This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Blue screen warning

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I recently had this happen to me my backround was blue and said Blue screen warning:spyware threat has been detected on your pc. I checked the forums and found something so heres the results and thanks a lot.


ComboFix 08-02.05.3 - valuable customer 2008-02-06 19:35:04.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2578 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\nnnmljg.dll
C:\Documents and Settings\All Users\Application Data.\gtaxsxof.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Michael\Application Data\inst.exe
C:\Documents and Settings\Michael\Application Data\ShoppingReport
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Program Files\3721
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\Accoona
C:\Program Files\Accoona\ASearchAssist.dll
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.dat
C:\Program Files\akl\unsetup.exe
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\e-zshopper
C:\Program Files\e-zshopper\BarLcher.dll
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\absolute key logger.lnk
C:\WINDOWS\aconti.exe
C:\WINDOWS\aconti.ini
C:\WINDOWS\aconti.log
C:\WINDOWS\aconti.sdb
C:\WINDOWS\acontidialer.txt
C:\WINDOWS\adbar.dll
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\default.htm
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\OPTIONS\CABS\_desktop.ini
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\acespy
C:\WINDOWS\system32\acespy\__acelog.ndx
C:\WINDOWS\system32\acespy\systune.exe
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\system32\nnnmljg.dll
C:\WINDOWS\system32\sysmwwod.dll
C:\WINDOWS\system32\sysogg.dll
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xqtkpadw.dll
C:\WINDOWS\xxxvideo.exe

—– BITS: Possible infected sites —–

hxxp://softworldnetwork.com
hxxp://softworldnetwork2.com
.
((((((((((((((((((((((((( Files Created from 2008-01-07 to 2008-02-07 )))))))))))))))))))))))))))))))
.

2008-02-06 19:17 . 2008-02-06 19:17 268 –ah—– C:\sqmdata16.sqm
2008-02-06 19:17 . 2008-02-06 19:17 244 –ah—– C:\sqmnoopt16.sqm
2008-02-06 19:02 . 2008-02-06 19:02 268 –ah—– C:\sqmdata15.sqm
2008-02-06 19:02 . 2008-02-06 19:02 244 –ah—– C:\sqmnoopt15.sqm
2008-02-06 18:36 . 2008-02-06 18:36 3,793,862 –a—— C:\WINDOWS\zwFqOxVylq.exe
2008-02-06 18:35 . 2008-02-06 18:46 d——– C:\WINDOWS\cblmwrrl
2008-02-06 18:35 . 2008-02-06 18:35 256,000 –a—— C:\WINDOWS\system32\apiuser32.dll
2008-02-06 18:35 . 2008-02-06 18:35 184,832 –a—— C:\WINDOWS\mfcliryx.dll
2008-02-06 18:35 . 2008-02-06 18:35 89,617 –a—— C:\WINDOWS\system32\rxjddnvj.exe
2008-02-06 18:35 . 2008-02-06 18:35 89,617 –a—— C:\WINDOWS\lelezwro.exe
2008-02-06 18:35 . 2008-02-06 18:35 58,368 –a—— C:\wpohl.exe
2008-02-06 18:35 . 2008-02-06 18:35 54,764 –a—— C:\WINDOWS\system32\jnhjkfrn
2008-02-06 18:35 . 2008-02-06 18:35 39,424 –a—— C:\WINDOWS\wpydgfwj.exe
2008-02-06 18:35 . 2008-02-06 18:35 32,768 –a—— C:\arbfikac.exe
2008-02-06 18:35 . 2008-02-06 18:35 3,584 –a—— C:\qrwkjyd.exe
2008-02-05 16:03 . 2008-02-05 16:03 d——– C:\Documents and Settings\Jason\WINDOWS
2008-02-04 17:07 . 2008-02-04 17:24 d——– C:\Program Files\Wolfenstein - Enemy Territory
2008-02-03 00:08 . 2008-02-04 20:48 d——– C:\vcs5BGEffects
2008-02-03 00:06 . 2008-02-03 00:16 d——– C:\Program Files\AV Vcs 6.0 DIAMOND
2008-02-02 21:01 . 2008-02-02 21:01 dr-h—– C:\Documents and Settings\Mike's Mom\Application Data\SecuROM
2008-02-02 12:10 . 2008-02-02 12:10 dr-h—– C:\Documents and Settings\Guest\Application Data\SecuROM
2008-02-02 00:18 . 2008-02-02 00:18 dr-h—– C:\Documents and Settings\Jason\Application Data\SecuROM
2008-01-31 20:50 . 2008-01-31 20:50 d——– C:\Program Files\RivaTuner v2.06
2008-01-31 15:10 . 2008-01-31 15:10 d——– C:\Program Files\uTorrent
2008-01-31 15:10 . 2008-02-06 15:45 d——– C:\Documents and Settings\Michael\Application Data\uTorrent
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\Common Files\Motive
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\ATT
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Documents and Settings\All Users\Application Data\Motive
2008-01-30 14:54 . 2008-01-30 14:54 268 –ah—– C:\sqmdata14.sqm
2008-01-30 14:54 . 2008-01-30 14:54 244 –ah—– C:\sqmnoopt14.sqm
2008-01-30 14:30 . 2008-01-30 14:30 d——– C:\WINDOWS\ERUNT
2008-01-30 14:26 . 2008-02-06 19:13 d——– C:\SDFix
2008-01-30 14:12 . 2008-01-30 14:12 268 –ah—– C:\sqmdata13.sqm
2008-01-30 14:12 . 2008-01-30 14:12 244 –ah—– C:\sqmnoopt13.sqm
2008-01-30 13:00 . 2008-01-30 13:00 268 –ah—– C:\sqmdata12.sqm
2008-01-30 13:00 . 2008-01-30 13:00 244 –ah—– C:\sqmnoopt12.sqm
2008-01-29 19:32 . 2008-01-29 19:32 268 –ah—– C:\sqmdata11.sqm
2008-01-29 19:32 . 2008-01-29 19:32 244 –ah—– C:\sqmnoopt11.sqm
2008-01-26 20:47 . 2008-01-26 20:47 d——– C:\Documents and Settings\Jason\.jagex_cache_32
2008-01-26 20:19 . 2008-01-26 20:19 d——– C:\Documents and Settings\Michael\Application Data\EPSON
2008-01-22 22:45 . 2008-01-27 22:05 d——– C:\Program Files\DNA
2008-01-22 22:45 . 2008-01-25 12:47 d——– C:\Documents and Settings\Michael\Application Data\BitTorrent
2008-01-21 00:59 . 2008-01-21 00:59 244 –ah—– C:\sqmnoopt10.sqm
2008-01-21 00:59 . 2008-01-21 00:59 232 –ah—– C:\sqmdata10.sqm
2008-01-17 16:13 . 2008-01-17 16:47 d——– C:\HLServer
2008-01-17 16:02 . 2008-01-17 16:46 d——– C:\Documents and Settings\Michael\Application Data\GetRightToGo
2008-01-17 14:16 . 2008-01-17 14:16 268 –ah—– C:\sqmdata09.sqm
2008-01-17 14:16 . 2008-01-17 14:16 244 –ah—– C:\sqmnoopt09.sqm
2008-01-12 13:22 . 2008-01-12 13:22 d——– C:\Documents and Settings\Mike's Mom\Application Data\Disney Interactive Studios
2008-01-09 17:30 . 2008-01-09 17:30 d——– C:\Documents and Settings\Jason\Application Data\Disney Interactive Studios
2008-01-07 23:24 . 2008-01-24 13:28 d——– C:\HammerAutosave

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-07 02:11 ——— d—–w C:\Documents and Settings\Michael\Application Data\LimeWire
2008-02-07 00:39 ——— d—–w C:\Program Files\Steam
2008-02-06 23:46 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-06 23:24 ——— d—–w C:\Program Files\HP
2008-02-06 01:14 ——— d—–w C:\Program Files\AIMTunes
2008-02-05 13:06 ——— d—–w C:\Program Files\WinTV
2008-02-03 20:54 6,776 —-a-w C:\Documents and Settings\All Users\Application Data\ypinfo.bin
2008-02-01 23:15 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-01 23:15 ——— d—–w C:\Program Files\Sierra
2008-01-30 22:51 ——— d—–w C:\Program Files\Real
2008-01-29 21:05 ——— d—–w C:\Documents and Settings\Michael\Application Data\Xfire
2008-01-17 23:58 ——— d—–w C:\Documents and Settings\Michael\Application Data\IGN_DLM
2008-01-07 05:34 ——— d—–w C:\Documents and Settings\Michael\Application Data\Disney Interactive Studios
2008-01-07 01:59 ——— d—–w C:\Documents and Settings\Jason\Application Data\Ahead
2007-12-31 15:21 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\DivX
2007-12-30 20:45 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\Yahoo!
2007-12-30 06:54 ——— d—–w C:\Program Files\Audacity
2007-12-26 06:55 ——— d—–w C:\Program Files\ACE-HIGH MP3 WAV WMA OGG Converter
2007-12-26 06:52 ——— d—–w C:\Program Files\MP3 Converter Simple
2007-12-23 16:24 ——— d—–w C:\Program Files\QuickTime
2007-12-22 23:37 ——— d—–w C:\Program Files\iTunes
2007-12-22 23:37 ——— d—–w C:\Program Files\iPod
2007-12-22 23:11 ——— d—–w C:\Program Files\Common Files\Download Manager
2007-12-22 02:35 ——— d—–w C:\Program Files\AV Vcs 5.0 DIAMOND
2007-12-20 01:56 ——— d—–w C:\Program Files\Illustrate
2007-12-17 01:02 ——— d—–w C:\Documents and Settings\Jason\Application Data\DivX
2007-12-14 22:17 ——— d—–w C:\Program Files\DivX
2007-12-12 01:12 ——— d—–w C:\Documents and Settings\valuable customer\Application Data\HP
2007-12-10 07:00 ——— d—–w C:\Program Files\OOBOX
2007-12-09 19:48 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Xfire
2007-12-07 21:21 ——— d—–w C:\Documents and Settings\Michael\Application Data\HP
2007-12-07 06:06 ——— d—–w C:\Documents and Settings\Jason\Application Data\Apple Computer
2007-12-07 04:08 ——— d—–w C:\Documents and Settings\Jason\Application Data\HP
2007-12-07 02:28 ——— d—–w C:\Program Files\Common Files\xing shared
2007-12-07 02:28 ——— d—–w C:\Program Files\Common Files\Real
2007-12-03 06:52 47,360 —-a-w C:\Documents and Settings\Michael\Application Data\pcouffin.sys
2007-12-03 06:43 356,352 —-a-w C:\WINDOWS\eSellerateEngine.dll
2007-10-11 03:05 22,328 —-a-w C:\Documents and Settings\Michael\Application Data\PnkBstrK.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}]
C:\Program Files\Helper\1202351811.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 17:05 143360]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 16:43 4670704]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 13:57 1103480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 01:33 16132608 C:\WINDOWS\RTHDCPL.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 23:43 8466432]
"nwiz"="nwiz.exe" [2007-06-28 23:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-28 23:43 81920]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 17:08 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 17:09 842584]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 08:30 81920]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" [ ]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 15:19 129536]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 23:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2007-06-26 12:48 509224]
"YPC"="C:\PROGRA~1\Yahoo!\PARENT~1\ypc.exe" [2005-02-11 17:14 352256]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2006-09-08 15:47 277296]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51 39792]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2007-11-06 19:09 166304]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-06 18:28 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]
"drmsrv32"="c:\arbfikac.exe" [2008-02-06 18:35 32768]

C:\Documents and Settings\Guest\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

C:\Documents and Settings\Mike's Mom\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

C:\Documents and Settings\valuable customer\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoStart IR.lnk - C:\Program Files\WinTV\Ir.exe [2007-10-10 16:33:07 106551]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 21:44:08 257752]
Wireless Configuration Utility HW.14.lnk - C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe [2007-06-07 17:05:22 634880]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 12:11 233472]

R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2006-09-08 15:47]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 13:38]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-06 18:58]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-06 19:09]
R3 hcw18bda;Hauppauge WinTV 418 Driver;C:\WINDOWS\system32\drivers\hcw18bda.sys [2007-05-10 10:43]
R3 MSHUSBVideo;NX6000 Filter Driver;C:\WINDOWS\system32\Drivers\nx6000.sys [2006-08-23 16:33]
S2 RCService;RCService;"C:\Program Files\gigabyte\RCService\RCService.exe" []
S3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys []
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2007-09-25 17:18]
S3 HauppaugeTVServer;HauppaugeTVServer;C:\PROGRA~1\WinTV\HCWTVS~1.EXE [2007-02-20 14:11]
S3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;C:\WINDOWS\system32\DRIVERS\RTL8187B.sys [2007-05-04 04:40]
S3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2002-10-01 17:57]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-06 19:10]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\AutoRun.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-01-31 05:00:00 C:\WINDOWS\Tasks\!Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-02-01 04:00:00 C:\WINDOWS\Tasks\!smallville.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-01-31 06:01:12 C:\WINDOWS\Tasks\Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\BGRecorder.exeC -c3 -ntod -startr:Bionic_Woman_1114_2100###.mpg -qdef -limit:3660
"2008-02-07 03:38:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-01 04:06:04 C:\WINDOWS\Tasks\smallville.job"
- C:\PROGRA~1\WinTV\BGRecorder.exe8 -c12 -ntod -startr:smallville###.mpg -qdef -limit:3600
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-06 19:40:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\Program Files\Zune\ZuneNss.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\system32\YPCSER~1.EXE
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Desktop Search\WindowsSearchFilter.exe
.
**************************************************************************
.
Completion time: 2008-02-06 19:44:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-07 03:44:30
.
2008-01-09 07:46:14 — E O F —
Your post has been Moved, Closed or Edited for one of the following reasons:

1.) You posted multiple topics and only one is required

2.) You are spamming links to other places without approval

3.) You have posted your hijackthis log to the wrong forum:
( http://forums.whatthetech.com/HijackThis_L…emoval_f27.html ) <— correct forum for HijackThis Logs

4.) Abusive language or other problems in your text

5.) Your log is too old (20 days or more) and no replies from you after a volunteer tried to help you

If you came here for help, and you have not posted a Hijackthis log to the proper forum, then you may do so now, if you came here to spam or abuse, you will be dealt with harsher on your next offense

This is a family oriented forum to help those that need help.

==============================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI