This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Random windows loading

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 6:53:46 PM, on 2/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\WINDOWS.0\system32\netdde.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VirusScan\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VirusScan\mcshield.exe
C:\PROGRA~1\McAfee\VirusScan\mcsysmon.exe
C:\WINDOWS.0\system32\nvsvc32.exe
C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
C:\WINDOWS.0\system32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS.0\system32\taskmgr.exe
C:\WINDOWS.0\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS.0\explorer.exe
C:\Documents and Settings\Frankie3\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O15 - Trusted Zone: http://microsite.coupons.com
O15 - Trusted Zone: http://www.bricks.coupons.com
O15 - Trusted Zone: http://www.ebay.com
O15 - Trusted Zone: http://s72.photobucket.com
O15 - Trusted Zone: http://www.pyzam.com
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcsysmon.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS.0\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe

————————————————————————————————————————————————
My system is running very slow (full HD which adds to the problem) and I have some sort of loader that opens a browser when ever I click IE, and sometimes it just loads a window by it self. (This is the address of one of the random windows–[http://moneypalacecash.com/.landing/?position=tv&source=cc&aid=vmron&p=22&aid=ccron-page22&mt_info=4026_1486_5683]
I have Mcafee (obviously) which doesn't catch these generated windows. I haven't tried to fix anything, except running a HJT scan this morning, and deleted the "O23 - Remote Packet Capture…… " but it comes right back. HELP?
Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Malwarebytes' Anti-Malware 1.01
Database version: 313

Scan type: Quick Scan
Objects scanned: 60538
Time elapsed: 13 minute(s), 21 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 47
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 11
Files Infected: 14

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS.0\system32\geede.dll (Trojan.Vundo) -> Unloaded module successfully.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7eb49e0d-d68c-42c0-bccc-a389ef06156b} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7eb49e0d-d68c-42c0-bccc-a389ef06156b} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{98663e21-9cce-4cf6-863c-911a9523a66f} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{98663e21-9cce-4cf6-863c-911a9523a66f} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{11a69ae4-fbed-4832-a2bf-45af82825583} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a95b2816-1d7e-4561-a202-68c0de02353a} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a95b2816-1d7e-4561-a202-68c0de02353a} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{454206c1-acee-4b57-862d-0e054336dff5} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{9a47b9e0-44f0-4b57-8223-b242b8b2db48} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{abae87e5-713a-45c8-87b8-330fe0df7552} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bd012772-e991-4283-a105-90ebe90b58ce} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f977e736-3861-4129-a54c-e5c2d800eaaf} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{5291d5a7-2788-42d7-b3b4-7f71d089c10f} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{7d5a0af3-1908-4c96-aafa-0e017ae56237} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\sssinstaller.sinstaller (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\sssinstaller.sinstaller.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\sssinstaller.installer (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\sssinstaller.installer.1 (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{0fbc3efb-fc98-4b32-bf10-bde9aa4dea5a} (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6a4b7d17-1de9-4c14-8adf-eb4c07060519} (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{abf441b2-9b57-4838-96a0-34b1cecd4aa5} (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{74278296-0ec7-4f7a-ad55-eb7a2f35f311} (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\aldd (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\MalwareAlarm (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{98663e21-9cce-4cf6-863c-911a9523a66f} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ADP (Rogue.Multiple) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\The Weather Channel FW (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\Installr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\Installr\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS.0\system32\geede.dll (Trojan.Vundo) -> Failed to delete. (Delete on reboot).
C:\WINDOWS.0\system32\edeeg.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS.0\system32\edeeg.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Program Files\Uninstall Fun Web Products.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\WINDOWS.0\system32\packet.dll (Spyware.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS.0\system32\pthreadVC.dll (Spyware.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS.0\system32\wpcap.dll (Spyware.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS.0\17PHolmes572.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS.0\mrofinu572.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS.0\mrofinu572.exe.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History\search2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\Installr\1.bin\F3EZSETP.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.
—————————————————————————————————————————–
HJT Log
—————————————————————————————————————————–
Logfile of HijackThis v1.99.1
Scan saved at 7:59:44 PM, on 2/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\WINDOWS.0\system32\netdde.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VirusScan\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VirusScan\mcshield.exe
C:\PROGRA~1\McAfee\VirusScan\mcsysmon.exe
C:\WINDOWS.0\system32\nvsvc32.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
C:\WINDOWS.0\system32\svchost.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS.0\system32\NOTEPAD.EXE
C:\WINDOWS.0\explorer.exe
C:\WINDOWS.0\system32\NOTEPAD.EXE
C:\Documents and Settings\Frankie3\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS.0\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O15 - Trusted Zone: http://microsite.coupons.com
O15 - Trusted Zone: http://www.bricks.coupons.com
O15 - Trusted Zone: http://www.ebay.com
O15 - Trusted Zone: http://s72.photobucket.com
O15 - Trusted Zone: http://www.pyzam.com
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcsysmon.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS.0\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe

———————————————————————————
Current System symptoms/activity
—————————————————–
After reboot from Malwarebytes' Anti-Malware Scan, clicking IE generated this site to load
[http://www.perfectlovercalculator.com/Other/?a=AdOn].
I haven't attempted to open any additional browser windows.
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.

Open the HijackThis Folder. Find the file HijackThis.exe, Right Click on the file and Select Rename. Rename Hijackthis.exe to Spyware.exe.

Post a new HijackThis Log.
Logfile of HijackThis v1.99.1
Scan saved at 8:32:29 PM, on 2/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\WINDOWS.0\system32\netdde.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VirusScan\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VirusScan\mcshield.exe
C:\PROGRA~1\McAfee\VirusScan\mcsysmon.exe
C:\WINDOWS.0\system32\nvsvc32.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
C:\WINDOWS.0\system32\svchost.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS.0\system32\NOTEPAD.EXE
C:\WINDOWS.0\explorer.exe
C:\WINDOWS.0\system32\NOTEPAD.EXE
C:\WINDOWS.0\system32\NOTEPAD.EXE
C:\Documents and Settings\Frankie3\Desktop\Spyware.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: {29c95898-f466-534a-2654-95ce77afac84} - {48cafa77-ec59-4562-a435-664f89859c92} - C:\WINDOWS.0\system32\mbtfxtwo.dll
O2 - BHO: (no name) - {6DE2FCF5-1CF5-4546-8555-7740CDEAFFB3} - C:\WINDOWS.0\system32\geede.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {98663E21-9CCE-4CF6-863C-911A9523A66F} - C:\WINDOWS.0\system32\vtuusqr.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS.0\system32\rfjwfqtj.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS.0\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O15 - Trusted Zone: http://microsite.coupons.com
O15 - Trusted Zone: http://www.bricks.coupons.com
O15 - Trusted Zone: http://www.ebay.com
O15 - Trusted Zone: http://s72.photobucket.com
O15 - Trusted Zone: http://www.pyzam.com
O20 - Winlogon Notify: rfjwfqtj - C:\WINDOWS.0\SYSTEM32\rfjwfqtj.dll
O20 - Winlogon Notify: vtuusqr - C:\WINDOWS.0\SYSTEM32\vtuusqr.dll
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcsysmon.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS.0\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe

No problems understanding your instructions………? Why do you ask.

It took you awhile to reply.
I see you have a Vundo infection as well.


Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Lo-o-ong disinfection!
—————————————————————————–

ComboFix 08-01-30.1 - Frankie3 2008-02-02 20:46:49.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.636 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS.0\system32\geede.dll
C:\WINDOWS.0\system32\vtuusqr.dll
C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Frankie3\g2mdlhlpx.exe
C:\setup.exe
C:\WINDOWS.0\dat.txt
C:\WINDOWS.0\system32\drivers\npf.sys
C:\WINDOWS.0\system32\edeeg.ini
C:\WINDOWS.0\system32\edeeg.ini2
C:\WINDOWS.0\system32\geede.dll
C:\WINDOWS.0\system32\isxqcowt.dll
C:\WINDOWS.0\system32\khfeddb.dll
C:\WINDOWS.0\system32\mbtfxtwo.dll
C:\WINDOWS.0\system32\mcrh.tmp
C:\WINDOWS.0\system32\pac.txt
C:\WINDOWS.0\system32\rfjwfqtj.dll
C:\WINDOWS.0\system32\rfjwfqtj.dll . . . . failed to delete
C:\WINDOWS.0\system32\rfjwfqtj.dllbox
C:\WINDOWS.0\system32\tsuvsafq.dll
C:\WINDOWS.0\system32\twocqxsi.ini
C:\WINDOWS.0\system32\vtuusqr.dll
C:\WINDOWS.0\system32\yayvwtr.dll
C:\WINDOWS.0\system32\yaywwut.dll
C:\WINDOWS.0\system32\yaywxyv.dll
C:\windows\xpupdate.exe

—– BITS: Possible infected sites —–

hxxp://www.thenetworkcom.com
hxxp://onlinesafepro.com

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_NPF
——-\nm
——-\NPF


((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 )))))))))))))))))))))))))))))))
.

2008-02-02 21:19 . 2008-02-02 21:20 134 —hs—- C:\WINDOWS.0\system32\rfjwfqtj.dllbox
2008-02-02 19:18 . 2008-02-02 19:19 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-02 19:18 . 2008-02-02 19:18 d—-c— C:\Documents and Settings\Frankie3\Application Data\Malwarebytes
2008-02-02 07:33 . 2008-02-02 07:33 d——– C:\WINDOWS.0\McAfee.com
2008-02-01 21:30 . 2008-02-02 21:13 163,904 –a—— C:\WINDOWS.0\system32\rfjwfqtj.dll
2008-01-27 18:17 . 2008-01-27 18:25 d—-c— C:\Documents and Settings\Frankie3\Application Data\DivX
2008-01-27 18:15 . 2008-01-27 18:15 d——– C:\Program Files\DivX
2008-01-27 18:15 . 2008-01-04 16:58 129,784 –a—— C:\WINDOWS.0\system32\pxafs.dll
2008-01-27 18:15 . 2008-01-04 16:58 9,464 ——— C:\WINDOWS.0\system32\drivers\cdralw2k.sys
2008-01-27 18:15 . 2008-01-04 16:58 9,336 ——— C:\WINDOWS.0\system32\drivers\cdr4_xp.sys
2008-01-27 18:02 . 2008-01-27 18:02 d——– C:\Program Files\Common Files\xing shared
2008-01-24 20:39 . 2008-01-24 21:24 d——– C:\Program Files\FriendBlasterPro
2008-01-24 20:39 . 2005-07-15 12:49 245,760 –a—— C:\WINDOWS.0\system32\aUpdateNow.ocx
2008-01-23 22:54 . 2008-01-23 22:56 d——– C:\Program Files\Oberon Media
2008-01-23 13:34 . 2008-01-23 13:42 d——– C:\WINDOWS.0\system32\nGpxx01
2008-01-23 13:34 . 2008-01-23 13:34 d—-c— C:\Temp\cXzz9
2008-01-23 13:34 . 2008-01-25 12:24 d—-c— C:\Temp
2008-01-19 16:30 . 2008-01-19 16:30 d——– C:\Program Files\Magic Traffic Bot
2008-01-19 12:16 . 2007-06-25 10:57 171,240 –a—— C:\WINDOWS.0\system32\drivers\mfehidk.sys
2008-01-19 12:16 . 2007-06-25 14:54 71,496 –a—— C:\WINDOWS.0\system32\drivers\mfeavfk.sys
2008-01-19 12:16 . 2007-06-25 10:57 37,480 –a—— C:\WINDOWS.0\system32\drivers\mfesmfk.sys
2008-01-19 12:16 . 2007-06-25 10:57 34,184 –a—— C:\WINDOWS.0\system32\drivers\mfebopk.sys
2008-01-19 12:16 . 2007-06-25 10:57 32,008 –a—— C:\WINDOWS.0\system32\drivers\mferkdk.sys
2008-01-19 12:15 . 2007-03-02 14:16 109,608 –a—— C:\WINDOWS.0\system32\drivers\Mpfp.sys
2008-01-19 12:14 . 2008-01-19 12:15 d——– C:\Program Files\McAfee.com
2008-01-19 12:14 . 2008-01-20 18:38 d——– C:\Program Files\McAfee
2008-01-19 12:14 . 2008-01-19 12:16 d——– C:\Program Files\Common Files\McAfee
2008-01-19 11:46 . 2008-01-19 12:24 d—-c— C:\Documents and Settings\All Users.WINDOWS.0\Application Data\McAfee
2008-01-11 19:59 . 1999-09-07 21:27 244,232 –a—— C:\WINDOWS.0\system32\Msflxgrd.ocx
2008-01-07 20:16 . 2008-01-07 20:16 630,784 –a—— C:\WINDOWS.0\system32\divxdec.ax
2008-01-05 12:32 . 1996-06-09 13:52 34,864 –a—— C:\WINDOWS.0\UNWISE.EXE
2008-01-04 19:28 . 2008-01-04 19:28 266 –ah—– C:\WINDOWS.0\log.vbs
2008-01-04 16:59 . 2008-01-04 16:59 524,288 –a—— C:\WINDOWS.0\system32\DivXsm.exe
2008-01-04 16:59 . 2008-01-04 16:59 4,816 –a—— C:\WINDOWS.0\system32\divxsm.tlb
2008-01-04 16:58 . 2008-01-04 16:58 3,596,288 –a—— C:\WINDOWS.0\system32\qt-dx331.dll
2008-01-04 16:58 . 2008-01-04 16:58 1,044,480 –a—— C:\WINDOWS.0\system32\libdivx.dll
2008-01-04 16:58 . 2008-01-04 16:58 200,704 –a—— C:\WINDOWS.0\system32\ssldivx.dll
2008-01-04 16:56 . 2008-01-04 16:56 156,992 –a—— C:\WINDOWS.0\system32\DivXCodecVersionChecker.exe
2008-01-04 16:56 . 2008-01-04 16:56 12,288 –a—— C:\WINDOWS.0\system32\DivXWMPExtType.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-02 22:00 ——— dc—-w C:\Documents and Settings\Frankie3\Application Data\OpenOffice.org2
2008-02-01 16:41 ——— d—–w C:\Program Files\Coupons
2008-01-27 23:02 ——— d—–w C:\Program Files\Real
2008-01-27 23:01 ——— d—–w C:\Program Files\Common Files\Real
2008-01-24 03:56 ——— dc–a-w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP
2008-01-20 23:46 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-20 11:51 ——— d—–w C:\Program Files\sitesubmitter
2008-01-19 17:23 ——— dc—-w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Symantec
2008-01-04 21:58 43,528 -c—-w C:\WINDOWS.0\system32\drivers\PxHelp20.sys
2008-01-03 13:03 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-12 12:22 ——— d—–w C:\Program Files\PC TechZone
2007-12-11 12:08 ——— d—–w C:\Program Files\Photodex
2007-12-09 12:26 ——— d—–w C:\Program Files\Invest
2007-12-09 12:25 336 —-a-w C:\Program Files\temp995.bat
2007-12-09 12:25 ——— d—–w C:\Program Files\pdf995
2007-12-09 12:24 ——— d—–w C:\Program Files\JDiSoftware
2007-12-07 14:10 ——— dc—-w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\pdf995
2006-11-20 19:27 81,920 -c–a-w C:\Program Files\Common Files\wrapper-windows-x86-32.dll
2006-11-19 04:03 1,035,090 -c–a-w C:\Program Files\wrar361.exe
2006-01-28 04:17 20,459,766 -c–a-w C:\Program Files\def.phd
2006-01-28 04:17 140,354 -c–a-w C:\Program Files\compupic.jrn
2006-01-23 19:39 5,632 -csha-w C:\Program Files\Thumbs.db
2006-01-09 04:46 5,529,600 -c–a-w C:\Program Files\all.dnt
2006-01-09 04:46 172,032 -c–a-w C:\Program Files\pro.dnt
2006-01-09 04:46 1,634,304 -c–a-w C:\Program Files\if.dnt
2005-12-31 02:50 2,855,552 -c–a-w C:\Program Files\PPView97.exe
2005-12-15 09:09 2,731,008 -c–a-w C:\Program Files\openofficeorg20.msi
2005-12-15 08:14 49,541,055 -c–a-w C:\Program Files\openofficeorg3.cab
2005-12-15 08:14 2,339,756 -c–a-w C:\Program Files\openofficeorg4.cab
2005-12-15 08:10 6,129,372 -c–a-w C:\Program Files\openofficeorg2.cab
2005-12-15 08:10 17,710,073 -c–a-w C:\Program Files\openofficeorg1.cab
2005-11-27 12:59 683,535 -c–a-w C:\Program Files\Recovery_instructions.zip
2004-08-09 20:13 1,852,928 -c–a-w C:\Program Files\ABBYY PDF Transformer 1.0.msi
2004-08-05 09:08 92,160 -c–a-w C:\Program Files\1036.mst
2004-08-05 09:08 81,920 -c–a-w C:\Program Files\1029.mst
2004-08-05 09:08 76,288 -c–a-w C:\Program Files\1031.mst
2004-08-05 09:08 74,752 -c–a-w C:\Program Files\1040.mst
2004-08-05 09:08 74,752 -c–a-w C:\Program Files\1038.mst
2004-08-05 09:08 71,680 -c–a-w C:\Program Files\1045.mst
2004-08-05 09:08 71,680 -c–a-w C:\Program Files\1043.mst
2004-08-05 09:08 71,680 -c–a-w C:\Program Files\1034.mst
2004-08-05 09:08 38,619,860 -c–a-w C:\Program Files\Data1.cab
2004-08-05 09:08 3,584 -c–a-w C:\Program Files\1033.mst
2004-08-05 09:08 121,856 -c–a-w C:\Program Files\1049.mst
2004-08-05 01:15 285 -c–a-w C:\Program Files\setup.ini
2003-10-03 03:30 4,979,304 -c–a-w C:\Program Files\t-c623x0.zip
2002-03-11 15:06 1,822,520 -c–a-w C:\Program Files\instmsiw.exe
2002-03-11 14:45 1,708,856 -c–a-w C:\Program Files\instmsia.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2008-02-02 21:13 163904 –a—— C:\WINDOWS.0\system32\rfjwfqtj.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW4"="C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24 286720]
"NvCplDaemon"="C:\WINDOWS.0\system32\NvCpl.dll" [2006-10-22 12:22 7700480]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rfjwfqtj]
rfjwfqtj.dll 2008-02-02 21:13 163904 C:\WINDOWS.0\system32\rfjwfqtj.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS.0^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"freenet-darknet-8889-8888"=2 (0x2)

S0 viamraid;viamraid;C:\WINDOWS.0\system32\DRIVERS\viamraid.sys []
S3 ICAM3NT5;Intel USB Video Camera III;C:\WINDOWS.0\system32\Drivers\Icam3.sys [2001-08-17 09:05]
S3 NUVision;Pinnacle DVC 80 Video;C:\WINDOWS.0\system32\DRIVERS\nuvvid2.sys [2001-12-03 13:55]
S3 Wdm1;USB Bridge Cable Driver;C:\WINDOWS.0\system32\Drivers\usbbc.sys [2001-01-07 20:53]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-02 08:00:01 C:\WINDOWS.0\Tasks\012008scan.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-01-30 03:49:05 C:\WINDOWS.0\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-04 15:31:33 C:\WINDOWS.0\Tasks\LifeChatTask.job"
- C:\Program Files\Microsoft LifeChat\LifeChat.exe
"2008-02-02 04:31:41 C:\WINDOWS.0\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe)
"2008-02-01 06:00:21 C:\WINDOWS.0\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-02 21:20:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS.0\system32\winlogon.exe
-> C:\WINDOWS.0\system32\rfjwfqtj.dll

PROCESS: C:\WINDOWS.0\Explorer.EXE [6.00.2900.2180]
-> C:\WINDOWS.0\system32\rfjwfqtj.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS.0\system32\netdde.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VirusScan\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VirusScan\mcshield.exe
C:\PROGRA~1\McAfee\VirusScan\mcsysmon.exe
C:\WINDOWS.0\system32\nvsvc32.exe
C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
C:\WINDOWS.0\system32\wdfmgr.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS.0\system32\wscntfy.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-02-02 21:25:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-03 02:24:58

—————————————————————————————————
HJT Log
—————————————————————————-
Logfile of HijackThis v1.99.1
Scan saved at 9:32:42 PM, on 2/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\WINDOWS.0\system32\netdde.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VirusScan\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
C:\WINDOWS.0\Explorer.EXE
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VirusScan\mcshield.exe
C:\PROGRA~1\McAfee\VirusScan\mcsysmon.exe
C:\WINDOWS.0\system32\nvsvc32.exe
C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
C:\WINDOWS.0\system32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS.0\system32\wscntfy.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS.0\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Frankie3\Desktop\Spyware.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS.0\system32\rfjwfqtj.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS.0\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O15 - Trusted Zone: http://microsite.coupons.com
O15 - Trusted Zone: http://www.bricks.coupons.com
O15 - Trusted Zone: http://www.ebay.com
O15 - Trusted Zone: http://s72.photobucket.com
O15 - Trusted Zone: http://www.pyzam.com
O20 - Winlogon Notify: rfjwfqtj - C:\WINDOWS.0\SYSTEM32\rfjwfqtj.dll
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcsysmon.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS.0\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS.0\system32\rfjwfqtj.dllbox
C:\WINDOWS.0\system32\rfjwfqtj.dll

Folder::
C:\Temp\cXzz9
C:\Program Files\Coupons

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rfjwfqtj]


Save this as Save this as "CFScript"


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Pc seems smoother & faster, less hiccups, no random windows. Cool. :notworthy:

———————————————————————-
ComboFix 08-01-30.1 - Frankie3 2008-02-02 22:04:18.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.645 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\Frankie3\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS.0\system32\rfjwfqtj.dll
C:\WINDOWS.0\system32\rfjwfqtj.dllbox
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS.0\system32\rfjwfqtj.dll
C:\Program Files\Coupons
C:\Program Files\Coupons\Coupons.com.url
C:\Program Files\Coupons\uninstall.exe
C:\Program Files\Coupons\Uninstall\IRIMG1.JPG
C:\Program Files\Coupons\Uninstall\IRIMG2.JPG
C:\Program Files\Coupons\Uninstall\IRIMG3.JPG
C:\Program Files\Coupons\Uninstall\IRIMG4.JPG
C:\Program Files\Coupons\Uninstall\IRIMG5.JPG
C:\Program Files\Coupons\Uninstall\IRIMG6.JPG
C:\Program Files\Coupons\Uninstall\IRIMG7.JPG
C:\Program Files\Coupons\Uninstall\IRIMG8.JPG
C:\Program Files\Coupons\Uninstall\uninstall.dat
C:\Program Files\Coupons\Uninstall\uninstall.xml
C:\Temp\cXzz9
C:\WINDOWS.0\system32\rfjwfqtj.dll
C:\WINDOWS.0\system32\rfjwfqtj.dllbox

.
((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 )))))))))))))))))))))))))))))))
.

2008-02-02 19:18 . 2008-02-02 19:19 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-02 19:18 . 2008-02-02 19:18 d—-c— C:\Documents and Settings\Frankie3\Application Data\Malwarebytes
2008-02-02 07:33 . 2008-02-02 07:33 d——– C:\WINDOWS.0\McAfee.com
2008-01-27 18:17 . 2008-01-27 18:25 d—-c— C:\Documents and Settings\Frankie3\Application Data\DivX
2008-01-27 18:15 . 2008-01-27 18:15 d——– C:\Program Files\DivX
2008-01-27 18:15 . 2008-01-04 16:58 129,784 –a—— C:\WINDOWS.0\system32\pxafs.dll
2008-01-27 18:15 . 2008-01-04 16:58 9,464 ——— C:\WINDOWS.0\system32\drivers\cdralw2k.sys
2008-01-27 18:15 . 2008-01-04 16:58 9,336 ——— C:\WINDOWS.0\system32\drivers\cdr4_xp.sys
2008-01-27 18:02 . 2008-01-27 18:02 d——– C:\Program Files\Common Files\xing shared
2008-01-24 20:39 . 2008-01-24 21:24 d——– C:\Program Files\FriendBlasterPro
2008-01-24 20:39 . 2005-07-15 12:49 245,760 –a—— C:\WINDOWS.0\system32\aUpdateNow.ocx
2008-01-23 22:54 . 2008-01-23 22:56 d——– C:\Program Files\Oberon Media
2008-01-23 13:34 . 2008-01-23 13:42 d——– C:\WINDOWS.0\system32\nGpxx01
2008-01-23 13:34 . 2008-02-02 22:09 d—-c— C:\Temp
2008-01-19 16:30 . 2008-01-19 16:30 d——– C:\Program Files\Magic Traffic Bot
2008-01-19 12:16 . 2007-06-25 10:57 171,240 –a—— C:\WINDOWS.0\system32\drivers\mfehidk.sys
2008-01-19 12:16 . 2007-06-25 14:54 71,496 –a—— C:\WINDOWS.0\system32\drivers\mfeavfk.sys
2008-01-19 12:16 . 2007-06-25 10:57 37,480 –a—— C:\WINDOWS.0\system32\drivers\mfesmfk.sys
2008-01-19 12:16 . 2007-06-25 10:57 34,184 –a—— C:\WINDOWS.0\system32\drivers\mfebopk.sys
2008-01-19 12:16 . 2007-06-25 10:57 32,008 –a—— C:\WINDOWS.0\system32\drivers\mferkdk.sys
2008-01-19 12:15 . 2007-03-02 14:16 109,608 –a—— C:\WINDOWS.0\system32\drivers\Mpfp.sys
2008-01-19 12:14 . 2008-01-19 12:15 d——– C:\Program Files\McAfee.com
2008-01-19 12:14 . 2008-01-20 18:38 d——– C:\Program Files\McAfee
2008-01-19 12:14 . 2008-01-19 12:16 d——– C:\Program Files\Common Files\McAfee
2008-01-19 11:46 . 2008-01-19 12:24 d—-c— C:\Documents and Settings\All Users.WINDOWS.0\Application Data\McAfee
2008-01-11 19:59 . 1999-09-07 21:27 244,232 –a—— C:\WINDOWS.0\system32\Msflxgrd.ocx
2008-01-07 20:16 . 2008-01-07 20:16 630,784 –a—— C:\WINDOWS.0\system32\divxdec.ax
2008-01-05 12:32 . 1996-06-09 13:52 34,864 –a—— C:\WINDOWS.0\UNWISE.EXE
2008-01-04 19:28 . 2008-01-04 19:28 266 –ah—– C:\WINDOWS.0\log.vbs
2008-01-04 16:59 . 2008-01-04 16:59 524,288 –a—— C:\WINDOWS.0\system32\DivXsm.exe
2008-01-04 16:59 . 2008-01-04 16:59 4,816 –a—— C:\WINDOWS.0\system32\divxsm.tlb
2008-01-04 16:58 . 2008-01-04 16:58 3,596,288 –a—— C:\WINDOWS.0\system32\qt-dx331.dll
2008-01-04 16:58 . 2008-01-04 16:58 1,044,480 –a—— C:\WINDOWS.0\system32\libdivx.dll
2008-01-04 16:58 . 2008-01-04 16:58 200,704 –a—— C:\WINDOWS.0\system32\ssldivx.dll
2008-01-04 16:56 . 2008-01-04 16:56 156,992 –a—— C:\WINDOWS.0\system32\DivXCodecVersionChecker.exe
2008-01-04 16:56 . 2008-01-04 16:56 12,288 –a—— C:\WINDOWS.0\system32\DivXWMPExtType.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-02 22:00 ——— dc—-w C:\Documents and Settings\Frankie3\Application Data\OpenOffice.org2
2008-01-27 23:02 ——— d—–w C:\Program Files\Real
2008-01-27 23:01 ——— d—–w C:\Program Files\Common Files\Real
2008-01-24 03:56 ——— dc–a-w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\TEMP
2008-01-20 23:46 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-20 11:51 ——— d—–w C:\Program Files\sitesubmitter
2008-01-19 17:23 ——— dc—-w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Symantec
2008-01-04 21:58 43,528 -c—-w C:\WINDOWS.0\system32\drivers\PxHelp20.sys
2008-01-03 13:03 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-12 12:22 ——— d—–w C:\Program Files\PC TechZone
2007-12-11 12:08 ——— d—–w C:\Program Files\Photodex
2007-12-09 12:26 ——— d—–w C:\Program Files\Invest
2007-12-09 12:25 336 —-a-w C:\Program Files\temp995.bat
2007-12-09 12:25 ——— d—–w C:\Program Files\pdf995
2007-12-09 12:24 ——— d—–w C:\Program Files\JDiSoftware
2007-12-07 14:10 ——— dc—-w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\pdf995
2006-11-20 19:27 81,920 -c–a-w C:\Program Files\Common Files\wrapper-windows-x86-32.dll
2006-11-19 04:03 1,035,090 -c–a-w C:\Program Files\wrar361.exe
2006-01-28 04:17 20,459,766 -c–a-w C:\Program Files\def.phd
2006-01-28 04:17 140,354 -c–a-w C:\Program Files\compupic.jrn
2006-01-23 19:39 5,632 -csha-w C:\Program Files\Thumbs.db
2006-01-09 04:46 5,529,600 -c–a-w C:\Program Files\all.dnt
2006-01-09 04:46 172,032 -c–a-w C:\Program Files\pro.dnt
2006-01-09 04:46 1,634,304 -c–a-w C:\Program Files\if.dnt
2005-12-31 02:50 2,855,552 -c–a-w C:\Program Files\PPView97.exe
2005-12-15 09:09 2,731,008 -c–a-w C:\Program Files\openofficeorg20.msi
2005-12-15 08:14 49,541,055 -c–a-w C:\Program Files\openofficeorg3.cab
2005-12-15 08:14 2,339,756 -c–a-w C:\Program Files\openofficeorg4.cab
2005-12-15 08:10 6,129,372 -c–a-w C:\Program Files\openofficeorg2.cab
2005-12-15 08:10 17,710,073 -c–a-w C:\Program Files\openofficeorg1.cab
2005-11-27 12:59 683,535 -c–a-w C:\Program Files\Recovery_instructions.zip
2004-08-09 20:13 1,852,928 -c–a-w C:\Program Files\ABBYY PDF Transformer 1.0.msi
2004-08-05 09:08 92,160 -c–a-w C:\Program Files\1036.mst
2004-08-05 09:08 81,920 -c–a-w C:\Program Files\1029.mst
2004-08-05 09:08 76,288 -c–a-w C:\Program Files\1031.mst
2004-08-05 09:08 74,752 -c–a-w C:\Program Files\1040.mst
2004-08-05 09:08 74,752 -c–a-w C:\Program Files\1038.mst
2004-08-05 09:08 71,680 -c–a-w C:\Program Files\1045.mst
2004-08-05 09:08 71,680 -c–a-w C:\Program Files\1043.mst
2004-08-05 09:08 71,680 -c–a-w C:\Program Files\1034.mst
2004-08-05 09:08 38,619,860 -c–a-w C:\Program Files\Data1.cab
2004-08-05 09:08 3,584 -c–a-w C:\Program Files\1033.mst
2004-08-05 09:08 121,856 -c–a-w C:\Program Files\1049.mst
2004-08-05 01:15 285 -c–a-w C:\Program Files\setup.ini
2003-10-03 03:30 4,979,304 -c–a-w C:\Program Files\t-c623x0.zip
2002-03-11 15:06 1,822,520 -c–a-w C:\Program Files\instmsiw.exe
2002-03-11 14:45 1,708,856 -c–a-w C:\Program Files\instmsia.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW4"="C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24 286720]
"NvCplDaemon"="C:\WINDOWS.0\system32\NvCpl.dll" [2006-10-22 12:22 7700480]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS.0^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"freenet-darknet-8889-8888"=2 (0x2)

S0 viamraid;viamraid;C:\WINDOWS.0\system32\DRIVERS\viamraid.sys []
S3 ICAM3NT5;Intel USB Video Camera III;C:\WINDOWS.0\system32\Drivers\Icam3.sys [2001-08-17 09:05]
S3 NUVision;Pinnacle DVC 80 Video;C:\WINDOWS.0\system32\DRIVERS\nuvvid2.sys [2001-12-03 13:55]
S3 Wdm1;USB Bridge Cable Driver;C:\WINDOWS.0\system32\Drivers\usbbc.sys [2001-01-07 20:53]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-02 08:00:01 C:\WINDOWS.0\Tasks\012008scan.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-01-30 03:49:05 C:\WINDOWS.0\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-04 15:31:33 C:\WINDOWS.0\Tasks\LifeChatTask.job"
- C:\Program Files\Microsoft LifeChat\LifeChat.exe
"2008-02-02 04:31:41 C:\WINDOWS.0\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe)
"2008-02-01 06:00:21 C:\WINDOWS.0\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-02 22:15:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS.0\system32\netdde.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VirusScan\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VirusScan\mcshield.exe
C:\PROGRA~1\McAfee\VirusScan\mcsysmon.exe
C:\WINDOWS.0\system32\nvsvc32.exe
C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
C:\WINDOWS.0\system32\wdfmgr.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-02-02 22:18:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-03 03:18:39
ComboFix2.txt 2008-02-03 02:25:09

———————————————————
HJT Log
——————————————————–
Logfile of HijackThis v1.99.1
Scan saved at 10:21:03 PM, on 2/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\WINDOWS.0\Explorer.EXE
C:\WINDOWS.0\system32\netdde.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VirusScan\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VirusScan\mcshield.exe
C:\PROGRA~1\McAfee\VirusScan\mcsysmon.exe
C:\WINDOWS.0\system32\nvsvc32.exe
C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
C:\WINDOWS.0\system32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS.0\system32\wuauclt.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS.0\system32\notepad.exe
C:\Documents and Settings\Frankie3\Desktop\Spyware.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\virusscan\scriptcl.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS.0\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O15 - Trusted Zone: http://microsite.coupons.com
O15 - Trusted Zone: http://www.bricks.coupons.com
O15 - Trusted Zone: http://www.ebay.com
O15 - Trusted Zone: http://s72.photobucket.com
O15 - Trusted Zone: http://www.pyzam.com
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VirusScan\mcsysmon.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS.0\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI