This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Problem similar to Intelligent Advisor, instead I get

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\Program Files\Alwil Software\Avast4\ashDisp .exe 
C:\WINDOWS\system32\[u]0[/u]0THotkey .exe

Folder::
C:\SDFix

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00THotkey"=-
"QuickTime Task"=-

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run
HERE IS THE COMBOFIX LOG:

ComboFix 08-01-04.1 - Bryce Helsel 2008-01-05 23:50:18.5 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Bryce Helsel\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\Program Files\Alwil Software\Avast4\ashDisp .exe
C:\WINDOWS\system32\00THotkey .exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Alwil Software\Avast4\ashDisp .exe
C:\SDFix
C:\SDFix\apps\assosfix.reg
C:\SDFix\apps\cliptext.exe
C:\SDFix\apps\download.exe
C:\SDFix\apps\dummy.exe
C:\SDFix\apps\dummy.sys
C:\SDFix\apps\Enable_Command_Prompt.reg
C:\SDFix\apps\ERDNT.E_E
C:\SDFix\apps\ERDNTDOS.LOC
C:\SDFix\apps\ERDNTWIN.LOC
C:\SDFix\apps\ERUNT.EXE
C:\SDFix\apps\ERUNT.LOC
C:\SDFix\apps\fix.reg
C:\SDFix\apps\FixBH.reg
C:\SDFix\apps\FIXCU.reg
C:\SDFix\apps\FIXLM.reg
C:\SDFix\apps\FixPath.exe
C:\SDFix\apps\FixRedir.reg
C:\SDFix\apps\FixWebCheck.reg
C:\SDFix\apps\fixXP.reg
C:\SDFix\apps\FixXPsp2.reg
C:\SDFix\apps\HPFix.reg
C:\SDFix\apps\HPFix2.reg
C:\SDFix\apps\HPFix3.reg
C:\SDFix\apps\HPFix4.reg
C:\SDFix\apps\isadmin.exe
C:\SDFix\apps\leg2.txt
C:\SDFix\apps\legacy.txt
C:\SDFix\apps\legacybk.txt
C:\SDFix\apps\locate.com
C:\SDFix\apps\LS.exe
C:\SDFix\apps\MD5File.exe
C:\SDFix\apps\MyGcpvFix.reg
C:\SDFix\apps\MyGkFix2.reg
C:\SDFix\apps\Process.exe
C:\SDFix\apps\procs.exe
C:\SDFix\apps\psservice.exe
C:\SDFix\apps\RegDACL.exe
C:\SDFix\apps\regedit.exe
C:\SDFix\apps\Rem.txt
C:\SDFix\apps\Rem2.txt
C:\SDFix\apps\Replace\W2K.exe
C:\SDFix\apps\Replace\w2k\beep.sys
C:\SDFix\apps\Replace\w2k\null.sys
C:\SDFix\apps\Replace\XP.exe
C:\SDFix\apps\Replace\xp\beep.sys
C:\SDFix\apps\Replace\xp\null.sys
C:\SDFix\apps\Reset_AppInit_DLLs.reg
C:\SDFix\apps\RestartIt!.exe
C:\SDFix\apps\Restore_SecurityCenter.reg
C:\SDFix\apps\Restore_SharedAccess.reg
C:\SDFix\apps\sc.exe
C:\SDFix\apps\SecurityProviders.reg
C:\SDFix\apps\SF.exe
C:\SDFix\apps\shutdown.exe
C:\SDFix\apps\srv2.txt
C:\SDFix\apps\svc.txt
C:\SDFix\apps\svcbk.txt
C:\SDFix\apps\swreg.exe
C:\SDFix\apps\swsc.exe
C:\SDFix\apps\unzip.exe
C:\SDFix\apps\WINMSG.EXE
C:\SDFix\apps\zip.exe
C:\SDFix\backups\attrib.exe
C:\SDFix\backups\backupreg.zip
C:\SDFix\backups\backups.zip
C:\SDFix\backups\find.exe
C:\SDFix\backups\findstr.exe
C:\SDFix\backups\HOSTS
C:\SDFix\backups\regedit.exe
C:\SDFix\catchme.exe
C:\SDFix\Data.txt
C:\SDFix\dummy.exe
C:\SDFix\dummy.sys
C:\SDFix\RunThis.cmd
C:\SDFix\SDFIX_ReadMe_Online.url

.
((((((((((((((((((((((((( Files Created from 2007-12-06 to 2008-01-06 )))))))))))))))))))))))))))))))
.

2008-01-05 10:51 . 2008-01-04 13:21 155,648 –a—— C:\WINDOWS\system32\igfxtray.exe
2008-01-05 10:51 . 2008-01-04 13:21 118,784 –a—— C:\WINDOWS\system32\hkcmd.exe
2008-01-04 18:10 . 2008-01-04 18:10 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-01-04 18:10 . 2008-01-04 18:10 d——– C:\WINDOWS\LastGood
2008-01-04 18:10 . 2008-01-04 18:10 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-04 13:31 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-04 12:27 . 2008-01-04 12:28 d——– C:\WINDOWS\ERUNT
2008-01-04 02:36 . 2008-01-04 02:36 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-04 02:36 . 2008-01-04 02:36 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-03 17:17 . 2008-01-03 17:17 d——– C:\Program Files\Trend Micro
2008-01-03 15:09 . 2008-01-03 15:09 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-03 15:08 . 2008-01-05 10:46 d——– C:\Program Files\SUPERAntiSpyware
2008-01-03 14:57 . 2008-01-03 17:13 d——– C:\Program Files\RogueRemover FREE
2008-01-03 13:38 . 2008-01-03 13:38 d——– C:\Documents and Settings\Bryce Helsel\Application Data\PrevxCSI
2008-01-03 13:38 . 2008-01-03 13:38 d——– C:\Documents and Settings\All Users\Application Data\Prevx
2008-01-03 13:32 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-03 13:31 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2008-01-03 13:31 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2008-01-03 13:31 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AVASTSS.scr
2008-01-03 13:31 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-03 13:31 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-03 13:31 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-03 13:31 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-02 01:49 . 2008-01-02 01:49 d——– C:\Program Files\Lavasoft
2008-01-02 01:49 . 2008-01-02 01:49 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-02 01:45 . 2008-01-03 17:15 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-01-02 01:19 . 2008-01-04 13:21 258,048 –a—— C:\WINDOWS\system32\00THotkey .exe
2007-12-31 20:53 . 2007-12-31 20:53 d——– C:\Documents and Settings\Bryce Helsel\Incomplete
2007-12-31 20:51 . 2007-12-31 20:51 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-31 20:46 . 2008-01-03 11:41 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-31 19:51 . 2007-12-31 19:51 d——– C:\WINDOWS\Cache
2007-12-31 17:05 . 2004-11-15 15:37 264,440 –a—— C:\WINDOWS\system32\drivers\stac97.sys
2007-12-30 18:34 . 2007-12-31 15:39 d——– C:\Program Files\Tunebite
2007-12-30 18:32 . 2007-12-30 18:32 d——– C:\Program Files\BitZipper
2007-12-30 18:32 . 2007-12-30 18:32 d——– C:\Documents and Settings\Bryce Helsel\Application Data\BitZipper
2007-12-30 17:09 . 2007-12-30 17:09 d——– C:\Documents and Settings\Bryce Helsel\Application Data\RTPlayer
2007-12-30 16:59 . 2007-12-31 15:37 d——– C:\Documents and Settings\Bryce Helsel\Application Data\tunebite
2007-12-26 22:33 . 2007-12-26 22:33 d——– C:\Program Files\NCH Software
2007-12-26 22:33 . 2007-12-26 22:33 d——– C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2007-12-26 22:29 . 2007-12-26 22:46 d——– C:\Program Files\NCH Swift Sound
2007-12-26 22:29 . 2007-12-26 22:39 d——– C:\Documents and Settings\Bryce Helsel\Application Data\NCH Swift Sound
2007-12-26 21:33 . 2007-12-26 21:33 d——– C:\Program Files\Western Digital Technologies
2007-12-26 21:12 . 2007-12-26 21:12 d——– C:\Program Files\Common Files\ArcSoft
2007-12-26 21:12 . 2007-12-26 21:15 d——– C:\Documents and Settings\Bryce Helsel\Application Data\ArcSoft
2007-12-26 21:12 . 2005-02-23 14:58 11,776 –a—— C:\WINDOWS\system32\drivers\afc.sys
2007-12-26 21:11 . 2007-12-26 21:11 d——– C:\WINDOWS\system32\PhotoImpression Slideshow
2007-12-26 21:11 . 2007-12-26 21:11 d——– C:\Program Files\ArcSoft
2007-12-26 21:11 . 2005-04-27 16:36 245,408 –a—— C:\WINDOWS\system32\unicows.dll
2007-12-26 21:11 . 1995-08-01 04:44 212,480 –a—— C:\WINDOWS\PCDLIB32.DLL
2007-12-26 21:11 . 2006-10-20 16:11 126,976 –a—— C:\WINDOWS\system32\PhotoImpression Slideshow.scr
2007-12-17 15:53 . 2008-01-05 10:45 d——– C:\Program Files\QuickTime
2007-12-11 17:34 . 2007-12-11 17:34 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-12-11 17:34 . 2007-12-11 17:34 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-12-11 16:56 . 2007-12-11 16:56 d——– C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-08 19:14 . 2007-12-08 19:14 d——– C:\Program Files\iPod
2007-12-08 19:13 . 2007-12-08 19:14 d——– C:\Program Files\iTunes
2007-12-08 19:03 . 2007-12-08 19:03 d——– C:\Program Files\Common Files\Apple
2007-12-08 17:44 . 2007-12-08 17:44 d——– C:\Program Files\Windows Live Toolbar

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 15:46 ——— d—–w C:\Program Files\X3watchpro
2008-01-05 15:45 ——— d—–w C:\Program Files\Apoint2K
2008-01-04 18:27 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Skype
2008-01-04 17:19 ——— d—–w C:\Program Files\Java
2008-01-04 08:16 ——— d–h–w C:\Documents and Settings\Bryce Helsel\Application Data\x3watchpro
2008-01-03 16:47 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\LimeWire
2008-01-01 21:00 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Ruckus Network
2007-12-31 22:09 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-31 22:09 ——— d—–w C:\Program Files\SigmaTel
2007-12-31 21:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-31 06:58 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\uTorrent
2007-12-19 23:25 ——— d—–w C:\Program Files\DivX
2007-11-29 21:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2007-11-29 13:40 ——— d—–w C:\Program Files\MSXML 4.0
2007-11-28 01:29 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Nero
2007-11-15 20:24 ——— d—–w C:\Program Files\MagicDisc
2007-11-15 05:46 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\MSN6
2007-11-15 05:03 ——— d—–w C:\Program Files\Creative
2007-11-15 04:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2007-11-14 07:07 ——— d—–w C:\Program Files\Microsoft Works
2007-11-14 07:06 ——— d—–w C:\Program Files\MSBuild
2007-11-14 07:03 ——— d—–w C:\Program Files\Microsoft.NET
2007-11-14 06:53 ——— d—–w C:\Program Files\Microsoft Visual Studio 8
2007-11-14 06:07 ——— d—–w C:\Program Files\MagicISO
2007-11-14 06:04 223,128 —-a-w C:\WINDOWS\system32\drivers\vaxscsi.sys
2007-11-14 06:00 ——— d—–w C:\Program Files\Google
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2004-06-09 06:01 1,822,848 —-a-w C:\Documents and Settings\DLA Writing.temp\INSNTMSI.EXE
2004-06-09 06:01 1,709,160 —-a-w C:\Documents and Settings\DLA Writing.temp\INS9XMSI.EXE
2004-01-23 07:00 462,848 —-a-w C:\Documents and Settings\DLA Writing.temp\Setup.exe
2006-01-02 17:49 321 –sha-w C:\WINDOWS\system32\ospcont.dat
.
—-a-w		   258,048 2008-01-04 18:21:38  C:\WINDOWS\system32\00THotkey .exe


((((((((((((((((((((((((((((( snapshot@2008-01-04_13.50.49.52 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 07:56:48 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
+ 2008-01-03 22:35:29 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
+ 2008-01-04 18:21:34 122,939 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
- 2004-08-04 07:56:48 15,360 -c–a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
+ 2008-01-03 22:35:29 15,360 -c–a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
+ 2005-05-24 17:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2008-01-04 13:22 65536]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-01-04 13:24 22880040]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-03 17:35 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2008-01-04 13:23 313472]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-04 13:23 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"000StTHK"="000StTHK.exe" [2001-06-23 20:28 24576 C:\WINDOWS\system32\000StTHK.exe]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2008-01-04 13:21 192512]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2008-01-04 13:21 122939]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2008-01-04 13:21 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2008-01-04 13:21 118784]
"SigmaTel StacMon"="C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [2008-01-04 13:21 86073]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 15:00 88363 C:\WINDOWS\agrsmmsg.exe]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2008-01-04 13:22 1089589]
"PINGER"="C:\TOSHIBA\IVP\ISM\pinger.exe" [2008-01-04 13:22 151552]
"TPSMain"="TPSMain.exe" [2004-06-01 20:43 278528 C:\WINDOWS\system32\TPSMain.exe]
"x3watchpro"="C:\Program Files\X3watchpro\x3watchpro.exe" [2008-01-04 13:22 409600]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-01-04 13:22 33648]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-01-04 13:22 132496]

C:\Documents and Settings\Bryce Helsel\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-07-19 22:13:20]

S3 Camdrv30;Philips ToUcam XS;C:\WINDOWS\system32\Drivers\camdrv30.sys [2001-01-25 02:40]
S3 tbhsd;Tunebite High-Speed Dubbing;C:\WINDOWS\system32\drivers\tbhsd.sys []

.
Contents of the 'Scheduled Tasks' folder
"2007-12-29 23:35:13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-06 04:49:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-05 22:32:19 C:\WINDOWS\Tasks\User_Feed_Synchronization-{EC38B375-0340-4869-8D44-280E8199B66E}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-05 23:54:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-05 23:55:43
ComboFix-quarantined-files.txt 2008-01-06 04:55:29
ComboFix2.txt 2008-01-05 19:04:26
ComboFix3.txt 2008-01-05 17:28:24
ComboFix4.txt 2008-01-04 23:07:14
ComboFix5.txt 2008-01-04 18:51:09
.
2007-12-12 04:26:47 — E O F —


HERE IS THE HIJACK THIS LOG:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:57:52 PM, on 1/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TPSMain.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\iseeu.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [PINGER] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [x3watchpro] C:\Program Files\X3watchpro\x3watchpro.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} (LocalExec Control) - https://my.uga.edu/nps/portal/gadgets/com.n…t/LocalExec.CAB
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1132753115798
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132847722513
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe

–
End of file - 9166 bytes
Hi

Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\system32\00THotkey .exe

RenV:: 
—-a-w		   258,048 2008-01-04 18:21:38  C:\WINDOWS\system32\[u]0[/u]0THotkey .exe

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run
HERE IS THE COMBOFIX LOG:

ComboFix 08-01-04.1 - Bryce Helsel 2008-01-06 12:35:26.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.46 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Bryce Helsel\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\00THotkey .exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\00THotkey .exe

.
((((((((((((((((((((((((( Files Created from 2007-12-06 to 2008-01-06 )))))))))))))))))))))))))))))))
.

2008-01-05 10:51 . 2008-01-04 13:21 155,648 –a—— C:\WINDOWS\system32\igfxtray.exe
2008-01-05 10:51 . 2008-01-04 13:21 118,784 –a—— C:\WINDOWS\system32\hkcmd.exe
2008-01-04 18:10 . 2008-01-04 18:10 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-01-04 18:10 . 2008-01-04 18:10 d——– C:\WINDOWS\LastGood
2008-01-04 18:10 . 2008-01-04 18:10 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-04 13:31 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-04 12:27 . 2008-01-04 12:28 d——– C:\WINDOWS\ERUNT
2008-01-04 02:36 . 2008-01-04 02:36 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-04 02:36 . 2008-01-04 02:36 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-03 17:17 . 2008-01-03 17:17 d——– C:\Program Files\Trend Micro
2008-01-03 15:09 . 2008-01-03 15:09 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-03 15:08 . 2008-01-05 10:46 d——– C:\Program Files\SUPERAntiSpyware
2008-01-03 14:57 . 2008-01-03 17:13 d——– C:\Program Files\RogueRemover FREE
2008-01-03 13:38 . 2008-01-03 13:38 d——– C:\Documents and Settings\Bryce Helsel\Application Data\PrevxCSI
2008-01-03 13:38 . 2008-01-03 13:38 d——– C:\Documents and Settings\All Users\Application Data\Prevx
2008-01-03 13:32 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-03 13:31 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2008-01-03 13:31 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2008-01-03 13:31 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AVASTSS.scr
2008-01-03 13:31 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-03 13:31 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-03 13:31 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-03 13:31 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-02 01:49 . 2008-01-02 01:49 d——– C:\Program Files\Lavasoft
2008-01-02 01:49 . 2008-01-02 01:49 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-02 01:45 . 2008-01-03 17:15 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-12-31 20:53 . 2007-12-31 20:53 d——– C:\Documents and Settings\Bryce Helsel\Incomplete
2007-12-31 20:51 . 2007-12-31 20:51 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-31 20:46 . 2008-01-03 11:41 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-31 19:51 . 2007-12-31 19:51 d——– C:\WINDOWS\Cache
2007-12-31 17:05 . 2004-11-15 15:37 264,440 –a—— C:\WINDOWS\system32\drivers\stac97.sys
2007-12-30 18:34 . 2007-12-31 15:39 d——– C:\Program Files\Tunebite
2007-12-30 18:32 . 2007-12-30 18:32 d——– C:\Program Files\BitZipper
2007-12-30 18:32 . 2007-12-30 18:32 d——– C:\Documents and Settings\Bryce Helsel\Application Data\BitZipper
2007-12-30 17:09 . 2007-12-30 17:09 d——– C:\Documents and Settings\Bryce Helsel\Application Data\RTPlayer
2007-12-30 16:59 . 2007-12-31 15:37 d——– C:\Documents and Settings\Bryce Helsel\Application Data\tunebite
2007-12-26 22:33 . 2007-12-26 22:33 d——– C:\Program Files\NCH Software
2007-12-26 22:33 . 2007-12-26 22:33 d——– C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2007-12-26 22:29 . 2007-12-26 22:46 d——– C:\Program Files\NCH Swift Sound
2007-12-26 22:29 . 2007-12-26 22:39 d——– C:\Documents and Settings\Bryce Helsel\Application Data\NCH Swift Sound
2007-12-26 21:33 . 2007-12-26 21:33 d——– C:\Program Files\Western Digital Technologies
2007-12-26 21:12 . 2007-12-26 21:12 d——– C:\Program Files\Common Files\ArcSoft
2007-12-26 21:12 . 2007-12-26 21:15 d——– C:\Documents and Settings\Bryce Helsel\Application Data\ArcSoft
2007-12-26 21:12 . 2005-02-23 14:58 11,776 –a—— C:\WINDOWS\system32\drivers\afc.sys
2007-12-26 21:11 . 2007-12-26 21:11 d——– C:\WINDOWS\system32\PhotoImpression Slideshow
2007-12-26 21:11 . 2007-12-26 21:11 d——– C:\Program Files\ArcSoft
2007-12-26 21:11 . 2005-04-27 16:36 245,408 –a—— C:\WINDOWS\system32\unicows.dll
2007-12-26 21:11 . 1995-08-01 04:44 212,480 –a—— C:\WINDOWS\PCDLIB32.DLL
2007-12-26 21:11 . 2006-10-20 16:11 126,976 –a—— C:\WINDOWS\system32\PhotoImpression Slideshow.scr
2007-12-17 15:53 . 2008-01-05 10:45 d——– C:\Program Files\QuickTime
2007-12-11 17:34 . 2007-12-11 17:34 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-12-11 17:34 . 2007-12-11 17:34 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-12-11 16:56 . 2007-12-11 16:56 d——– C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-08 19:14 . 2007-12-08 19:14 d——– C:\Program Files\iPod
2007-12-08 19:13 . 2007-12-08 19:14 d——– C:\Program Files\iTunes
2007-12-08 19:03 . 2007-12-08 19:03 d——– C:\Program Files\Common Files\Apple
2007-12-08 17:44 . 2007-12-08 17:44 d——– C:\Program Files\Windows Live Toolbar

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 15:46 ——— d—–w C:\Program Files\X3watchpro
2008-01-05 15:45 ——— d—–w C:\Program Files\Apoint2K
2008-01-04 18:27 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Skype
2008-01-04 17:19 ——— d—–w C:\Program Files\Java
2008-01-04 08:16 ——— d–h–w C:\Documents and Settings\Bryce Helsel\Application Data\x3watchpro
2008-01-03 16:47 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\LimeWire
2008-01-01 21:00 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Ruckus Network
2007-12-31 22:09 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-31 22:09 ——— d—–w C:\Program Files\SigmaTel
2007-12-31 21:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-31 06:58 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\uTorrent
2007-12-19 23:25 ——— d—–w C:\Program Files\DivX
2007-11-29 21:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2007-11-29 13:40 ——— d—–w C:\Program Files\MSXML 4.0
2007-11-28 01:29 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Nero
2007-11-15 20:24 ——— d—–w C:\Program Files\MagicDisc
2007-11-15 05:46 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\MSN6
2007-11-15 05:03 ——— d—–w C:\Program Files\Creative
2007-11-15 04:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2007-11-14 07:07 ——— d—–w C:\Program Files\Microsoft Works
2007-11-14 07:06 ——— d—–w C:\Program Files\MSBuild
2007-11-14 07:03 ——— d—–w C:\Program Files\Microsoft.NET
2007-11-14 06:53 ——— d—–w C:\Program Files\Microsoft Visual Studio 8
2007-11-14 06:07 ——— d—–w C:\Program Files\MagicISO
2007-11-14 06:04 223,128 —-a-w C:\WINDOWS\system32\drivers\vaxscsi.sys
2007-11-14 06:00 ——— d—–w C:\Program Files\Google
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2004-06-09 06:01 1,822,848 —-a-w C:\Documents and Settings\DLA Writing.temp\INSNTMSI.EXE
2004-06-09 06:01 1,709,160 —-a-w C:\Documents and Settings\DLA Writing.temp\INS9XMSI.EXE
2004-01-23 07:00 462,848 —-a-w C:\Documents and Settings\DLA Writing.temp\Setup.exe
2006-01-02 17:49 321 –sha-w C:\WINDOWS\system32\ospcont.dat
.

((((((((((((((((((((((((((((( snapshot@2008-01-04_13.50.49.52 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 07:56:48 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
+ 2008-01-03 22:35:29 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
+ 2008-01-04 18:21:34 122,939 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
- 2004-08-04 07:56:48 15,360 -c–a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
+ 2008-01-03 22:35:29 15,360 -c–a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
+ 2005-05-24 17:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2008-01-04 13:22 65536]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-01-04 13:24 22880040]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-03 17:35 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2008-01-04 13:23 313472]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-04 13:23 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"000StTHK"="000StTHK.exe" [2001-06-23 20:28 24576 C:\WINDOWS\system32\000StTHK.exe]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2008-01-04 13:21 192512]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2008-01-04 13:21 122939]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2008-01-04 13:21 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2008-01-04 13:21 118784]
"SigmaTel StacMon"="C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [2008-01-04 13:21 86073]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 15:00 88363 C:\WINDOWS\agrsmmsg.exe]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2008-01-04 13:22 1089589]
"PINGER"="C:\TOSHIBA\IVP\ISM\pinger.exe" [2008-01-04 13:22 151552]
"TPSMain"="TPSMain.exe" [2004-06-01 20:43 278528 C:\WINDOWS\system32\TPSMain.exe]
"x3watchpro"="C:\Program Files\X3watchpro\x3watchpro.exe" [2008-01-04 13:22 409600]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-01-04 13:22 33648]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-01-04 13:22 132496]

C:\Documents and Settings\Bryce Helsel\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-07-19 22:13:20]

S3 Camdrv30;Philips ToUcam XS;C:\WINDOWS\system32\Drivers\camdrv30.sys [2001-01-25 02:40]
S3 tbhsd;Tunebite High-Speed Dubbing;C:\WINDOWS\system32\drivers\tbhsd.sys []

.
Contents of the 'Scheduled Tasks' folder
"2007-12-29 23:35:13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-06 04:49:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-06 17:39:17 C:\WINDOWS\Tasks\User_Feed_Synchronization-{EC38B375-0340-4869-8D44-280E8199B66E}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-06 12:39:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-06 12:40:47
ComboFix-quarantined-files.txt 2008-01-06 17:40:33
ComboFix2.txt 2008-01-06 04:55:44
ComboFix3.txt 2008-01-05 19:04:26
ComboFix4.txt 2008-01-05 17:28:24
ComboFix5.txt 2008-01-04 23:07:14
.
2007-12-12 04:26:47 — E O F —




HERE IS THE HIJACKTHIS LOG:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:44:54 PM, on 1/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TPSMain.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\iseeu.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [PINGER] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [x3watchpro] C:\Program Files\X3watchpro\x3watchpro.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} (LocalExec Control) - https://my.uga.edu/nps/portal/gadgets/com.n…t/LocalExec.CAB
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1132753115798
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132847722513
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe

–
End of file - 9166 bytes
Hi

You are looking much better. Any problems still?

First off, go to Add/Remove Programs and remove all Java applications, except Java™ 6 Update 3


I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto‑updating for the Viewpoint Manager ‑‑ the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.

Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware.
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight Viewpoint Media Player, click Remove.


  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the x and the /u, it needs to be there.

    [external image: Posted Image]

Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):

O3 - Toolbar: (no name) - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - (no file)


WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit HijackThis. Then reboot the computer and post a new HijackThis log.

You can also delete RenV from your computer.
No Scotty, I have not encountered any problems in a while, but then again, I have not navigated away from this site. But I have not had any popups. Thank you very much so far.


HERE IS THE HIJACKTHIS LOG:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:44:31 PM, on 1/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\X3watchpro\x3watchpro.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Trend Micro\HijackThis\iseeu.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [PINGER] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [x3watchpro] C:\Program Files\X3watchpro\x3watchpro.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} (LocalExec Control) - https://my.uga.edu/nps/portal/gadgets/com.n…t/LocalExec.CAB
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1132753115798
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132847722513
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe

–
End of file - 9738 bytes
Hi

Congratulations, you appear to be malware free.

You may wish to keep hold of the Kaspersky Online Scan as an extra on-demand virus-scanner.
If not you can uninstall it through Start>Control Panel>Add/Remove Programs


Here are some free programs I recommend, although you will not need them all.

Spybot Search and Destroy
Download it from here . Just choose a mirror and off you go.
Find here the tutorial on how to use Spybot properly here

Install Spyware Guard
Download it from here
Find here the tutorial on how to use Spyware Guard here

Install SpyWare Blaster
Download it from here
Find here the tutorial on how to use Spyware Blaster here

Install WinPatrol
Download it from here
Here you can find information about how WinPatrol works here


Make sure your Windows is ALWAYS up to date!

An unpatched Windows is vulnerable and even with the "best" Antivirus and Firewall installed, malware will find its way through.
So visit http://windowsupdate.microsoft.com/ to download and install the latest updates.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Please check out Tony Klein's article "How did I get infected in the first place?"


Follow this list and your potential for being infected again will reduce dramatically.

I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can be closed.
Scotty, you are the man! Thank you so much for your help. I can tell you exactly how I got infected. I foolishly downloaded a sketchy file from a p2p program. It was very unlike me, as I am very careful about what I download. I am indebted to you. Thanks again for your expert support. You do a job that does not appear to get much credit.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI