:55 105,984 —-a-w C:\WINDOWS\system32\url(3)(2).dll
2007-08-05 13:57 576 -c–a-w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((( snapshot@2007-12-23_16.44.04.93 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-07-16 21:43:24 118,784 —-a-w C:\WINDOWS\system32\msuuncerb.dll
+ 2007-01-11 23:30:00 118,784 —-a-w C:\WINDOWS\system32\msuuncerb.dll
- 2007-03-29 21:27:02 9,845 -c–a-w C:\WINDOWS\system32\mswrn9ofe.dll
+ 2007-02-07 00:41:13 9,845 -c–a-w C:\WINDOWS\system32\mswrn9ofe.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 14:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24]
"Power2GoExpress"="NA" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 18:03]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 16:57]
"ProStoresStoreMonitor"="C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe" [2005-09-22 20:15]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 22:56]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-06-14 22:50]
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [2005-12-09 20:44]
"RTHDCPL"="RTHDCPL.EXE" [2005-11-09 07:14 C:\WINDOWS\RTHDCPL.exe]
"HostManager"="C:\Program Files\Common Files\AOL\1181880268\EE\AOLHostManager.exe" [2004-11-03 16:03]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-18 19:42]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-10 14:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2005-11-30 06:02 C:\WINDOWS\system32\nwiz.exe]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 18:19 C:\WINDOWS\arpwrmsg.exe]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 18:16]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-10 14:00 C:\WINDOWS\system32\rundll32.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-14 23:05]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 14:57]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2007-10-13 13:47:24]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]
WG111v2 Smart Wizard Wireless Setting.lnk - C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2007-08-22 17:25:59]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

R2 Belkin Wireless USB Network Adapter Service;Belkin Wireless USB Network Adapter;C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe [2004-03-29 15:08]
R2 EAPPkt;Realtek EAPPkt Protocol;C:\WINDOWS\system32\DRIVERS\EAPPkt.sys [2005-04-01 10:43]
S3 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe" [2007-09-20 21:16]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2006-03-27 16:53]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c87c5be5-62f5-11dc-a80e-001150c173cc}]
\Shell\AutoRun\command - J:\PortableVault.exe

.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-24 09:20:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

**************************************************************************
.
Completion time: 2007-12-24 9:22:20
C:\ComboFix2.txt … 2007-12-23 19:46
C:\ComboFix3.txt … 2007-12-23 16:45
.
2007-12-21 08:02:47 — E O F —
Those files are being recreated as quickly as we can delete them.

BLACKLIGHT
  • Please download F-Secure Blacklight (fsbl.exe) from here
  • Save into C:\ with a name of fsbl.exe
  • Go to Start > Run
  • Copy and paste the contents of the below codebox into the run box
    C:\fsbl.exe /expert
  • Click OK
  • This will launch BlackLight
  • Select I accept the agreement
  • Click Next
  • Click Scan
  • Wait for the scan to finish
  • Click on Next>
  • Click Exit
  • A logfile will have been created in the C:\ drive
  • It will be named fsbl-xxxxxxxxxxxxxx.log where xxxxxxxxxxxxxx is the date and time of the scan
  • Use notepad to open that log
  • Post the contents of that log as a reply to this topic together with a new HijackThis log.
12/24/07 13:40:58 [Info]: BlackLight Engine 1.0.67 initialized
12/24/07 13:40:58 [Info]: OS: 5.1 build 2600 (Service Pack 2)
12/24/07 13:40:58 [Note]: 7019 4
12/24/07 13:40:58 [Note]: 7005 0
12/24/07 13:41:02 [Note]: 7006 0
12/24/07 13:41:02 [Note]: 7011 2756
12/24/07 13:41:03 [Note]: 7026 0
12/24/07 13:41:03 [Note]: 7026 0
12/24/07 13:41:04 [Note]: FSRAW library version 1.7.1024
12/24/07 14:12:21 [Note]: 2000 1012
12/24/07 14:45:24 [Note]: 7007 0



Logfile of HijackThis v1.99.1
Scan saved at 2:48:59 PM, on 12/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\PROGRA~1\COMMON~1\AOL\118188~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\118188~1\EE\AOLServiceHost.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\lxcccoms.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1181880268\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [ProStoresStoreMonitor] C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/share…GamesLoader.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://www.king.com/ctl/kingcomie.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {F73BE1F4-82AA-4405-AB81-FAFB5A122359} (SiteBuilderEditor Class) - http://store01.prostores.com/storeadmin/ut…es/pssbedit.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcccoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI