This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Dropper.Agent.GIT- mlljj.exe infecting start up items

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Help, please!

Brief background: I noticed my Norton 360 was not able to complete an update ("error 5"). A full Norton virus scan did not identify anything at all. Upon rebooting, all my start up items including Norton did not launch. I rebooted into safe mode and downloaded AVG, which found and deleted about 20+ files flagged with "Trojan horse Dropper.Agent.GIT".

Upon rebooting normally and doing some research, I ran AVG a second time and found another 16 items flagged with "Trojan horse Dropper.Agent.GIT". After AVG deleted them, I rebooted into safe mode and immediately ran AVG a third time. The single file with Agent.GIT that returned was c:\windows\system32\mlljj.exe.

Below is my current HijackThis log file after booting normally. Any help you can offer in removing this malware will be greatly appreciated!



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:54:36 PM, on 12/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\WINDOWS\System32\svchost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Host Process] C:\WINDOWS\Fonts\svchost.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE" -quiet
O4 - HKCU\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.8.6\webbuying.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://software-dl.real.com/1017b8b918d6bc…ne_Inst_Win.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1166005466109
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (file missing)
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 10209 bytes
Hello, and welcome to the forum.

My name is Simon V., and I'll be glad to help you with your computer problems.

Step 1

Please download and install CCleaner.

Open CCleaner. On the Windows tab, leave the default options alone.

  • On the Applications tab, check (tick) all the boxes except Saved Form Information. This will remove all your saved passwords if you leave this box checked.
  • Click on the Run Cleaner button at the bottom right hand corner.
  • Close CCleaner.

Step 2

Please download SDFix and save it to your desktop.

Double click SDFix.exe and it will extract the files to %systemdrive% (Drive that contains the Windows directory, typically C:\SDFix)

  • Print these instructions or copy them to Notepad and save it to your desktop, as you won't be able to access internet in Safe Mode.
  • Please reboot into Safe Mode. To do this, go to Start > Turn off Computer, and select Restart. Rapidly tap F8 just before Windows starts to load. In the menu that appears, select Safe Mode (Without Networking)

Once in Safe Mode, do the following:

  • Open the extracted SDFix folder and double-click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any trojan services and registry entries that it finds, then prompt you to press any key to reboot; press any key and it will restart the PC.
  • When the PC restarts SDFix will run again and complete the removal process then display Finished. Press any key to end the script and load your desktop icons.
  • Once the desktop icons load, the SDFix report will open on screen and also save into the SDFix folder as Report.txt (Report.txt will also be copied to clipboard ready for posting back on the forum).

Step 3

Open CCleaner. In the Left Pane, click Tools.

  • Verify that Uninstall is highlighted in color, or click on it.
  • In the lower right, click Save to Text File.
  • Pull down the arrow at the top of the Save dialog and choose Desktop as the location.
  • You can leave the filename as install.txt.
  • Click Save, then exit Ccleaner.

Step 4

In your next reply, please post:

  • the SDFix report (C:\SDFix\Report.txt)
  • the CCleaner Uninstall List (install.txt)
  • a new HijackThis log
Thanks, Simon! Below is the requested info:





SDFix report:


SDFix: Version 1.122

Run by [removed] on Wed 01/02/2008 at 08:16 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\Z.DAT - Deleted
C:\PROGRA~1\COMPLU~1\RTEREP~1.HTM - Deleted
C:\Temp\1cb\syscheck.log - Deleted
C:\n.bat - Deleted
C:\winlogon.exe - Deleted
C:\x.dat - Deleted
C:\z.dat - Deleted
C:\WINDOWS\system32\pac.txt - Deleted

x.dat and z.dat data copied to \SDFix\Data.txt


Folder C:\Temp\1cb - Removed
Folder C:\Temp\tn3 - Removed

Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-02 20:24:19
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\CancelAutoplay\CLSID]
"\30 A?E?2?A?E?D?8?F?-?5?6?9?5?-?4?a?6?d?-?9?7?0?9?-?1?4?E?5?1?C?D?1?7?B?1?C?'?"=""

scanning hidden files …

C:\WINDOWS\0.log 0 bytes

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\TurboTax\\Deluxe 2006\\32bit\\ttax.exe"="C:\\Program Files\\TurboTax\\Deluxe 2006\\32bit\\ttax.exe:LocalSubNet:Enabled:TurboTax"
"C:\\Program Files\\TurboTax\\Deluxe 2006\\32bit\\updatemgr.exe"="C:\\Program Files\\TurboTax\\Deluxe 2006\\32bit\\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"="C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice"
"C:\\Program Files\\Adobe\\Photoshop Elements 6.0\\AdobePhotoshopElementsMediaServer.exe"="C:\\Program Files\\Adobe\\Photoshop Elements 6.0\\AdobePhotoshopElementsMediaServer.exe:*:Disabled:Adobe Photoshop Elements Media Server"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Remaining Files:
—————

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Sat 19 Aug 2006 211 A.SHR — "C:\BOOT.BAK"
Thu 28 Jun 2007 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 13 Mar 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Sat 22 Sep 2007 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\cf7ced0e70c80a1e476f1abf49afecb1\BITF.tmp"
Mon 23 Sep 2002 36,352 A..H. — "C:\Work Files\GE Work Files\GE Files\1Stop Processes and Docs\1Stop e-Auto Gen2\~WRL0003.tmp"
Tue 10 Sep 2002 34,304 A..H. — "C:\Work Files\GE Work Files\GE Files\1Stop Processes and Docs\1Stop e-Auto Gen2\~WRL0005.tmp"
Mon 23 Sep 2002 35,328 A..H. — "C:\Work Files\GE Work Files\GE Files\1Stop Processes and Docs\1Stop e-Auto Gen2\~WRL0479.tmp"
Tue 13 May 2003 51,200 A..H. — "C:\Work Files\GE Work Files\GE Files\GE Misc\Natale UPs and DOWNs\~WRL0001.tmp"
Mon 15 Aug 2005 93,184 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\QC Historical Files\Ethicon NCR Weekly Status Spreadsheets\~WRL1021.tmp"
Mon 15 Aug 2005 94,208 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\QC Historical Files\Ethicon NCR Weekly Status Spreadsheets\~WRL1173.tmp"
Mon 15 Aug 2005 96,768 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\QC Historical Files\Ethicon NCR Weekly Status Spreadsheets\~WRL2516.tmp"
Mon 15 Aug 2005 96,768 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\QC Historical Files\Ethicon NCR Weekly Status Spreadsheets\~WRL2662.tmp"
Mon 15 Aug 2005 92,672 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\QC Historical Files\Ethicon NCR Weekly Status Spreadsheets\~WRL3862.tmp"
Mon 15 Aug 2005 96,256 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\QC Historical Files\Ethicon NCR Weekly Status Spreadsheets\~WRL3935.tmp"
Mon 15 Aug 2005 93,184 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\QC Historical Files\Nick Knowledge Transfer\2 - Ethicon NCR Weekly Status\~WRL1021.tmp"
Mon 15 Aug 2005 94,208 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\QC Historical Files\Nick Knowledge Transfer\2 - Ethicon NCR Weekly Status\~WRL1173.tmp"
Mon 15 Aug 2005 96,768 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\QC Historical Files\Nick Knowledge Transfer\2 - Ethicon NCR Weekly Status\~WRL2516.tmp"
Mon 15 Aug 2005 96,768 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\QC Historical Files\Nick Knowledge Transfer\2 - Ethicon NCR Weekly Status\~WRL2662.tmp"
Mon 15 Aug 2005 92,672 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\QC Historical Files\Nick Knowledge Transfer\2 - Ethicon NCR Weekly Status\~WRL3862.tmp"
Mon 15 Aug 2005 96,256 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\QC Historical Files\Nick Knowledge Transfer\2 - Ethicon NCR Weekly Status\~WRL3935.tmp"
Wed 28 Sep 2005 592,896 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL0008.tmp"
Wed 28 Sep 2005 1,779,712 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL0442.tmp"
Wed 28 Sep 2005 2,102,784 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL0469.tmp"
Wed 28 Sep 2005 1,853,952 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL0526.tmp"
Wed 28 Sep 2005 76,800 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL0605.tmp"
Mon 29 Aug 2005 844,800 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL0782.tmp"
Wed 28 Sep 2005 490,496 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL0827.tmp"
Wed 28 Sep 2005 1,787,392 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL1693.tmp"
Mon 29 Aug 2005 842,240 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL1736.tmp"
Mon 29 Aug 2005 862,720 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL1965.tmp"
Wed 28 Sep 2005 1,681,408 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL2375.tmp"
Wed 28 Sep 2005 245,248 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL2410.tmp"
Wed 28 Sep 2005 1,719,808 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL2417.tmp"
Wed 28 Sep 2005 1,778,176 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL2496.tmp"
Fri 26 Aug 2005 675,328 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL2613.tmp"
Wed 28 Sep 2005 2,101,248 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL2834.tmp"
Mon 29 Aug 2005 1,495,552 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL2885.tmp"
Wed 28 Sep 2005 2,101,760 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL3315.tmp"
Mon 29 Aug 2005 705,024 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL3542.tmp"
Fri 26 Aug 2005 1,627,136 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL3664.tmp"
Wed 28 Sep 2005 2,102,784 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL3733.tmp"
Mon 29 Aug 2005 866,304 A..H. — "C:\Work Files\Classic Work Files\Classic Work Files\My Documents\Six Sigma - Local\GE Reference\Quality Coach\~WRL3982.tmp"

Finished!






CCleaner Uninstall List:


Adobe Flash Player ActiveX
Adobe Help Center 2.0
Adobe Photoshop Elements 6.0
Adobe Premiere Elements 2.0
Adobe Reader 8.1.1
Adobe Shockwave Player
Agere Systems PCI-SV92PP Soft Modem
AiO_Scan_CDA
AiOSoftwareNPI
AVG 7.5
BufferChm
C3100
c3100_Help
CCleaner (remove only)
Customer Experience Enhancement
Destinations
DeviceManagementQFolder
DocProc
DocProcQFolder
DocumentViewer
DocumentViewerQFolder
DVD43 v3.9.0
Enhanced Multimedia Keyboard Solution
EPSON Printer Software
eSupportQFolder
ExtractNow
Fax_CDA
GdiplusUpgrade
GemMaster Mystic
Google Toolbar for Internet Explorer
HDView for Internet Explorer
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB888795)
Hotfix for Windows XP (KB891593)
Hotfix for Windows XP (KB893357)
Hotfix for Windows XP (KB895961)
Hotfix for Windows XP (KB899337)
Hotfix for Windows XP (KB899510)
Hotfix for Windows XP (KB902841)
Hotfix for Windows XP (KB906569)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB935448)
HP Boot Optimizer
HP Document Viewer 5.3
HP DVD Play 1.0
HP Imaging Device Functions 7.0
HP Photosmart and Deskjet 7.0.A
HP Photosmart Essential
HP Solution Center 7.0
HP Update
HP Web Helper
HPPhotoSmartExpress
HPProductAssistant
HpSdpAppCoreApp
HPSU306Stub
InstantShareDevicesMFC
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 5
J2SE Runtime Environment 5.0 Update 8
Java™ 6 Update 2
Java™ 6 Update 3
Java™ SE Runtime Environment 6 Update 1
JD Secure 3.1
LightScribe [removed]
LiveUpdate 3.2 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Logitech Camera Driver
Logitech QuickCam Software
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.0 Hotfix (KB930494)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Away Mode
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Standard Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
muvee autoProducer 4.5
muvee autoProducer unPlugged 1.2
NewCopy_CDA
Norton 360
NVIDIA Drivers
OCR Software by I.R.I.S 7.0
Otto
PanoStandAlone
PC-Doctor 5 for Windows
PS2
Python 2.2.3
Quicken 2007
QuickTime
Readme
Realtek High Definition Audio Driver
Remove IntelliMover Demo
Rhapsody Player Engine
Rosetta Stone 2.1.4.1A
Roxio BDAV Plugin
Roxio Creator 9 Home
Roxio Drag-to-Disc
Roxio DVD Info Pro
Roxio Easy Media Creator 9 Suite
Roxio EasyArchive
Roxio Express Labeler
Roxio Media Experience
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
Roxio RecordNow Tools
Scan
ScannerCopy
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB944653)
ShareIns
SolutionCenter
Sonic Activation Module
Sonic Backup MyPC
Sonic CinePlayer Decoder Pack
Sonic MyDVD Plus
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Spelling Dictionaries Support For Adobe Reader 8
Spybot - Search & Destroy
Status
Toolbox
TrayApp
TurboTax Deluxe Deduction Maximizer 2006
TurboTax ItsDeductible 2006
Unload
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update Rollup 2 for Windows XP Media Center Edition 2005
WD Diagnostics
WebFldrs XP
WebReg
WexTech AnswerWorks
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892050
Windows XP Hotfix - KB893066
Windows XP Media Center Edition 2005 KB925766
Xingtone Ringtone Maker






New HijackThis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:32:06 PM, on 1/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE" -quiet
O4 - HKCU\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.8.6\webbuying.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://software-dl.real.com/1017b8b918d6bc…ne_Inst_Win.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1166005466109
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (file missing)
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 10223 bytes
Hi :)

You had a password stealing trojan on your PC. The passwords stolen by the trojan can be found in this file: C:\SDFix\Data.txt. Open the file, look which passwords have been stolen and change them from a clean computer.

Step 1

Please download Combofix:

  • From BleepingComputer
  • From InfoSpyware
  • From GeeksToGo

Double-click on combofix.exe and follow the prompts.
When finished, it will produce a log for you. Save it to a convenient location.

Note: Do not mouseclick Combofix's window whilst it's running. That may cause it to stall.

Step 2

Click on Start, then Control Panel. Double click on Add or Remove Programs.

Please remove the following program(s):

  • J2SE Runtime Environment 5.0 Update 10
  • J2SE Runtime Environment 5.0 Update 5
  • J2SE Runtime Environment 5.0 Update 8
  • Java™ 6 Update 2
  • Java™ SE Runtime Environment 6 Update 1

Step 3

In your next reply, please post:

  • the Combofix log (C:\Combofix.txt)
  • a new HijackThis log
Password stealing trojan - not good. At least my data.txt password list is short. Thank you for alerting me! Unfortunately, I've encountered problems running Combofix. Sometimes, Combofix hangs up on the 2nd blue screen with only a flashing cursor (I did not click on either the 1st or 2nd blue screens). Other times, the initial prompt displays, the progress bars display after I answer the prompt, then the "Autoscan Scanning for infected files…" text is displayed with a flashing cursor on the bottom line. I tried leaving this up in this state three times (for 1 to 10 hours before aborting). One instance of trying to run Combofix produced the error "swreg.cfexe - Application Error The instruction at "0x7c9111de" referenced memory at "0x00660068". The memory could not be "read". Click OK to terminate the program." Note that I rebooted prior to each of 7 attempts at running Combofix, and I re-downloaded Combofix for one of my retries. Also note that at each reboot, I am now receiving the "Your computer is at risk. No fire wall is turned on…" message in the lower right, and then the firewall appears to automatically turn on with no click from me. This behavior is new.
Hi :)

You can try this:

Print these instructions or copy them to Notepad and save it to your desktop, as you won't be able to access internet in Safe Mode.

Please reboot into Safe Mode. To do this, go to Start > Turn off Computer, and select Restart. Rapidly tap F8 just before Windows starts to load. In the menu that appears, select Safe Mode (Without Networking).

Log in to your usual account.

Double-click on combofix.exe and follow the prompts.
When finished, it will produce a log for you. Save it to a convenient location.

Note: Do not mouseclick Combofix's window whilst it's running. That may cause it to stall.

Please post the Combofix log (C:\Combofix.txt) in your next reply, along with a new HijackThis log.
Thanks, Simon.

Combofix ran fine in safe mode. After Combofix rebooted (to normal mode), the producing log file window froze. Note that while the Combofix producing log window was displayed, a "windows installer" for Office 2003 popped up. After encoutering this frozen producing log file window, I reboot to safe mode and ran Combofix a 2nd time. Combofix ran faster (had less stage messages), it did not require a reboot this time, and it produced a log file directly in safe mode.

I then uninstalled the Java applications per your earlier "step 2" note. Below are the requested log files. Thank you for your continuing help!





Combofix log (from the 2nd run as described above):


ComboFix 08-01-04.1 - PBJG 2008-01-04 8:01:26.2 - NTFSx86 MINIMAL
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\jjllm.ini
C:\WINDOWS\system32\jjllm.ini2
C:\WINDOWS\system32\mlljj.dll
C:\WINDOWS\system32\mlljj.exe
C:\WINDOWS\system32\xxyvutr.dll
C:\WINDOWS\system32\z1

"C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe" replaces infected copy of "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
"C:\WINDOWS\system32\ctfmon .exe" replaces infected copy of "C:\WINDOWS\system32\ctfmon.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CORE




((((((((((((((((((((((((( Files Created from 2007-12-04 to 2008-01-04 )))))))))))))))))))))))))))))))
.

2008-01-03 06:45 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-02 20:14 . 2008-01-02 20:15 d——– C:\WINDOWS\ERUNT
2008-01-02 20:02 . 2008-01-02 20:02 d——– C:\Program Files\CCleaner
2007-12-30 22:51 . 2007-12-31 12:31 d——– C:\Documents and Settings\PBJG\Application Data\AVG7
2007-12-30 22:50 . 2007-12-30 22:50 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-30 22:50 . 2007-12-30 22:50 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-30 21:51 . 2007-12-30 22:52 d——– C:\Documents and Settings\All Users\Application Data\Avg7
2007-12-30 19:54 . 2007-12-30 19:54 d——– C:\Documents and Settings\PBJG\Application Data\CyberLink
2007-12-30 16:59 . 2007-12-30 16:59 d——– C:\Program Files\Trend Micro
2007-12-30 15:46 . 2007-12-30 16:18 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-30 13:08 . 2007-12-30 13:08 d——– C:\Documents and Settings\PBJG\Application Data\Uniblue
2007-12-30 10:48 . 2007-12-31 10:33 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-12-30 09:24 . 2007-12-30 13:59 262,144 –a—— C:\WINDOWS\system32\ElkCtrl .exe
2007-12-30 09:24 . 2007-12-30 13:59 221,184 –a—— C:\WINDOWS\system32\LVCOMSX .EXE
2007-12-30 07:19 . 2007-12-30 07:19 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-30 07:15 . 2007-12-30 07:15 d——– C:\WINDOWS\system32\mr9
2007-12-30 07:15 . 2007-12-30 07:42 d——– C:\WINDOWS\system32\cc9
2007-12-30 07:15 . 2007-12-30 18:16 d——– C:\WINDOWS\system32\ardCo18
2007-12-30 07:15 . 2007-12-30 07:15 d——– C:\WINDOWS\system32\aj2
2007-12-30 07:15 . 2007-12-30 07:15 d——– C:\temp\cEeer12
2007-12-30 07:14 . 2007-12-30 14:00 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-30 07:07 . 2007-12-30 23:37 d——– C:\Documents and Settings\All Users\Application Data\1Click DVD Copy
2007-12-30 07:06 . 2007-12-31 13:47 d——– C:\Documents and Settings\PBJG\Application Data\Vso
2007-12-30 07:06 . 2007-12-31 13:47 87,608 –a—— C:\Documents and Settings\PBJG\Application Data\ezpinst.exe
2007-12-30 07:06 . 2007-12-30 07:06 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2007-12-30 07:06 . 2007-12-31 13:47 47,360 –a—— C:\Documents and Settings\PBJG\Application Data\pcouffin.sys
2007-12-25 13:15 . 2007-12-25 13:15 d——– C:\Documents and Settings\All Users\Application Data\espionServerData
2007-12-24 13:26 . 2007-12-24 13:26 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-24 13:11 . 2007-12-24 13:11 d——– C:\Program Files\Common Files\Macrovision Shared
2007-12-10 18:49 . 2007-05-29 13:55 22,112 –a—— C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-12-10 18:49 . 2007-05-29 13:55 10,592 –a—— C:\WINDOWS\system32\drivers\COH_Mon.cat
2007-12-10 18:49 . 2007-05-29 13:55 705 –a—— C:\WINDOWS\system32\drivers\COH_Mon.inf

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-04 12:58 ——— d—–w C:\Program Files\Java
2008-01-04 12:48 0 —-a-w C:\WINDOWS\system32\drivers\lvuvc.hs
2007-12-31 18:47 ——— d—–w C:\Program Files\DivX
2007-12-31 05:09 ——— d—–w C:\Program Files\QuickTime
2007-12-31 03:33 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-31 03:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-31 03:32 ——— d—–w C:\Program Files\Symantec
2007-12-31 03:32 ——— d—–w C:\Program Files\Norton 360
2007-12-31 00:34 ——— d—–w C:\Program Files\MSN Messenger
2007-12-30 23:33 ——— d—–w C:\Program Files\InterActual
2007-12-30 18:58 ——— d—–w C:\Program Files\dvd43
2007-12-30 18:48 ——— d–h–w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-12-30 18:48 ——— d—–w C:\Program Files\Yahoo!
2007-12-30 18:47 ——— d—–w C:\Documents and Settings\PBJG\Application Data\Yahoo!
2007-12-30 16:14 ——— d—–w C:\Program Files\LimeWire
2007-12-30 11:16 ——— d—–w C:\Program Files\vso
2007-12-30 05:14 ——— d—–w C:\Program Files\GemMaster
2007-12-24 18:11 ——— d—–w C:\Program Files\Common Files\Adobe
2007-12-24 18:06 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-12-24 18:06 129,784 ——w C:\WINDOWS\system32\PxAFS.DLL
2007-12-24 18:06 118,520 ——w C:\WINDOWS\system32\pxinsi64.exe
2007-12-24 18:06 116,472 ——w C:\WINDOWS\system32\pxcpyi64.exe
2007-12-06 23:03 71,168 —-a-w C:\WINDOWS\system32\LxrJD31s.exe
2007-12-06 23:03 69,824 —-a-w C:\WINDOWS\system32\drivers\LxrJD31d.sys
2007-12-06 23:03 61,440 —-a-w C:\WINDOWS\system32\LxrJD20Sat.dll
2007-12-06 23:03 249,856 —-a-w C:\WINDOWS\system32\LxrJD31.dll
2007-12-06 23:03 163,840 —-a-w C:\WINDOWS\system32\LxrJD31c.exe
2007-12-06 23:03 146,432 —-a-w C:\WINDOWS\system32\LxrJD31p.exe
2007-11-14 08:19 ——— d—–w C:\Program Files\DISC
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-04 22:36 ——— d—–w C:\Program Files\Western Digital Technologies
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 —-a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 —-a-w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 —-a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 —-a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 —-a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 —-a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 —-a-w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 —-a-w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 —-a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 —-a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 —-a-w C:\WINDOWS\system32\dllcache\ieakui.dll
.
—-a-w			61,440 2007-12-30 19:00:44  C:\hp\KBD\KBD .EXE
—-a-w			67,488 2007-12-30 18:59:42  C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy .exe
—-a-w			39,792 2007-12-30 18:59:39  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w		   221,184 2007-12-30 18:59:32  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe
—-a-w		   115,816 2007-12-30 18:59:40  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   694,272 2007-12-30 18:59:30  C:\Program Files\dvd43\dvd43_tray .exe
—-a-w		   579,072 2007-12-31 05:10:03  C:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w		   389,120 2007-12-30 18:59:19  C:\Program Files\Logitech\Video\CameraAssistant .exe
—-a-w			73,728 2007-12-30 18:59:20  C:\Program Files\Logitech\Video\InstallHelper .exe
—-a-w		   196,608 2007-12-30 18:59:52  C:\Program Files\Logitech\Video\ManifestEngine .exe
—-a-w		 5,674,352 2007-12-30 19:00:11  C:\Program Files\MSN Messenger\MsnMsgr .Exe
—-a-w		 1,116,920 2007-12-30 18:59:36  C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc .exe
—-a-w		   102,400 2007-12-30 18:59:32  C:\Program Files\Roxio\Media Experience\DMXLauncher .exe
—-a-w		   224,248 2007-12-30 18:48:30  C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
—-a-w			64,512 2007-12-31 03:35:13  C:\WINDOWS\ehome\ehtray .exe
—-a-w		   237,568 2007-12-30 18:58:41  C:\WINDOWS\SMINST\RECGUARD .EXE
—-a-w		   262,144 2007-12-30 18:59:23  C:\WINDOWS\system32\ElkCtrl .exe
—-a-w		   221,184 2007-12-30 18:59:15  C:\WINDOWS\system32\LVCOMSX .EXE
—-a-w			99,840 2007-12-30 18:59:25  C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2F1 .EXE


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{63a08ac4-f4e8-442f-83aa-d9ccd605a552}]
C:\WINDOWS\system32\gbpumdk.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .exe" [ ]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 19:19 77312 C:\WINDOWS\arpwrmsg.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-01-24 13:15 7311360]
"nwiz"="nwiz.exe" [2006-01-24 13:15 1519616 C:\WINDOWS\system32\nwiz.exe]
"PCDrProfiler"="" []
"RTHDCPL"="RTHDCPL.EXE" [2006-08-14 13:00 16050176 C:\WINDOWS\RTHDCPL.exe]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-12-30 22:35 49152]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-30 22:50 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-04 00:12:18]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-01 20:06]
S2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 00:45]
S3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-07-28 12:37]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7b2cf876-6cd6-11db-b63c-0017313595a3}]
\Shell\AutoRun\command - L:\JDSecure\Windows\JDSecure31.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-12-08 17:39:29 C:\WINDOWS\Tasks\RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 0~0.job"
- C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\Main\Roxio_Central33.exe?Sched RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 0~0
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-04 08:05:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-04 8:05:44
ComboFix-quarantined-files.txt 2008-01-04 13:05:41
.
2007-12-13 08:05:09 — E O F —








New HijackThis log:



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:07:20 AM, on 1/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: (no name) - {63a08ac4-f4e8-442f-83aa-d9ccd605a552} - C:\WINDOWS\system32\gbpumdk.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\webhelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE" -quiet
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://software-dl.real.com/1017b8b918d6bc…ne_Inst_Win.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1166005466109
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (file missing)
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 8850 bytes
Hi :)

Step 1

Open Notepad (Go to Start > Run, type Notepad and hit Enter), and copy/paste the text in the quotebox below into it:

File::

C:\WINDOWS\system32\d3d9caps.dat
C:\WINDOWS\system32\drivers\lvuvc.hs

Folder::

C:\WINDOWS\system32\mr9
C:\WINDOWS\system32\cc9
C:\WINDOWS\system32\ardCo18
C:\WINDOWS\system32\aj2
C:\temp\cEeer12

Registry::

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{63a08ac4-f4e8-442f-83aa-d9ccd605a552}]

RenV::

—-a-w			61,440 2007-12-30 19:00:44  C:\hp\KBD\KBD .EXE
—-a-w			67,488 2007-12-30 18:59:42  C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy .exe
—-a-w			39,792 2007-12-30 18:59:39  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w		   221,184 2007-12-30 18:59:32  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe
—-a-w		   115,816 2007-12-30 18:59:40  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   694,272 2007-12-30 18:59:30  C:\Program Files\dvd43\dvd43_tray .exe
—-a-w		   579,072 2007-12-31 05:10:03  C:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w		   389,120 2007-12-30 18:59:19  C:\Program Files\Logitech\Video\CameraAssistant .exe
—-a-w			73,728 2007-12-30 18:59:20  C:\Program Files\Logitech\Video\InstallHelper .exe
—-a-w		   196,608 2007-12-30 18:59:52  C:\Program Files\Logitech\Video\ManifestEngine .exe
—-a-w		 5,674,352 2007-12-30 19:00:11  C:\Program Files\MSN Messenger\MsnMsgr .Exe
—-a-w		 1,116,920 2007-12-30 18:59:36  C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc .exe
—-a-w		   102,400 2007-12-30 18:59:32  C:\Program Files\Roxio\Media Experience\DMXLauncher .exe
—-a-w		   224,248 2007-12-30 18:48:30  C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
—-a-w			64,512 2007-12-31 03:35:13  C:\WINDOWS\ehome\ehtray .exe
—-a-w		   237,568 2007-12-30 18:58:41  C:\WINDOWS\SMINST\RECGUARD .EXE
—-a-w		   262,144 2007-12-30 18:59:23  C:\WINDOWS\system32\ElkCtrl .exe
—-a-w		   221,184 2007-12-30 18:59:15  C:\WINDOWS\system32\LVCOMSX .EXE
—-a-w			99,840 2007-12-30 18:59:25  C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2F1 .EXE

Click on File > Save as….

In the File Name box, copy/paste CFScript.txt (Note: Do not change the filename!)

Click Save (Save the CFScript in the same location as Combofix.exe)

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe.
It will create a log. Be sure to save it to a convenient location.

Step 2

Please do an online scan with Kaspersky WebScanner.

Click on Kaspersky Online Scanner. On the welcome screen, click Accept.

You will be promted to install an ActiveX component from Kaspersky, click Install.

  • The program will launch and then begin downloading the latest definition files.
  • Once the files have been downloaded click on Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:

  • Scan using the following Anti-Virus database:

    Extended (if available, otherwise Standard)

  • Scan Options:

    Scan Archives
    Scan Mail Bases

  • Click OK.
  • Now under Select a Target to Scan:

    Select My Computer.

  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button and save the file to your desktop.

Step 3

In your next reply, please post:

  • the Combofix log (C:\Combofix.txt)
  • the Kaspersky Online Scan report
  • a new HijackThis log
New Combofix log via CFScript:


ComboFix 08-01-04.1 - PBJG 2008-01-05 16:39:33.3 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.756 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\PBJG\Desktop\CFScript.txt

FILE
C:\WINDOWS\system32\d3d9caps.dat
C:\WINDOWS\system32\drivers\lvuvc.hs
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\temp\cEeer12
C:\temp\cEeer12\skAt.log
C:\WINDOWS\system32\aj2
C:\WINDOWS\system32\aj2\bumebrpl5.exe
C:\WINDOWS\system32\ardCo18
C:\WINDOWS\system32\cc9
C:\WINDOWS\system32\d3d9caps.dat
C:\WINDOWS\system32\drivers\lvuvc.hs
C:\WINDOWS\system32\mr9
C:\WINDOWS\system32\mr9\gyreo83122.exe
D:\Autorun.inf
J:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2007-12-05 to 2008-01-05 )))))))))))))))))))))))))))))))
.

2008-01-03 06:45 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-02 20:14 . 2008-01-02 20:15 d——– C:\WINDOWS\ERUNT
2008-01-02 20:02 . 2008-01-02 20:02 d——– C:\Program Files\CCleaner
2007-12-30 22:51 . 2007-12-31 12:31 d——– C:\Documents and Settings\PBJG\Application Data\AVG7
2007-12-30 22:50 . 2007-12-30 22:50 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-30 22:50 . 2007-12-30 22:50 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-30 21:51 . 2007-12-30 22:52 d——– C:\Documents and Settings\All Users\Application Data\Avg7
2007-12-30 19:54 . 2007-12-30 19:54 d——– C:\Documents and Settings\PBJG\Application Data\CyberLink
2007-12-30 16:59 . 2007-12-30 16:59 d——– C:\Program Files\Trend Micro
2007-12-30 15:46 . 2007-12-30 16:18 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-30 13:08 . 2007-12-30 13:08 d——– C:\Documents and Settings\PBJG\Application Data\Uniblue
2007-12-30 09:24 . 2007-12-30 13:59 262,144 –a—— C:\WINDOWS\system32\ElkCtrl .exe
2007-12-30 09:24 . 2007-12-30 13:59 221,184 –a—— C:\WINDOWS\system32\LVCOMSX .EXE
2007-12-30 07:19 . 2007-12-30 07:19 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-30 07:14 . 2007-12-30 14:00 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-30 07:07 . 2007-12-30 23:37 d——– C:\Documents and Settings\All Users\Application Data\1Click DVD Copy
2007-12-30 07:06 . 2007-12-31 13:47 d——– C:\Documents and Settings\PBJG\Application Data\Vso
2007-12-30 07:06 . 2007-12-31 13:47 87,608 –a—— C:\Documents and Settings\PBJG\Application Data\ezpinst.exe
2007-12-30 07:06 . 2007-12-30 07:06 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2007-12-30 07:06 . 2007-12-31 13:47 47,360 –a—— C:\Documents and Settings\PBJG\Application Data\pcouffin.sys
2007-12-25 13:15 . 2007-12-25 13:15 d——– C:\Documents and Settings\All Users\Application Data\espionServerData
2007-12-24 13:26 . 2007-12-24 13:26 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-24 13:11 . 2007-12-24 13:11 d——– C:\Program Files\Common Files\Macrovision Shared
2007-12-10 18:49 . 2007-05-29 13:55 22,112 –a—— C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-12-10 18:49 . 2007-05-29 13:55 10,592 –a—— C:\WINDOWS\system32\drivers\COH_Mon.cat
2007-12-10 18:49 . 2007-05-29 13:55 705 –a—— C:\WINDOWS\system32\drivers\COH_Mon.inf

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-04 12:58 ——— d—–w C:\Program Files\Java
2007-12-31 18:47 ——— d—–w C:\Program Files\DivX
2007-12-31 05:09 ——— d—–w C:\Program Files\QuickTime
2007-12-31 03:33 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-31 03:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-31 03:32 ——— d—–w C:\Program Files\Symantec
2007-12-31 03:32 ——— d—–w C:\Program Files\Norton 360
2007-12-31 00:34 ——— d—–w C:\Program Files\MSN Messenger
2007-12-30 23:33 ——— d—–w C:\Program Files\InterActual
2007-12-30 18:58 ——— d—–w C:\Program Files\dvd43
2007-12-30 18:48 ——— d–h–w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-12-30 18:48 ——— d—–w C:\Program Files\Yahoo!
2007-12-30 18:47 ——— d—–w C:\Documents and Settings\PBJG\Application Data\Yahoo!
2007-12-30 16:14 ——— d—–w C:\Program Files\LimeWire
2007-12-30 11:16 ——— d—–w C:\Program Files\vso
2007-12-30 05:14 ——— d—–w C:\Program Files\GemMaster
2007-12-24 18:11 ——— d—–w C:\Program Files\Common Files\Adobe
2007-12-24 18:06 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-12-24 18:06 129,784 ——w C:\WINDOWS\system32\PxAFS.DLL
2007-12-24 18:06 118,520 ——w C:\WINDOWS\system32\pxinsi64.exe
2007-12-24 18:06 116,472 ——w C:\WINDOWS\system32\pxcpyi64.exe
2007-12-06 23:03 71,168 —-a-w C:\WINDOWS\system32\LxrJD31s.exe
2007-12-06 23:03 69,824 —-a-w C:\WINDOWS\system32\drivers\LxrJD31d.sys
2007-12-06 23:03 61,440 —-a-w C:\WINDOWS\system32\LxrJD20Sat.dll
2007-12-06 23:03 249,856 —-a-w C:\WINDOWS\system32\LxrJD31.dll
2007-12-06 23:03 163,840 —-a-w C:\WINDOWS\system32\LxrJD31c.exe
2007-12-06 23:03 146,432 —-a-w C:\WINDOWS\system32\LxrJD31p.exe
2007-11-14 08:19 ——— d—–w C:\Program Files\DISC
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 —-a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 —-a-w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 —-a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 —-a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 —-a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 —-a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 —-a-w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 —-a-w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 —-a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 —-a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 —-a-w C:\WINDOWS\system32\dllcache\ieakui.dll
.
—-a-w			67,488 2007-12-30 18:59:42  C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy .exe
—-a-w			39,792 2007-12-30 18:59:39  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w		   221,184 2007-12-30 18:59:32  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe
—-a-w		   115,816 2007-12-30 18:59:40  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   694,272 2007-12-30 18:59:30  C:\Program Files\dvd43\dvd43_tray .exe
—-a-w		   579,072 2007-12-31 05:10:03  C:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w		   389,120 2007-12-30 18:59:19  C:\Program Files\Logitech\Video\CameraAssistant .exe
—-a-w			73,728 2007-12-30 18:59:20  C:\Program Files\Logitech\Video\InstallHelper .exe
—-a-w		   196,608 2007-12-30 18:59:52  C:\Program Files\Logitech\Video\ManifestEngine .exe
—-a-w		 5,674,352 2007-12-30 19:00:11  C:\Program Files\MSN Messenger\MsnMsgr .Exe
—-a-w		 1,116,920 2007-12-30 18:59:36  C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc .exe
—-a-w		   102,400 2007-12-30 18:59:32  C:\Program Files\Roxio\Media Experience\DMXLauncher .exe
—-a-w		   224,248 2007-12-30 18:48:30  C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
—-a-w			64,512 2007-12-31 03:35:13  C:\WINDOWS\ehome\ehtray .exe
—-a-w		   237,568 2007-12-30 18:58:41  C:\WINDOWS\SMINST\RECGUARD .EXE
—-a-w		   262,144 2007-12-30 18:59:23  C:\WINDOWS\system32\ElkCtrl .exe
—-a-w		   221,184 2007-12-30 18:59:15  C:\WINDOWS\system32\LVCOMSX .EXE
—-a-w			99,840 2007-12-30 18:59:25  C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2F1 .EXE


((((((((((((((((((((((((((((( snapshot@2008-01-04_ 8.05.20.71 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-04 00:10:35 12,288 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-01-04 13:11:49 12,288 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-01-04 00:10:35 135,168 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-01-04 13:11:49 135,168 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-01-04 00:10:35 11,264 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-01-04 13:11:49 11,264 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-01-04 00:10:35 27,136 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-01-04 13:11:49 27,136 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-01-04 00:10:35 4,096 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-01-04 13:11:49 4,096 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-01-04 00:10:35 794,624 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-01-04 13:11:49 794,624 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-01-04 00:10:35 249,856 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-01-04 13:11:49 249,856 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-01-04 00:10:35 23,040 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-01-04 13:11:49 23,040 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-01-04 00:10:35 286,720 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-01-04 13:11:49 286,720 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-01-04 00:10:35 409,600 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-01-04 13:11:49 409,600 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2004-08-09 21:00:00 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .exe" [ ]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-09 16:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 19:19 77312 C:\WINDOWS\arpwrmsg.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-01-24 13:15 7311360]
"nwiz"="nwiz.exe" [2006-01-24 13:15 1519616 C:\WINDOWS\system32\nwiz.exe]
"PCDrProfiler"="" []
"RTHDCPL"="RTHDCPL.EXE" [2006-08-14 13:00 16050176 C:\WINDOWS\RTHDCPL.exe]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-12-30 22:35 49152]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-30 22:50 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-04 00:12:18]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-01 20:06]
S2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 00:45]
S3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-07-28 12:37]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7b2cf876-6cd6-11db-b63c-0017313595a3}]
\Shell\AutoRun\command - L:\JDSecure\Windows\JDSecure31.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-12-08 17:39:29 C:\WINDOWS\Tasks\RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 0~0.job"
- C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\Main\Roxio_Central33.exe?Sched RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 0~0
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-05 16:43:17
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-05 16:43:47
ComboFix-quarantined-files.txt 2008-01-05 21:43:46
ComboFix2.txt 2008-01-04 13:05:44
.
2007-12-13 08:05:09 — E O F —






Kaspersky Online Scan Report:


——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Saturday, January 05, 2008 8:14:23 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 5/01/2008
Kaspersky Anti-Virus database records: 502954
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan Statistics:
Total number of scanned objects: 158873
Number of viruses found: 14
Number of infected objects: 37
Number of suspicious objects: 2
Duration of the scan process: 02:22:50

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WebBuyingAssistant.zip/v1.8.6/wbuninst.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WebBuyingAssistant.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-01-05_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp(2)\25D6183D.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp(3)\6656576D.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp(4)\DD80A265.TMP Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\PBJG\Application Data\Roxio\MediaManager9\Album.ldb Object is locked skipped
C:\Documents and Settings\PBJG\Application Data\Roxio\MediaManager9\Album.psod Object is locked skipped
C:\Documents and Settings\PBJG\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\PBJG\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\PBJG\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\PBJG\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\PBJG\Local Settings\History\History.IE5\MSHist012008010520080106\index.dat Object is locked skipped
C:\Documents and Settings\PBJG\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\PBJG\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\PBJG\ntuser.dat Object is locked skipped
C:\Documents and Settings\PBJG\ntuser.dat.LOG Object is locked skipped
C:\QooBox\Quarantine\C\Program Files\HP\HP Software Update\HPWuSchd2.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\aj2\bumebrpl5.exe.vir Infected: Trojan.Win32.Pakes.bvs skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ctfmon.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mlljj.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mr9\gyreo83122.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mr9\gyreo83122.exe.vir NSIS: infected - 1 skipped
C:\QooBox\Quarantine\catchme2008-01-04_ 74919.79.zip/mlljj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dih skipped
C:\QooBox\Quarantine\catchme2008-01-04_ 74919.79.zip/xxyvutr.dll Infected: Trojan-Downloader.Win32.Small.hlf skipped
C:\QooBox\Quarantine\catchme2008-01-04_ 74919.79.zip ZIP: infected - 2 skipped
C:\SDFix\backups\backups.zip/backups/rtereprege.html Infected: Trojan-Clicker.HTML.IFrame.dn skipped
C:\SDFix\backups\backups.zip/backups/winlogon.exe Infected: not-a-virus:PSWTool.Win32.PassView.p skipped
C:\SDFix\backups\backups.zip ZIP: infected - 2 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP540\A0085060.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP540\A0085061.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP545\A0092646.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP545\A0092674.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092688.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092696.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092704.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092705.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092706.Exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092707.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092709.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092710.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092711.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092712.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092713.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092714.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092715.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092716.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092717.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092718.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092719.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092720.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092721.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092722.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092723.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092725.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092727.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092728.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092729.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092730.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP546\A0092731.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092734.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092735.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092736.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092737.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092738.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092739.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092740.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092741.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092742.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092743.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092744.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092745.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092746.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092747.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092748.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092749.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092750.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092751.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092752.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092753.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092754.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092755.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092756.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092757.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092758.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092759.Exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092760.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092761.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092762.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092775.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092783.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092784.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092786.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092787.Exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092788.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092790.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092791.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092792.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092793.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092794.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092795.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092796.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092797.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092801.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092802.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP547\A0092803.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092804.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092806.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092808.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092809.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092810.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092812.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092813.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092815.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092816.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092817.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092818.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092828.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092830.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092832.Exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092833.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092835.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092837.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092838.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092841.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092844.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092846.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092847.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092848.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092849.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092850.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092851.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092853.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092855.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092857.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092858.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092859.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092860.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092862.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092864.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092875.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092889.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092890.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092892.Exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092893.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092895.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092897.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092898.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092900.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092901.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092902.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092903.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092904.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092905.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092906.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092907.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092909.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092910.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092912.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092914.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092915.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092916.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092917.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092918.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092923.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092932.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092933.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092934.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092935.Exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092937.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092938.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092939.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092940.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092941.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092942.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092943.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092945.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092946.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092949.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092951.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092953.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092954.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092956.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092957.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092958.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092959.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092962.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092965.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092967.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092968.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092970.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092972.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP548\A0092979.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093026.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093027.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093029.Exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093030.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093032.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093034.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093035.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093037.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093039.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093042.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093043.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093044.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093045.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093047.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093048.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093051.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093052.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093053.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093054.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093055.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093057.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093059.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093062.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093072.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP549\A0093127.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093194.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093211.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093221.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093222.Exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093223.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093226.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093228.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093229.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093234.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093235.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093236.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093237.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093238.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093240.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093241.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093243.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093245.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093246.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093247.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093248.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093249.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093251.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093253.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093255.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093266.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093292.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093292.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093293.dll Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093294.dll Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP550\A0093341.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093345.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093346.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093347.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093348.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093349.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093350.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093351.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093352.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093353.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093354.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093355.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093356.Exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093357.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093358.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093359.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093360.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093361.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093362.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093363.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093364.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093365.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093366.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093367.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093368.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093369.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093370.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093371.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093372.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093373.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093374.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093375.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093376.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093377.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093378.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093379.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093380.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093381.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093382.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093383.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093384.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093385.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093386.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093387.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093388.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093389.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093390.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093391.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093392.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093393.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP551\A0093399.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093575.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093577.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093578.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093579.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093589.sys Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093594.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093596.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093597.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093598.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093599.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093606.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093607.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093608.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093609.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093610.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093611.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093622.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093624.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093625.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093626.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093637.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093639.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093640.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093641.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093643.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093648.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093650.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093651.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093652.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093653.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093654.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093655.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093666.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093668.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093669.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093670.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093671.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093672.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093744.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093746.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093747.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093748.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093749.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093750.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0093751.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0094182.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0094183.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP552\A0094185.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP553\A0094195.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP553\A0094196.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP553\A0094197.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP553\A0094198.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP553\A0094199.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP553\A0094200.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP553\A0094221.dll Infected: not-a-virus:AdWare.Win32.Agent.wx skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP553\A0096494.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP553\A0096507.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP553\A0096730.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP553\A0096733.exe Infected: not-a-virus:PSWTool.Win32.PassView.p skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP553\A0096739.exe Infected: not-a-virus:PSWTool.Win32.PassView.p skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP555\A0096892.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP557\A0096937.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP558\A0096977.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP558\A0097018.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP559\A0097056.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP559\A0097065.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP559\A0097066.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP565\A0097881.exe Infected: Trojan.Win32.Pakes.bvs skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP565\A0097882.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP565\A0097882.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP566\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{79242D8D-193E-4A81-99F8-8B664361AAF5}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{1A7FB20C-89F4-49A1-B696-B573205A3CFD}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TEMP\JET5634.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\Work Files\GE Work Files\GE Email Archive\Archive.pst/~~Older Archive Folders/Rcvd Email Archive/26 Feb 1998 13:44 from Morrison, Patty (ED&C;,IM):Resend ED&C; IM /IMNEWS~1.DOC Infected: Virus.MSWord.Niceday skipped
C:\Work Files\GE Work Files\GE Email Archive\Archive.pst/~~Older Archive Folders/Rcvd Email Archive/26 Feb 1998 13:44 from Morrison, Patty (ED&C;,IM):Resend ED&C; IM /IMNEWS~2.DOC Infected: Virus.MSWord.Niceday skipped
C:\Work Files\GE Work Files\GE Email Archive\Archive.pst/~~Older Archive Folders/Rcvd Email Archive/05 Feb 1998 20:35 to Fischer, Dick; Grygiel, Pete; Jefferson, Th/BLM_FI~1.DOC Infected: Virus.MSWord.Niceday skipped
C:\Work Files\GE Work Files\GE Email Archive\Archive.pst/~~Older Archive Folders/Rcvd Email Archive/07 Nov 1997 19:14 from Lavigne, Eva (ED&C;,FIN):T&L; in a bag remi/REIMIN~1.DOC Infected: Virus.MSWord.Cap skipped
C:\Work Files\GE Work Files\GE Email Archive\Archive.pst/~~Older Archive Folders/Rcvd Email Archive/07 Nov 1997 17:10 from Nooney, Sue (ED&C;,MKT):/LTORGANN.DOC Infected: Virus.MSWord.Cap skipped
C:\Work Files\GE Work Files\GE Email Archive\Archive.pst/~~Older Archive Folders/Rcvd Email Archive/03 Nov 1997 19:46 to Adcock, Bob; Anderson, Marsha; Balonis,Denn/IMMEDI~1.DOC Infected: Virus.MSWord.Cap skipped
C:\Work Files\GE Work Files\GE Email Archive\Archive.pst/~~Older Archive Folders/Sent Items Archive/18 Oct 1997 18:09 to Grygiel, Brenda:Fun /ATT1.EXE Infected: not-virus:BadJoke.Win16.Stupid.a skipped
C:\Work Files\GE Work Files\GE Email Archive\Archive.pst Mail MS Mail: infected - 7 skipped
C:\Work Files\GE Work Files\GE Email Archive\outlook.ost/Offline store/Root - Mailbox/IPM_SUBTREE/Deleted Items/15 Mar 2004 12:47 from Wesa, Richard (GE Consumer & Industrial):/Gift.rar Infected: Email-Worm.Win32.Bagle.o skipped
C:\Work Files\GE Work Files\GE Email Archive\outlook.ost/Offline store/Root - Mailbox/IPM_SUBTREE/Deleted Items/16 Mar 2004 04:56 from [removed]:Important notify about yo/Readme.zip/yxwqblwia.exe Infected: Email-Worm.Win32.Bagle.o skipped
C:\Work Files\GE Work Files\GE Email Archive\outlook.ost/Offline store/Root - Mailbox/IPM_SUBTREE/Deleted Items/16 Mar 2004 04:56 from [removed]:Important notify about yo/Readme.zip Infected: Email-Worm.Win32.Bagle.o skipped
C:\Work Files\GE Work Files\GE Email Archive\outlook.ost/Offline store/Root - Mailbox/IPM_SUBTREE/Deleted Items/15 Mar 2004 12:54 from System Administrator:Undeliverable:Re: Ya/15 Mar 2004 12:50 from Grygiel, Pete (GE Consumer & Industrial):/details.rar Infected: Email-Worm.Win32.Bagle.o skipped
C:\Work Files\GE Work Files\GE Email Archive\outlook.ost/Offline store/Root - Mailbox/IPM_SUBTREE/Deleted Items/15 Mar 2004 10:32 from [removed]:Re: Thanks :)/Info.zip/kpvhdayfb.exe Infected: Email-Worm.Win32.Bagle.o skipped
C:\Work Files\GE Work Files\GE Email Archive\outlook.ost/Offline store/Root - Mailbox/IPM_SUBTREE/Deleted Items/15 Mar 2004 10:32 from [removed]:Re: Thanks :)/Info.zip Infected: Email-Worm.Win32.Bagle.o skipped
C:\Work Files\GE Work Files\GE Email Archive\outlook.ost Mail MS Mail: infected - 6 skipped
J:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP477\A0067642.exe/data0115 Infected: not-a-virus:AdWare.Win32.TopMoxie.e skipped
J:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP477\A0067642.exe NSIS: infected - 1 skipped

Scan process completed.





New HijackThis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:16:51 PM, on 1/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\webhelper.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE" -quiet
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://software-dl.real.com/1017b8b918d6bc…ne_Inst_Win.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1166005466109
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (file missing)
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 10070 bytes
Hi :)

Step 1

Open HijackThis, perform a scan and put a check next to the following items (if present):

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u


Close all programs except HijackThis and click on Fix checked.

Step 2

Please delete your current copy of Combofix, and download the newest version:

  • From BleepingComputer
  • From InfoSpyware
  • From GeeksToGo

Open Notepad (Go to Start > Run, type Notepad and hit Enter), and copy/paste the text in the quotebox below into it:

RenV::

—-a-w			67,488 2007-12-30 18:59:42  C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy .exe
—-a-w			39,792 2007-12-30 18:59:39  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w		   221,184 2007-12-30 18:59:32  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe
—-a-w		   115,816 2007-12-30 18:59:40  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   694,272 2007-12-30 18:59:30  C:\Program Files\dvd43\dvd43_tray .exe
—-a-w		   579,072 2007-12-31 05:10:03  C:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w		   389,120 2007-12-30 18:59:19  C:\Program Files\Logitech\Video\CameraAssistant .exe
—-a-w			73,728 2007-12-30 18:59:20  C:\Program Files\Logitech\Video\InstallHelper .exe
—-a-w		   196,608 2007-12-30 18:59:52  C:\Program Files\Logitech\Video\ManifestEngine .exe
—-a-w		 5,674,352 2007-12-30 19:00:11  C:\Program Files\MSN Messenger\MsnMsgr .Exe
—-a-w		 1,116,920 2007-12-30 18:59:36  C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc .exe
—-a-w		   102,400 2007-12-30 18:59:32  C:\Program Files\Roxio\Media Experience\DMXLauncher .exe
—-a-w		   224,248 2007-12-30 18:48:30  C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
—-a-w			64,512 2007-12-31 03:35:13  C:\WINDOWS\ehome\ehtray .exe
—-a-w		   237,568 2007-12-30 18:58:41  C:\WINDOWS\SMINST\RECGUARD .EXE
—-a-w		   262,144 2007-12-30 18:59:23  C:\WINDOWS\system32\ElkCtrl .exe
—-a-w		   221,184 2007-12-30 18:59:15  C:\WINDOWS\system32\LVCOMSX .EXE
—-a-w			99,840 2007-12-30 18:59:25  C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2F1 .EXE

Click on File > Save as….

In the File Name box, copy/paste CFScript.txt (Note: Do not change the filename!)

Click Save (Save the CFScript in the same location as Combofix.exe)

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe.
It will create a log. Post it in your next reply, along with a new HijackThis log. Also tell me how your computer is currently running.
I successfully fixed the two checked HijackThis items, downloaded a new Combofix and ran it via the new CFScript text in safe mode, and a generated a new HijackThis log in normal mode. My computer currently appears to be running normally as far as I can tell with no IE popups, firewall messages, or performance issues. My start up applications are gone (likely damage from the malware), but I can easily reinstall them once my PC is confirmed to be clean. Below are the requested new log files:



New Combofix log (safe mode) after new download of Combofix and via new CFScript:


ComboFix 08-01-04.1 - PBJG 2008-01-06 15:20:17.4 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.757 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\PBJG\Desktop\CFScript.txt
.

((((((((((((((((((((((((( Files Created from 2007-12-06 to 2008-01-06 )))))))))))))))))))))))))))))))
.

2008-01-05 17:18 . 2008-01-05 17:18 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-01-05 17:18 . 2008-01-05 17:18 d——– C:\WINDOWS\LastGood
2008-01-05 17:18 . 2008-01-05 17:18 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-05 16:51 . 2008-01-05 16:52 0 –a—— C:\WINDOWS\system32\drivers\lvuvc.hs
2008-01-03 06:45 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-02 20:14 . 2008-01-02 20:15 d——– C:\WINDOWS\ERUNT
2008-01-02 20:02 . 2008-01-02 20:02 d——– C:\Program Files\CCleaner
2007-12-30 22:51 . 2007-12-31 12:31 d——– C:\Documents and Settings\PBJG\Application Data\AVG7
2007-12-30 22:50 . 2007-12-30 22:50 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-30 22:50 . 2007-12-30 22:50 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-30 21:51 . 2007-12-30 22:52 d——– C:\Documents and Settings\All Users\Application Data\Avg7
2007-12-30 19:54 . 2007-12-30 19:54 d——– C:\Documents and Settings\PBJG\Application Data\CyberLink
2007-12-30 16:59 . 2007-12-30 16:59 d——– C:\Program Files\Trend Micro
2007-12-30 15:46 . 2007-12-30 16:18 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-30 13:08 . 2007-12-30 13:08 d——– C:\Documents and Settings\PBJG\Application Data\Uniblue
2007-12-30 09:24 . 2007-12-30 13:59 262,144 –a—— C:\WINDOWS\system32\ElkCtrl .exe
2007-12-30 09:24 . 2007-12-30 13:59 221,184 –a—— C:\WINDOWS\system32\LVCOMSX .EXE
2007-12-30 07:19 . 2007-12-30 07:19 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-30 07:14 . 2007-12-30 14:00 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-30 07:07 . 2007-12-30 23:37 d——– C:\Documents and Settings\All Users\Application Data\1Click DVD Copy
2007-12-30 07:06 . 2007-12-31 13:47 d——– C:\Documents and Settings\PBJG\Application Data\Vso
2007-12-30 07:06 . 2007-12-31 13:47 87,608 –a—— C:\Documents and Settings\PBJG\Application Data\ezpinst.exe
2007-12-30 07:06 . 2007-12-30 07:06 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2007-12-30 07:06 . 2007-12-31 13:47 47,360 –a—— C:\Documents and Settings\PBJG\Application Data\pcouffin.sys
2007-12-25 13:15 . 2007-12-25 13:15 d——– C:\Documents and Settings\All Users\Application Data\espionServerData
2007-12-24 13:26 . 2007-12-24 13:26 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-24 13:11 . 2007-12-24 13:11 d——– C:\Program Files\Common Files\Macrovision Shared
2007-12-10 18:49 . 2007-05-29 13:55 22,112 –a—— C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-12-10 18:49 . 2007-05-29 13:55 10,592 –a—— C:\WINDOWS\system32\drivers\COH_Mon.cat
2007-12-10 18:49 . 2007-05-29 13:55 705 –a—— C:\WINDOWS\system32\drivers\COH_Mon.inf

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-04 12:58 ——— d—–w C:\Program Files\Java
2007-12-31 18:47 ——— d—–w C:\Program Files\DivX
2007-12-31 05:09 ——— d—–w C:\Program Files\QuickTime
2007-12-31 03:33 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-31 03:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-31 03:32 ——— d—–w C:\Program Files\Symantec
2007-12-31 03:32 ——— d—–w C:\Program Files\Norton 360
2007-12-31 00:34 ——— d—–w C:\Program Files\MSN Messenger
2007-12-30 23:33 ——— d—–w C:\Program Files\InterActual
2007-12-30 18:58 ——— d—–w C:\Program Files\dvd43
2007-12-30 18:48 ——— d–h–w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-12-30 18:48 ——— d—–w C:\Program Files\Yahoo!
2007-12-30 18:47 ——— d—–w C:\Documents and Settings\PBJG\Application Data\Yahoo!
2007-12-30 16:14 ——— d—–w C:\Program Files\LimeWire
2007-12-30 11:16 ——— d—–w C:\Program Files\vso
2007-12-30 05:14 ——— d—–w C:\Program Files\GemMaster
2007-12-24 18:11 ——— d—–w C:\Program Files\Common Files\Adobe
2007-12-24 18:06 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-12-24 18:06 129,784 ——w C:\WINDOWS\system32\PxAFS.DLL
2007-12-24 18:06 118,520 ——w C:\WINDOWS\system32\pxinsi64.exe
2007-12-24 18:06 116,472 ——w C:\WINDOWS\system32\pxcpyi64.exe
2007-12-06 23:03 71,168 —-a-w C:\WINDOWS\system32\LxrJD31s.exe
2007-12-06 23:03 69,824 —-a-w C:\WINDOWS\system32\drivers\LxrJD31d.sys
2007-12-06 23:03 61,440 —-a-w C:\WINDOWS\system32\LxrJD20Sat.dll
2007-12-06 23:03 249,856 —-a-w C:\WINDOWS\system32\LxrJD31.dll
2007-12-06 23:03 163,840 —-a-w C:\WINDOWS\system32\LxrJD31c.exe
2007-12-06 23:03 146,432 —-a-w C:\WINDOWS\system32\LxrJD31p.exe
2007-11-14 08:19 ——— d—–w C:\Program Files\DISC
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 —-a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 —-a-w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 —-a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 —-a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 —-a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 —-a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 —-a-w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 —-a-w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 —-a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 —-a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 —-a-w C:\WINDOWS\system32\dllcache\ieakui.dll
.
——w			39,792 2007-12-30 18:59:39  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w		   221,184 2007-12-30 18:59:32  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe
—-a-w		   115,816 2007-12-30 18:59:40  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   694,272 2007-12-30 18:59:30  C:\Program Files\dvd43\dvd43_tray .exe
—-a-w		   579,072 2007-12-31 05:10:03  C:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w		   389,120 2007-12-30 18:59:19  C:\Program Files\Logitech\Video\CameraAssistant .exe
—-a-w			73,728 2007-12-30 18:59:20  C:\Program Files\Logitech\Video\InstallHelper .exe
—-a-w		   196,608 2007-12-30 18:59:52  C:\Program Files\Logitech\Video\ManifestEngine .exe
—-a-w		 5,674,352 2007-12-30 19:00:11  C:\Program Files\MSN Messenger\MsnMsgr .Exe
—-a-w		 1,116,920 2007-12-30 18:59:36  C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc .exe
—-a-w		   102,400 2007-12-30 18:59:32  C:\Program Files\Roxio\Media Experience\DMXLauncher .exe
—-a-w		   224,248 2007-12-30 18:48:30  C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
—-a-w			64,512 2007-12-31 03:35:13  C:\WINDOWS\ehome\ehtray .exe
—-a-w		   237,568 2007-12-30 18:58:41  C:\WINDOWS\SMINST\RECGUARD .EXE
—-a-w		   262,144 2007-12-30 18:59:23  C:\WINDOWS\system32\ElkCtrl .exe
—-a-w		   221,184 2007-12-30 18:59:15  C:\WINDOWS\system32\LVCOMSX .EXE
—-a-w			99,840 2007-12-30 18:59:25  C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2F1 .EXE


((((((((((((((((((((((((((((( snapshot_2008-01-05_16.43.27.78 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-05-24 17:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .exe" [ ]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-09 16:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 19:19 77312 C:\WINDOWS\arpwrmsg.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-01-24 13:15 7311360]
"nwiz"="nwiz.exe" [2006-01-24 13:15 1519616 C:\WINDOWS\system32\nwiz.exe]
"PCDrProfiler"="" []
"RTHDCPL"="RTHDCPL.EXE" [2006-08-14 13:00 16050176 C:\WINDOWS\RTHDCPL.exe]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-12-30 22:35 49152]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-30 22:50 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-04 00:12:18]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-01 20:06]
S2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 00:45]
S3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-07-28 12:37]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7b2cf876-6cd6-11db-b63c-0017313595a3}]
\Shell\AutoRun\command - L:\JDSecure\Windows\JDSecure31.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-12-08 17:39:29 C:\WINDOWS\Tasks\RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 0~0.job"
- C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\Main\Roxio_Central33.exe?Sched RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 0~0
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-06 15:24:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-06 15:24:58
ComboFix-quarantined-files.txt 2008-01-06 20:24:50
ComboFix2.txt 2008-01-05 21:43:48
ComboFix3.txt 2008-01-04 13:05:44
.
2007-12-13 08:05:09 — E O F —







New HijackThis log (normal mode):


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:46:29 PM, on 1/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\webhelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE" -quiet
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://software-dl.real.com/1017b8b918d6bc…ne_Inst_Win.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1166005466109
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (file missing)
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 9955 bytes
Hi :)

There's still an infection showing. Please delete your current copy of Combofix again, and download the newest version as it has been updated yet again:

Link 1
Link 2
Link 3

Note: Disable all your monitoring programs (Anti-Virus, Anti-Spyware) before running Combofix.

Double-click on combofix.exe and follow the prompts.
When finished, it will produce a log for you. Please post the contents of that log in your next reply. You can now re enable your monitoring programs.

Note: Do not mouseclick Combofix's window whilst it's running. That may cause it to stall.
New Combofix log (from safe mode) from new Combofix download with anti virus / spyware disabled:


ComboFix 08-01-07.4 - PBJG 2008-01-07 7:49:41.5 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.759 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-12-07 to 2008-01-07 )))))))))))))))))))))))))))))))
.

2008-01-05 17:18 . 2008-01-05 17:18 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-01-05 17:18 . 2008-01-05 17:18 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-05 16:51 . 2008-01-07 07:42 0 –a—— C:\WINDOWS\system32\drivers\lvuvc.hs
2008-01-03 06:45 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-02 20:14 . 2008-01-02 20:15 d——– C:\WINDOWS\ERUNT
2008-01-02 20:02 . 2008-01-02 20:02 d——– C:\Program Files\CCleaner
2007-12-30 22:51 . 2008-01-06 16:05 d——– C:\Documents and Settings\PBJG\Application Data\AVG7
2007-12-30 22:50 . 2007-12-30 22:50 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-30 21:51 . 2008-01-07 07:36 d——– C:\Documents and Settings\All Users\Application Data\Avg7
2007-12-30 19:54 . 2007-12-30 19:54 d——– C:\Documents and Settings\PBJG\Application Data\CyberLink
2007-12-30 16:59 . 2007-12-30 16:59 d——– C:\Program Files\Trend Micro
2007-12-30 15:46 . 2008-01-07 07:31 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-30 13:08 . 2007-12-30 13:08 d——– C:\Documents and Settings\PBJG\Application Data\Uniblue
2007-12-30 09:24 . 2007-12-30 13:59 262,144 –a—— C:\WINDOWS\system32\ElkCtrl .exe
2007-12-30 09:24 . 2007-12-30 13:59 221,184 –a—— C:\WINDOWS\system32\LVCOMSX .EXE
2007-12-30 07:19 . 2007-12-30 07:19 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-30 07:14 . 2007-12-30 14:00 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-30 07:07 . 2007-12-30 23:37 d——– C:\Documents and Settings\All Users\Application Data\1Click DVD Copy
2007-12-30 07:06 . 2007-12-31 13:47 d——– C:\Documents and Settings\PBJG\Application Data\Vso
2007-12-30 07:06 . 2007-12-31 13:47 87,608 –a—— C:\Documents and Settings\PBJG\Application Data\ezpinst.exe
2007-12-30 07:06 . 2007-12-30 07:06 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2007-12-30 07:06 . 2007-12-31 13:47 47,360 –a—— C:\Documents and Settings\PBJG\Application Data\pcouffin.sys
2007-12-25 13:15 . 2007-12-25 13:15 d——– C:\Documents and Settings\All Users\Application Data\espionServerData
2007-12-24 13:26 . 2007-12-24 13:26 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-24 13:11 . 2007-12-24 13:11 d——– C:\Program Files\Common Files\Macrovision Shared
2007-12-10 18:49 . 2007-05-29 13:55 22,112 –a—— C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-12-10 18:49 . 2007-05-29 13:55 10,592 –a—— C:\WINDOWS\system32\drivers\COH_Mon.cat
2007-12-10 18:49 . 2007-05-29 13:55 705 –a—— C:\WINDOWS\system32\drivers\COH_Mon.inf

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-04 12:58 ——— d—–w C:\Program Files\Java
2007-12-31 18:47 ——— d—–w C:\Program Files\DivX
2007-12-31 05:09 ——— d—–w C:\Program Files\QuickTime
2007-12-31 03:33 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-31 03:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-31 03:32 ——— d—–w C:\Program Files\Symantec
2007-12-31 03:32 ——— d—–w C:\Program Files\Norton 360
2007-12-31 00:34 ——— d—–w C:\Program Files\MSN Messenger
2007-12-30 23:33 ——— d—–w C:\Program Files\InterActual
2007-12-30 18:58 ——— d—–w C:\Program Files\dvd43
2007-12-30 18:48 ——— d–h–w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-12-30 18:48 ——— d—–w C:\Program Files\Yahoo!
2007-12-30 18:47 ——— d—–w C:\Documents and Settings\PBJG\Application Data\Yahoo!
2007-12-30 16:14 ——— d—–w C:\Program Files\LimeWire
2007-12-30 11:16 ——— d—–w C:\Program Files\vso
2007-12-30 05:14 ——— d—–w C:\Program Files\GemMaster
2007-12-24 18:11 ——— d—–w C:\Program Files\Common Files\Adobe
2007-12-24 18:06 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-12-24 18:06 129,784 ——w C:\WINDOWS\system32\PxAFS.DLL
2007-12-24 18:06 118,520 ——w C:\WINDOWS\system32\pxinsi64.exe
2007-12-24 18:06 116,472 ——w C:\WINDOWS\system32\pxcpyi64.exe
2007-12-06 23:03 71,168 —-a-w C:\WINDOWS\system32\LxrJD31s.exe
2007-12-06 23:03 69,824 —-a-w C:\WINDOWS\system32\drivers\LxrJD31d.sys
2007-12-06 23:03 61,440 —-a-w C:\WINDOWS\system32\LxrJD20Sat.dll
2007-12-06 23:03 249,856 —-a-w C:\WINDOWS\system32\LxrJD31.dll
2007-12-06 23:03 163,840 —-a-w C:\WINDOWS\system32\LxrJD31c.exe
2007-12-06 23:03 146,432 —-a-w C:\WINDOWS\system32\LxrJD31p.exe
2007-11-14 08:19 ——— d—–w C:\Program Files\DISC
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 —-a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 —-a-w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 —-a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 —-a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 —-a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 —-a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 —-a-w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 —-a-w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 —-a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 —-a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 —-a-w C:\WINDOWS\system32\dllcache\ieakui.dll
.
——w			39,792 2007-12-30 18:59:39  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w		   221,184 2007-12-30 18:59:32  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe
—-a-w		   115,816 2007-12-30 18:59:40  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   694,272 2007-12-30 18:59:30  C:\Program Files\dvd43\dvd43_tray .exe
—-a-w		   579,072 2007-12-31 05:10:03  C:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w		   389,120 2007-12-30 18:59:19  C:\Program Files\Logitech\Video\CameraAssistant .exe
—-a-w			73,728 2007-12-30 18:59:20  C:\Program Files\Logitech\Video\InstallHelper .exe
—-a-w		   196,608 2007-12-30 18:59:52  C:\Program Files\Logitech\Video\ManifestEngine .exe
—-a-w		 5,674,352 2007-12-30 19:00:11  C:\Program Files\MSN Messenger\MsnMsgr .Exe
—-a-w		 1,116,920 2007-12-30 18:59:36  C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc .exe
—-a-w		   102,400 2007-12-30 18:59:32  C:\Program Files\Roxio\Media Experience\DMXLauncher .exe
—-a-w		   224,248 2007-12-30 18:48:30  C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
—-a-w			64,512 2007-12-31 03:35:13  C:\WINDOWS\ehome\ehtray .exe
—-a-w		   237,568 2007-12-30 18:58:41  C:\WINDOWS\SMINST\RECGUARD .EXE
—-a-w		   262,144 2007-12-30 18:59:23  C:\WINDOWS\system32\ElkCtrl .exe
—-a-w		   221,184 2007-12-30 18:59:15  C:\WINDOWS\system32\LVCOMSX .EXE
—-a-w			99,840 2007-12-30 18:59:25  C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2F1 .EXE


((((((((((((((((((((((((((((( snapshot_2008-01-05_16.43.27.78 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-05-24 17:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .exe" [ ]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-09 16:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 19:19 77312 C:\WINDOWS\arpwrmsg.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-01-24 13:15 7311360]
"nwiz"="nwiz.exe" [2006-01-24 13:15 1519616 C:\WINDOWS\system32\nwiz.exe]
"PCDrProfiler"="" []
"RTHDCPL"="RTHDCPL.EXE" [2006-08-14 13:00 16050176 C:\WINDOWS\RTHDCPL.exe]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-12-30 22:35 49152]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-04 00:12:18]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-01 20:06]
S2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 00:45]
S3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-07-28 12:37]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7b2cf876-6cd6-11db-b63c-0017313595a3}]
\Shell\AutoRun\command - L:\JDSecure\Windows\JDSecure31.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-12-08 17:39:29 C:\WINDOWS\Tasks\RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 0~0.job"
- C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\Main\Roxio_Central33.exe?Sched RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 0~0
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-07 07:53:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-07 7:53:59
ComboFix-quarantined-files.txt 2008-01-07 12:53:56
ComboFix2.txt 2008-01-06 20:24:59
ComboFix3.txt 2008-01-05 21:43:48
ComboFix4.txt 2008-01-04 13:05:44
.
2007-12-13 08:05:09 — E O F —
Hi,

It's really stuborn :o We'll need to run another CFScript, but please run Combofix in Normal Mode.

Open Notepad (Go to Start > Run, type Notepad and hit Enter), and copy/paste the text in the quotebox below into it:

RenV::

——w			39,792 2007-12-30 18:59:39  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w		   221,184 2007-12-30 18:59:32  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe
—-a-w		   115,816 2007-12-30 18:59:40  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   694,272 2007-12-30 18:59:30  C:\Program Files\dvd43\dvd43_tray .exe
—-a-w		   579,072 2007-12-31 05:10:03  C:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w		   389,120 2007-12-30 18:59:19  C:\Program Files\Logitech\Video\CameraAssistant .exe
—-a-w			73,728 2007-12-30 18:59:20  C:\Program Files\Logitech\Video\InstallHelper .exe
—-a-w		   196,608 2007-12-30 18:59:52  C:\Program Files\Logitech\Video\ManifestEngine .exe
—-a-w		 5,674,352 2007-12-30 19:00:11  C:\Program Files\MSN Messenger\MsnMsgr .Exe
—-a-w		 1,116,920 2007-12-30 18:59:36  C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc .exe
—-a-w		   102,400 2007-12-30 18:59:32  C:\Program Files\Roxio\Media Experience\DMXLauncher .exe
—-a-w		   224,248 2007-12-30 18:48:30  C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
—-a-w			64,512 2007-12-31 03:35:13  C:\WINDOWS\ehome\ehtray .exe
—-a-w		   237,568 2007-12-30 18:58:41  C:\WINDOWS\SMINST\RECGUARD .EXE
—-a-w		   262,144 2007-12-30 18:59:23  C:\WINDOWS\system32\ElkCtrl .exe
—-a-w		   221,184 2007-12-30 18:59:15  C:\WINDOWS\system32\LVCOMSX .EXE
—-a-w			99,840 2007-12-30 18:59:25  C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2F1 .EXE

Click on File > Save as….

In the File Name box, copy/paste CFScript.txt (Note: Do not change the filename!)

Click Save (Save the CFScript in the same location as Combofix.exe)

Close any open windows.

Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix.

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe.
It will create a log (C:\Combofix.txt). Post it back here in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI