Thanks! My computer is running a little slow. Just before I ran the combofix, I was still getting some pop-ups that would say
"Critical System Threads"
"Help speed up your pc"
Here are the logs:
ComboFix 08-01-30.1 - Karl 2008-01-31 20:20:16.3 - NTFSx86
Running from: C:\Documents and Settings\Karl\Desktop\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\Karl\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\Program Files\MyWebSearchWB\bar\1.bin\W6BAR.DLL
C:\WINDOWS\nermnkbg.dll
C:\WINDOWS\system32\arfutg.exe
C:\WINDOWS\system32\everybodybets.32x32.4.ico
C:\WINDOWS\system32\L7E16.tmp
C:\WINDOWS\system32\rxjddnvj.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Cassidy\Application Data\Viewpoint
C:\Documents and Settings\Cassidy\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\-678331546.mtz
C:\Documents and Settings\Cassidy\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\1106236703.swf
C:\Documents and Settings\Cassidy\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_01\1057593760.jpg
C:\Documents and Settings\Cassidy\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_01\149522599.jpg
C:\Documents and Settings\Cassidy\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\-351416385.jpg
C:\Documents and Settings\Cassidy\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\-789050290.jpg
C:\Documents and Settings\Cassidy\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\1052380094.jpg
C:\Documents and Settings\Cassidy\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\1404232407.swf
C:\Documents and Settings\Cassidy\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_03\-678331521.mts
C:\Documents and Settings\Cassidy\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_03\998646808.jpg
C:\Program Files\MyWebSearchWB
C:\Program Files\MyWebSearchWB\bar\1.bin\NPMYSRWB.DLL
C:\Program Files\MyWebSearchWB\bar\1.bin\W6BAR.DLL
C:\Program Files\MyWebSearchWB\bar\1.bin\W6FFXTBR.JAR
C:\Program Files\MyWebSearchWB\bar\1.bin\W6NTSTBR.JAR
C:\Program Files\MyWebSearchWB\bar\1.bin\W6WBTEMP.DLL
C:\Program Files\MyWebSearchWB\bar\Cache\
000169B1.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
00018075.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0002BD1C.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
00052C86.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
000B0BF1.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
003279A1.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0039FF79.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
005EE0D1.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
005EE1CB.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
008D3D59.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
00A6406C.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
00DEEFE6.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
00F8A6C9.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
00F91FF0.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
00F920CB.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
012CB16A
C:\Program Files\MyWebSearchWB\bar\Cache\
0181FE35.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
01C2E87E.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
020F3351.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
02283607.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
02283701.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0228378D.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
022C2039.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
023DBE6B.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
024218FB.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
024219B6.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
026E0DE9.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0282C977.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
028AEAE3.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
03B7F451.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
03DFBBE9.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
04329840.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
043298FC.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
04329979.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
04427F7B.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
04F23E82.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
04F23F4D.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
04F23FE9.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
04F24095.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
04FC5AA4.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0508F285.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0529CE14.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0529CED0.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0529CF4D.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
05609E2F.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0560A023.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0560A16B.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
05CCD08C.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
060037AA.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
071C7F1E.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
07835F2D.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
07836150.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
07836354.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
07836529.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0783673C.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
07877FD1.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
07A45BE1.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
07B8B356.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
07B8B48F.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
082F7BD9.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
082F7CE2.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
082F7D6F.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
084947F9.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
084948B4.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
08494941.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
084949CE.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
08494A5A.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
08494AE7.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
08EB03E7.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
08EB0520.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
08EB05DB.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
08EB82CB.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
091CDDAF.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
091CDEA9.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
091CDF35.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
09EA6C2E.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
09EA6E8F.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
09EA6FC8.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
09EA70C2.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
09EA719D.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
09EA7287.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
09EA7362.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0A142277.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0A19DC87.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0A19DDEF.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0B3AE18B.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0BB52FF7.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0BB530B3.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0BB5314F.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0BB531DC.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0CA80DCB.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0CA80EA6.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0F31AC68.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0FC8CC94.bin
C:\Program Files\MyWebSearchWB\bar\Cache\105B9D2C.bin
C:\Program Files\MyWebSearchWB\bar\Cache\111C209F.bin
C:\Program Files\MyWebSearchWB\bar\Cache\11EF2EC6.bin
C:\Program Files\MyWebSearchWB\bar\Cache\11EF303D.bin
C:\Program Files\MyWebSearchWB\bar\Cache\11EF3146.bin
C:\Program Files\MyWebSearchWB\bar\Cache\11EF3231.bin
C:\Program Files\MyWebSearchWB\bar\Cache\11EF330B.bin
C:\Program Files\MyWebSearchWB\bar\Cache\12CAA842.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1378D00F.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1378D109.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1378D196.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1378D222.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1378D29F.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1378D31C.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1378D3A9.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1378D445.bin
C:\Program Files\MyWebSearchWB\bar\Cache\13BE28FD.bin
C:\Program Files\MyWebSearchWB\bar\Cache\13DD5C2C.bin
C:\Program Files\MyWebSearchWB\bar\Cache\13DD5D07.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1409362F.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1542B3B9.bin
C:\Program Files\MyWebSearchWB\bar\Cache\16711209.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1AA61D5D.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1C27AECF.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1D56A5F3.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1FB4F21C.bin
C:\Program Files\MyWebSearchWB\bar\Cache\2136237C.bin
C:\Program Files\MyWebSearchWB\bar\Cache\files.ini
C:\Program Files\MyWebSearchWB\bar\History\search
C:\Program Files\MyWebSearchWB\bar\Settings\prevcfg.htm
C:\Program Files\Viewpoint
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Common\VistaBoot.sdll
C:\Program Files\Viewpoint\Viewpoint Manager\CPtask.xml
C:\Program Files\Viewpoint\Viewpoint Manager\VETScriptInterpreter.dll
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCP.cpl
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\s.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_av.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_cp.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_up.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bg.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bottom.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab_bg.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_off.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_on.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_off.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_on.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vwpt_logo.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\options.ini
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\viewpoint.ico
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\vmctrl.html
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPexe.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgrCore.dll
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream_0302021C.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream_0302021C_.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream_0305000D.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\ClassIDs.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\ComponentMgr_0305000D.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\ComponentRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\AOLUserShell.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\JpegReader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\Mts3Reader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SceneComponent.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SreeDMMX.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SWFView.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMgr.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPSpeech.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPVideo.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPVideo2.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\WaveletReader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\DownLoadHist.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\HostRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MetaStreamConfig.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\Cursors.dll
C:\WINDOWS\nermnkbg.dll
C:\WINDOWS\PerfInfo
C:\WINDOWS\PerfInfo\nTBirJgEvvwp.exe
C:\WINDOWS\system32\everybodybets.32x32.4.ico
C:\WINDOWS\system32\L7E16.tmp
C:\WINDOWS\system32\rxjddnvj.exe
.
((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 )))))))))))))))))))))))))))))))
.
2008-01-30 22:51 . 2008-01-30 22:51 772,701 --a------ C:\virus screen shot.rtf
2008-01-30 19:42 . 2008-01-30 19:42 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-01-30 19:42 . 2008-01-30 19:42 <DIR> d-------- C:\Documents and Settings\Karl\Application Data\Malwarebytes
2008-01-30 00:17 . 2008-01-30 00:17 <DIR> d-------- C:\EmergencyUtils
2008-01-29 22:38 . 2008-01-29 22:38 <DIR> d-------- C:\Documents and Settings\Administrator\.java
2008-01-29 22:38 . 2008-01-29 22:38 <DIR> d-------- C:\ComboFix
2008-01-28 23:46 . 2008-01-29 22:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-28 22:45 . 2008-01-29 08:10 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-01-28 22:45 . 2008-01-28 22:45 30,208 --a------ C:\ck.doc
2008-01-28 22:42 . 2008-01-29 22:38 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2008-01-28 21:49 . 2008-01-28 21:49 488,144 --a------ C:\HJTsetup
2008-01-28 21:30 . 2007-08-01 22:47 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-01-28 20:41 . 2008-01-29 22:37 <DIR> d-------- C:\Documents and Settings\Administrator\.housecall6.6
2008-01-27 21:46 . 2008-01-29 22:38 <DIR> d-------- C:\Documents and Settings\Karl\.housecall6.6
2008-01-26 20:55 . 2008-01-26 20:55 <DIR> d-------- C:\WINDOWS\lgrsskpb
2008-01-06 19:15 . 2008-01-16 17:53 <DIR> d-------- C:\Program Files\PopCap Games
2008-01-06 19:15 . 2008-01-21 10:55 21 --a------ C:\WINDOWS\popcinfot.dat
2008-01-06 19:15 . 2008-01-06 19:15 0 --a------ C:\WINDOWS\popcreg.dat
2008-01-02 20:56 . 2008-01-02 20:56 <DIR> d-------- C:\WINDOWS\VirtualEar
2008-01-02 20:56 . 2008-01-02 20:56 <DIR> d-------- C:\Program Files\Analog Devices
2008-01-02 18:06 . 2008-01-02 20:56 <DIR> d-------- C:\Documents and Settings\Karl\Application Data\RegistryClear
2008-01-02 18:05 . 2008-01-02 20:56 <DIR> d-------- C:\Program Files\RegistryClear
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-01 00:49 --------- d-----w C:\Documents and Settings\Adam\Application Data\WeatherBug
2008-01-30 14:00 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-30 02:01 --------- d-----w C:\Documents and Settings\Karl\Application Data\AVG7
2008-01-26 20:24 --------- d-----w C:\Program Files\Wal-Mart Music Downloads Store
2008-01-11 01:54 --------- d-----w C:\Documents and Settings\Karl\Application Data\WeatherBug
2007-12-31 21:51 --------- d-----w C:\Documents and Settings\Karl\Application Data\Apple Computer
2007-12-23 15:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-23 01:33 --------- d-----w C:\Documents and Settings\Cassidy\Application Data\WeatherBug
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2000-08-16 04:49 923 ----a-w C:\Program Files\RLA.scp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2004-08-31 15:32 1597440]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 03:40 218032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" []
"nwiz"="nwiz.exe" [2002-07-17 15:16 372736 C:\WINDOWS\system32\nwiz.exe]
"WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" [2000-07-14 18:00 24576]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2000-07-14 18:00 311350]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-07-14 18:00 28739]
"CHotkey"="mHotkey.exe" [2002-09-21 16:12 482816 C:\WINDOWS\mHotkey.exe]
"GWMDMMSG"="GWMDMMSG.exe" [2002-08-06 21:24 90112 C:\WINDOWS\GWMDMMSG.exe]
"GWMDMpi"="C:\WINDOWS\GWMDMpi.exe" [2002-08-06 21:24 53248]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-02 21:01 579072]
"MediaFace Integration"="C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe" [2003-08-18 17:46 53248]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2005-03-11 06:08 81920]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 10:00 49152]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 17:18 151552]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 11:49 163840]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 21:02 53248]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 17:29 303104]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 11:05 212992]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 08:41 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 08:14 270648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 07:13 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 01:15:54 65588]
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-07-14 18:00:00 24633]
R0 fasttrak;fasttrak;C:\WINDOWS\system32\DRIVERS\fasttrak.sys [2002-06-18 11:50]
R1 ATMhelpr;ATMhelpr;C:\WINDOWS\system32\drivers\ATMhelpr.sys [1997-06-17 04:00]
R2 NMSSvc;Intel® NMS;C:\WINDOWS\System32\NMSSvc.exe [2002-03-05 15:35]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" []
R3 NMSCFG;NIC Management Service Configuration Driver;C:\WINDOWS\system32\drivers\NMSCFG.SYS [2002-03-05 15:35]
S2 CoachWdm;Samsung Digimax 210SE Camera;C:\WINDOWS\system32\Drivers\CoachWdm.sys [2000-10-21 13:29]
*Newly Created Service* - NMSCFG
.
Contents of the 'Scheduled Tasks' folder
"2008-01-21 16:41:15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-28 09:30:00 C:\WINDOWS\Tasks\RegistryClear Scheduled Scan.job"
- C:\Program Files\RegistryClear\RegistryClear.ex
- C:\Program Files\RegistryClear
"2008-02-01 00:49:53 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-31 20:25:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\nermnkbg.dll
.
Completion time: 2008-01-31 20:31:38
ComboFix-quarantined-files.txt 2008-02-01 02:31:32
ComboFix2.txt 2008-01-31 02:57:53
ComboFix3.txt 2008-01-28 02:27:44
.
2008-01-26 16:03:12 --- E O F ---
Logfile of HijackThis v1.99.1
Scan saved at 8:47:40 PM, on 1/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\GWMDMMSG.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\HJT\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapp...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.vprmatrix.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.r3.attbi.com:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = sas.r3.attbi.com;<local>
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.msn.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.t...ivex/hcImpl.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://www.costcopho...stcoActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} -
http://mediaplayer.w...ler/install.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) -
http://www.samsphoto...ploadClient.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://download.mcaf...,26/mcgdmgr.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} -
http://download.abac...abasetup160.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)