This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] SPYware Infection= Herpes

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has contracted some spyware. this little screen pops up that says my comp is infected, and seems to randomly install the program. Awola onto the computer. And this seems to stop certain programs on my computer from working. I tried to reinstall Quicktime, and it wont let me. I click on the program to turn on, and it just doesn't!!!

HELP!

here's my Log:

————————

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 03:47, on 2008-02-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\AVENGINE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\AIM\aim.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\HP_Administrator\Application Data\uldnqceywl.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Deluxe\MiniMavis.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Wacom\TabUserW.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\WebProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Java\jre1.5.0\bin\jucheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ign.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [31fbd9b7] rundll32.exe "C:\WINDOWS\system32\rqkxwjvf.dll",b
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Microsft Windows Adapter 5.1.3013] C:\Documents and Settings\HP_Administrator\Application Data\uldnqceywl.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MiniMavis.lnk = C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Deluxe\MiniMavis.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O4 - Global Startup: TabUserW.lnk = C:\Program Files\Wacom\TabUserW.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n035p/EN/install/gtdownlr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab?s6
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe

–
End of file - 11927 bytes
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

As I am still training, my posts to you will be checked by an Expert member. This will ensure that all advice and instructions I give you are accurate and safe. This may mean that my replies may take a little longer.

jpshortstuff
Hi

You need to disable TeaTimer, so that it doesn't interfere with our fix.

This is a two step process.
First step:
  • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
  • If you have the new version 1.5, click once on Resident Protection, then right-click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
  • If you have Version 1.4, Click on Exit Spybot S&D Resident
Second step, For both versions :
  • Open Spybot S&D
  • Click Mode, choose Advanced Mode
  • Go to the bottom of the vertical panel on the left, click Tools
  • Then, also in left panel, click Resident shows a red/white shield.
  • If your firewall raises a question, say OK
  • In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
  • OK any prompts.
  • Use File, Exit to terminate Spybot
  • Reboot your machine for the changes to take effect.

Download ComboFix by sUBs from here or here

**Save it to your desktop**

Double click on ComboFix.exe & follow the prompts.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


Thanks,

jpshortstuff
I seem to have this issue with ComboFix. I double click on it, I see it process, then it brings up this blue screen, and says its going to start. but it just ends up staying on that blue screen and doesn;t move for like half an hour.
Lets try this.

Click Start >> Run and copy and paste the following into the popup box:
"%userprofile%\desktop\ComboFix.exe" /killall
and then hit enter.


If it still doesn't run, then try it in safe mode:
  • Restart the computer.
  • As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
  • Use the arrow keys to select the Safe mode menu item
  • Press Enter.
Once in safe mode run ComboFix.

Reboot back into normal mode and post the log (found at C:\ComboFix.txt), along with a new HijackThis log.
the combo fix workd on safe mode.

I followed the prompts until a point. then all of a sudden, before I knew it, the machine had restaartedon its own, and it was on normal mode again. I missed anything I could copy or paste. For a while the computer ran like it had absolutely no spyware. then after a few minutes it began to do the usual things wrong. I ran combo fix, yet again in safe mode. And AGAIN it had finished it process and restarted before I even knew what happened.
The comp still has the spyware.


I'll do it again, if you need me to. but here is the hijack log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 04:55, on 2008-02-11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\AVENGINE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\ApvxdWin.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\WebProxy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\HP_Administrator\Application Data\rgfehd.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Deluxe\MiniMavis.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Wacom\TabUserW.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ign.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [combofix] C:\WINDOWS\system32\kmd.exe /c C:\ComboFix(2)\Combobatch.bat
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Microsft Windows Adapter 5.1.3013] C:\Documents and Settings\HP_Administrator\Application Data\vuyuczp.exe
O4 - HKCU\..\Run: [Awola] "C:\Documents and Settings\HP_Administrator\Application Data\Awola\Awola.exe" /MIN
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MiniMavis.lnk = C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Deluxe\MiniMavis.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O4 - Global Startup: TabUserW.lnk = C:\Program Files\Wacom\TabUserW.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n035p/EN/install/gtdownlr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab?s6
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe

–
End of file - 12245 bytes
OM20,

The ComboFix report should have been created and saved automatically. You can find it at:
C:\ComboFix.txt

There may also be a ComboFix2.txt, but I want the one without any numbers.

Please copy and paste the results into a new reply in this topic.

Be aware that the process of cleaning a computer is likely to take many posts and often a few different tools, as is the nature of infections these days.

Thanks.
Found the file. all it had was this ————————————— ComboFix 08-02.05.3 - Administrator 2008-02-11 3:11:45.2 - NTFSx86 MINIMAL Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.801 [GMT -8:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix(2).exe . Unable to gain System Privileges
Ok, we're going to try a slightly different version of ComboFix.

Important:
You must delete all existing copies of ComboFix and this folder:
C:\ComboFix << FOLDER


Download Combofix from the link below. You must rename it before saving it. Save it to your desktop. I suggest that you rename it to Combo-Fix.exe. The tool will suggest that name as default any way.

>> Download ComboFix <<


[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results"
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards.
2. Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.
Notes:
  • Do not mouseclick combofix's window while it's running. That may cause it to stall
  • CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please stay by the machine as it runs, and if any errors occur please try and see what they are so we can pinpoint the problem.

Thanks.
Here's the Combo Fix Log.

_________________________________

ComboFix 08-02-15.1 - HP_Administrator 2008-02-15 15:36:06.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.468 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\Documents and Settings\All Users\Application Data.\ormbqruv.dll
C:\Documents and Settings\HP_Administrator\Application Data\Awola
C:\Documents and Settings\HP_Administrator\Application Data\Awola\Awola.exe
C:\Documents and Settings\HP_Administrator\Application Data\Awola\settings.ini
C:\Documents and Settings\HP_Administrator\Application Data\macromedia\Flash Player\#SharedObjects\G55UB7PQ\www.broadcaster.com
C:\Documents and Settings\HP_Administrator\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\HP_Administrator\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\HP_Administrator\load.exe
C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Awola
C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Awola\Awola Anti-Spyware 6.0.lnk
C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Awola\Uninstall Awola Anti-Spyware 6.0.lnk
C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\qdrloader.exe
C:\Program Files\QdrModule
C:\Program Files\QdrModule\dic.gz
C:\Program Files\QdrModule\kwd.gz
C:\Program Files\QdrModule\QdrModule10.exe
C:\Program Files\QdrPack
C:\Program Files\QdrPack\dicts.gz
C:\Program Files\QdrPack\QdrPack11.exe
C:\Program Files\QdrPack\trgts.gz
C:\WINDOWS\cookies.ini
C:\WINDOWS\ojczufgn.dll
C:\WINDOWS\PerfInfo
C:\WINDOWS\PerfInfo\ma77ge0wvR.exe
C:\WINDOWS\system32\ajumwkdo.ini
C:\WINDOWS\system32\ceasboqh.dll
C:\WINDOWS\system32\cebblggi.ini
C:\WINDOWS\system32\dpemhrss.dll
C:\WINDOWS\system32\fjopfugr.ini
C:\WINDOWS\system32\fvjwxkqr.ini
C:\WINDOWS\system32\gbsukwvf.dll
C:\WINDOWS\system32\gebyyvt.dll
C:\WINDOWS\system32\gtiwrfcy.ini
C:\WINDOWS\system32\gvelmijw.ini
C:\WINDOWS\system32\ieiavoeg.ini
C:\WINDOWS\system32\iggcpeix.ini
C:\WINDOWS\system32\igglbbec.dll
C:\WINDOWS\system32\iortteju.ini
C:\WINDOWS\system32\jjkmp.ini
C:\WINDOWS\system32\jjkmp.ini2
C:\WINDOWS\system32\jydiijbr.ini
C:\WINDOWS\system32\lyeflxnm.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\moskymla.dll
C:\WINDOWS\system32\ocytxcms.ini
C:\WINDOWS\system32\odkwmuja.dll
C:\WINDOWS\system32\ospilkpl.ini
C:\WINDOWS\system32\pmkjj.dll
C:\WINDOWS\system32\qdpsvpjb.ini
C:\WINDOWS\system32\rrutv.ini
C:\WINDOWS\system32\rrutv.ini2
C:\WINDOWS\system32\tuvgetdo.dll
C:\WINDOWS\system32\veowjvon.dll
C:\WINDOWS\system32\wjimlevg.dll
C:\WINDOWS\system32\yfcvwyax.ini
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE








((((((((((((((((((((((((( Files Created from 2008-01-15 to 2008-02-15 )))))))))))))))))))))))))))))))
.

2008-02-15 15:33 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\sjf.exe
2008-02-15 15:31 . 2008-02-15 15:31 268 –ah—– C:\sqmdata11.sqm
2008-02-15 15:31 . 2008-02-15 15:31 244 –ah—– C:\sqmnoopt11.sqm
2008-02-15 15:29 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\swncrht.exe
2008-02-15 15:20 . 2008-02-15 15:20 268 –ah—– C:\sqmdata10.sqm
2008-02-15 15:20 . 2008-02-15 15:20 244 –ah—– C:\sqmnoopt10.sqm
2008-02-14 14:51 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\gggxofzhs.exe
2008-02-14 00:09 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\dhcmcqvs.exe
2008-02-13 03:38 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\wzrnaeznx.exe
2008-02-12 03:26 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\wwna.exe
2008-02-12 02:06 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\fipgdst.exe
2008-02-11 15:04 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\qvghojxyf.exe
2008-02-11 13:02 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\flhtvlqff.exe
2008-02-11 10:41 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\ijdpswev.exe
2008-02-11 04:51 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\vuyuczp.exe
2008-02-11 02:45 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\rgfehd.exe
2008-02-10 10:54 . 2008-02-14 00:13 0 –ahs—- C:\Documents and Settings\HP_Administrator\Application Data\00b4e654d2b925c42d7b002cb9b6f8edf6374330f80ba1e2bc.dat
2008-02-10 09:28 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\sqfadc.exe
2008-02-10 09:08 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\vdguhwyel.exe
2008-02-10 09:03 . 2008-02-11 03:17 60,416 –a—— C:\WINDOWS\system32\drivers\ComboFix.sys
2008-02-10 08:30 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\kquw.exe
2008-02-09 23:28 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\whxrvtyaz.exe
2008-02-09 05:23 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\ftnyqar.exe
2008-02-08 12:34 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\cwzcdjlq.exe
2008-02-08 09:39 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\kvwyka.exe
2008-02-08 07:11 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\bypqztrokzm.exe
2008-02-08 06:35 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\xxhev.exe
2008-02-07 23:59 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\tlsq.exe
2008-02-07 09:26 . 2008-02-10 08:30 22 –a—— C:\WINDOWS\pskt.ini
2008-02-07 04:15 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\zynonssv.exe
2008-02-07 02:23 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\afy.exe
2008-02-06 09:17 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\yvtu.exe
2008-02-06 03:41 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\oyoaiydmazsq.exe
2008-02-05 01:28 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\zjiwbnmkkqni.exe
2008-02-04 04:00 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\gayxjubr.exe
2008-02-03 04:27 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\jcyhjlitgo.exe
2008-02-03 00:25 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\zmrdbwkutl.exe
2008-02-01 00:35 . 2008-02-01 00:35 d——– C:\WINDOWS\system32\LogFiles
2008-02-01 00:33 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\fqjun.exe
2008-01-31 02:32 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\icfh.exe
2008-01-30 23:26 . 2008-01-30 23:26 268 –ah—– C:\sqmdata09.sqm
2008-01-30 23:26 . 2008-01-30 23:26 244 –ah—– C:\sqmnoopt09.sqm
2008-01-30 23:14 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\entlkntkudn.exe
2008-01-28 22:31 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\ozqurflwysq.exe
2008-01-28 03:43 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\ytzapqwnzpvc.exe
2008-01-27 05:14 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\hedyrkqqkjpn.exe
2008-01-26 00:52 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\doiagxv.exe
2008-01-25 00:33 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\hhtjpimzgr.exe
2008-01-24 01:00 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\tvsvksl.exe
2008-01-23 04:30 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\srvp.exe
2008-01-22 02:28 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\ggqg.exe
2008-01-21 00:31 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\awhfzzsxn.exe
2008-01-20 07:19 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\xosdbhkicdu.exe
2008-01-19 12:12 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\tvcviexpwpbg.exe
2008-01-19 00:46 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\ylfgciz.exe
2008-01-17 02:32 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\awymcf.exe
2008-01-16 17:40 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\vdvwfo.exe
2008-01-16 10:49 . 2008-01-16 10:49 d——– C:\Presets
2008-01-15 07:15 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\ukhmqvah.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-15 23:35 297,276 —-a-w C:\WINDOWS\system32\drivers\APPFCONT.DAT.bck
2008-02-15 23:35 297,276 —-a-w C:\WINDOWS\system32\drivers\APPFCONT.DAT
2008-02-15 23:35 1,204 —-a-w C:\WINDOWS\system32\drivers\APPFLTR.CFG.bck
2008-02-15 23:35 1,204 —-a-w C:\WINDOWS\system32\drivers\APPFLTR.CFG
2008-02-15 23:34 13,880 —-a-w C:\WINDOWS\system32\drivers\COMFiltr.sys
2008-02-08 17:35 ——— d—–w C:\Program Files\Ahead
2008-01-15 16:21 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
2008-01-11 05:18 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\DivX
2008-01-10 04:49 ——— d—–w C:\Program Files\DivX
2007-12-31 20:18 8,711 —-a-w C:\JkLC.exe
2007-12-31 20:17 3,638 —-a-w C:\info.exe
2007-12-19 08:13 ——— d—–w C:\Program Files\Lavasoft
2007-12-18 21:50 ——— d—–w C:\Program Files\Trend Micro
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-17 08:16 ——— d—–w C:\Program Files\IObit
2007-12-16 10:34 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-16 10:29 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\zqwmggm.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\znijd.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\zmu.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\yznp.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\ysshg.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\yodv.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\xsn.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\xgbr.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\wuiqtpwba.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\whqfnoslbg.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\whglsxpsjtjs.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\wgjvsl.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\vtvluq.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\vljjorw.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\velwhcpmylt.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\uldnqceywl.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\uczqjfl.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\tmedvvnupm.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\tjjvka.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\ssmm.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\siwbozcvt.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\sinornq.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\shhupbcwzfo.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\rmhywgehplsc.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\rifdgbgk.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\rcaemtf.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\qiksmniobd.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\qhpxlrjtomr.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\ovmznz.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\oeswra.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\nkw.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\mrhtz.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\lznhlfnwzne.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\lxsxd.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\lrcydnitin.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\lnadvfmtepgq.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\lfxhmdn.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\lehqapom.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\lanclx.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\koxfnbfufsdx.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\jpdk.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\jmd.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\jlnhp.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\izpbgmrmczvb.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\izanw.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\iytbnk.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\ifjxjsroud.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\heti.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\gtyxwurgj.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\glzwk.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\ggaryoxfce.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\gbpdouyylnu.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\fqlo.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\famkk.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\esux.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\ekk.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\efjkbsuqe.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\dwewbmll.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\dlncmvly.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\djcbcot.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\dcqr.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\cnxs.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\cdlzdpployvp.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\bvbkaj.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\azaumhm.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\akl.exe
2007-12-15 09:30 12,800 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\ablyankpg.exe
2007-12-07 14:37 3,059,200 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-07 01:07 96,256 —-a-w C:\WINDOWS\system32\dllcache\inseng.dll
2007-12-07 01:07 659,456 —-a-w C:\WINDOWS\system32\wininet.dll
2007-12-07 01:07 659,456 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-12-07 01:07 615,424 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-12-07 01:07 55,808 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-12-07 01:07 532,480 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-12-07 01:07 474,112 —-a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-12-07 01:07 449,024 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-12-07 01:07 39,424 —-a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-12-07 01:07 357,888 —-a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-07 01:07 251,392 —-a-w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-12-07 01:07 205,312 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-12-07 01:07 16,384 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-12-07 01:07 151,040 —-a-w C:\WINDOWS\system32\dllcache\cdfview.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-25 07:57 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 04:00 15360]
"AIM"="C:\Program Files\AIM\aim.exe" [2005-08-05 14:08 67160]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 15:24 1694208]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2007-11-01 13:22 3317760]
"Microsft Windows Adapter 5.1.3013"="C:\Documents and Settings\HP_Administrator\Application Data\sjf.exe" [2007-12-15 01:30 12800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 10:04 59392]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 22:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-12-01 09:55 126976]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 21:34 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 12:54 253952]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-06-29 06:14 180269]
"APVXDWIN"="C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.exe" [2007-07-19 15:23 455984]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-06-29 06:24 98304]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-06 23:33 8720384]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-08-27 17:34:58 113664]
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-21 19:42:22 45056]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-05 01:28:24 258048]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
MiniMavis.lnk - C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Deluxe\MiniMavis.exe [2005-08-31 00:24:58 2392064]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2000-08-06 01:03:20 69632]
SpySubtract.lnk - C:\Program Files\InterMute\SpySubtract\sslaunch.exe [2005-06-29 06:26:37 73728]
TabUserW.lnk - C:\Program Files\Wacom\TabUserW.exe [2005-08-27 16:04:49 77824]
Updates from HP.lnk - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe [2005-06-29 06:27:39 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 2007-02-15 20:02 50736 C:\WINDOWS\system32\avldr.dll

R1 APPFLT;App Filter Plugin;C:\WINDOWS\system32\Drivers\APPFLT.SYS [2007-05-11 09:33]
R1 DSAFLT;DSA Filter Plugin;C:\WINDOWS\system32\Drivers\DSAFLT.SYS [2007-05-11 09:33]
R1 FNETMON;NetMon Filter Plugin;C:\WINDOWS\system32\Drivers\fnetmon.SYS [2007-05-11 09:33]
R1 IDSFLT;Ids Filter Plugin;C:\WINDOWS\system32\Drivers\IDSFLT.SYS [2007-07-11 11:39]
R1 NETFLTDI;Panda Net Driver [TDI Layer];C:\WINDOWS\system32\Drivers\NETFLTDI.SYS [2007-05-11 09:33]
R1 SMSFLT;SMS Filter Plugin;C:\WINDOWS\system32\Drivers\SMSFLT.SYS [2007-05-11 09:33]
R1 WNMFLT;Wifi Monitor Filter Plugin;C:\WINDOWS\system32\Drivers\WNMFLT.SYS [2007-05-11 09:33]
R2 cpoint;Panda CPoint Driver;C:\WINDOWS\system32\Drivers\cpoint.sys [2007-06-08 08:44]
R3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys []
R3 NETIMFLT;PANDA NDIS IM Filter Miniport;C:\WINDOWS\system32\DRIVERS\netimflt.sys [2007-04-24 15:43]
R3 PavSRK.sys;PavSRK.sys;C:\WINDOWS\system32\PavSRK.sys []
R3 PavTPK.sys;PavTPK.sys;C:\WINDOWS\system32\PavTPK.sys []
S1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\DRIVERS\ShlDrv51.sys []
S2 PavProc;Panda Process Protection Driver;C:\WINDOWS\system32\DRIVERS\PavProc.sys []
S3 AFW;AFW;C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\00175e2d.sys []
S4 itheioe6ecz1x5c;Print Spooler Service;C:\WINDOWS\system32\yofblo.exe []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

.
Contents of the 'Scheduled Tasks' folder
"2008-02-15 23:42:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-14 09:49:00 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-02-07 11:00:00 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-15 15:40:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-15 15:44:32
ComboFix-quarantined-files.txt 2008-02-15 23:44:29
.
2008-02-12 11:03:09 — E O F —






and…here is the Hijack Log


________________________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:47:30 PM, on 2/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\AVENGINE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Documents and Settings\HP_Administrator\Application Data\swncrht.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Deluxe\MiniMavis.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Wacom\TabUserW.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\explorer.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ign.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Microsft Windows Adapter 5.1.3013] C:\Documents and Settings\HP_Administrator\Application Data\sjf.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MiniMavis.lnk = C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Deluxe\MiniMavis.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O4 - Global Startup: TabUserW.lnk = C:\Program Files\Wacom\TabUserW.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n035p/EN/install/gtdownlr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab?s6
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe

–
End of file - 12007 bytes
Hi


1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

http://forums.whatthetech.com/SPYware_Infection_Herpes_t88582.html

Collect::
C:\JkLC.exe
C:\info.exe

File::
C:\Documents and Settings\HP_Administrator\Application Data\sjf.exe
C:\sqmdata11.sqm
C:\sqmnoopt11.sqm
C:\Documents and Settings\HP_Administrator\Application Data\swncrht.exe
C:\sqmdata10.sqm
C:\sqmnoopt10.sqm
C:\Documents and Settings\HP_Administrator\Application Data\gggxofzhs.exe
C:\Documents and Settings\HP_Administrator\Application Data\dhcmcqvs.exe
C:\Documents and Settings\HP_Administrator\Application Data\wzrnaeznx.exe
C:\Documents and Settings\HP_Administrator\Application Data\wwna.exe
C:\Documents and Settings\HP_Administrator\Application Data\fipgdst.exe
C:\Documents and Settings\HP_Administrator\Application Data\qvghojxyf.exe
C:\Documents and Settings\HP_Administrator\Application Data\flhtvlqff.exe
C:\Documents and Settings\HP_Administrator\Application Data\ijdpswev.exe
C:\Documents and Settings\HP_Administrator\Application Data\vuyuczp.exe
C:\Documents and Settings\HP_Administrator\Application Data\rgfehd.exe
C:\Documents and Settings\HP_Administrator\Application Data\00b4e654d2b925c42d7b002cb9b6f8edf6374330f80ba1e2bc.dat
C:\Documents and Settings\HP_Administrator\Application Data\sqfadc.exe
C:\Documents and Settings\HP_Administrator\Application Data\vdguhwyel.exe
C:\Documents and Settings\HP_Administrator\Application Data\kquw.exe
C:\Documents and Settings\HP_Administrator\Application Data\whxrvtyaz.exe
C:\Documents and Settings\HP_Administrator\Application Data\ftnyqar.exe
C:\Documents and Settings\HP_Administrator\Application Data\cwzcdjlq.exe
C:\Documents and Settings\HP_Administrator\Application Data\kvwyka.exe
C:\Documents and Settings\HP_Administrator\Application Data\bypqztrokzm.exe
C:\Documents and Settings\HP_Administrator\Application Data\xxhev.exe
C:\Documents and Settings\HP_Administrator\Application Data\tlsq.exe
C:\WINDOWS\pskt.ini
C:\Documents and Settings\HP_Administrator\Application Data\zynonssv.exe
C:\Documents and Settings\HP_Administrator\Application Data\afy.exe
C:\Documents and Settings\HP_Administrator\Application Data\yvtu.exe
C:\Documents and Settings\HP_Administrator\Application Data\oyoaiydmazsq.exe
C:\Documents and Settings\HP_Administrator\Application Data\zjiwbnmkkqni.exe
C:\Documents and Settings\HP_Administrator\Application Data\gayxjubr.exe
C:\Documents and Settings\HP_Administrator\Application Data\jcyhjlitgo.exe
C:\Documents and Settings\HP_Administrator\Application Data\zmrdbwkutl.exe
C:\Documents and Settings\HP_Administrator\Application Data\fqjun.exe
C:\Documents and Settings\HP_Administrator\Application Data\icfh.exe
C:\sqmdata09.sqm
C:\sqmnoopt09.sqm
C:\Documents and Settings\HP_Administrator\Application Data\entlkntkudn.exe
C:\Documents and Settings\HP_Administrator\Application Data\ozqurflwysq.exe
C:\Documents and Settings\HP_Administrator\Application Data\ytzapqwnzpvc.exe
C:\Documents and Settings\HP_Administrator\Application Data\hedyrkqqkjpn.exe
C:\Documents and Settings\HP_Administrator\Application Data\doiagxv.exe
C:\Documents and Settings\HP_Administrator\Application Data\hhtjpimzgr.exe
C:\Documents and Settings\HP_Administrator\Application Data\tvsvksl.exe
C:\Documents and Settings\HP_Administrator\Application Data\srvp.exe
C:\Documents and Settings\HP_Administrator\Application Data\ggqg.exe
C:\Documents and Settings\HP_Administrator\Application Data\awhfzzsxn.exe
C:\Documents and Settings\HP_Administrator\Application Data\xosdbhkicdu.exe
C:\Documents and Settings\HP_Administrator\Application Data\tvcviexpwpbg.exe
C:\Documents and Settings\HP_Administrator\Application Data\ylfgciz.exe
C:\Documents and Settings\HP_Administrator\Application Data\awymcf.exe
C:\Documents and Settings\HP_Administrator\Application Data\vdvwfo.exe
C:\Documents and Settings\HP_Administrator\Application Data\ukhmqvah.exe
C:\Documents and Settings\HP_Administrator\Application Data\zqwmggm.exe
C:\Documents and Settings\HP_Administrator\Application Data\znijd.exe
C:\Documents and Settings\HP_Administrator\Application Data\zmu.exe
C:\Documents and Settings\HP_Administrator\Application Data\yznp.exe
C:\Documents and Settings\HP_Administrator\Application Data\ysshg.exe
C:\Documents and Settings\HP_Administrator\Application Data\yodv.exe
C:\Documents and Settings\HP_Administrator\Application Data\xsn.exe
C:\Documents and Settings\HP_Administrator\Application Data\xgbr.exe
C:\Documents and Settings\HP_Administrator\Application Data\wuiqtpwba.exe
C:\Documents and Settings\HP_Administrator\Application Data\whqfnoslbg.exe
C:\Documents and Settings\HP_Administrator\Application Data\whglsxpsjtjs.exe
C:\Documents and Settings\HP_Administrator\Application Data\wgjvsl.exe
C:\Documents and Settings\HP_Administrator\Application Data\vtvluq.exe
C:\Documents and Settings\HP_Administrator\Application Data\vljjorw.exe
C:\Documents and Settings\HP_Administrator\Application Data\velwhcpmylt.exe
C:\Documents and Settings\HP_Administrator\Application Data\uldnqceywl.exe
C:\Documents and Settings\HP_Administrator\Application Data\uczqjfl.exe
C:\Documents and Settings\HP_Administrator\Application Data\tmedvvnupm.exe
C:\Documents and Settings\HP_Administrator\Application Data\tjjvka.exe
C:\Documents and Settings\HP_Administrator\Application Data\ssmm.exe
C:\Documents and Settings\HP_Administrator\Application Data\siwbozcvt.exe
C:\Documents and Settings\HP_Administrator\Application Data\sinornq.exe
C:\Documents and Settings\HP_Administrator\Application Data\shhupbcwzfo.exe
C:\Documents and Settings\HP_Administrator\Application Data\rmhywgehplsc.exe
C:\Documents and Settings\HP_Administrator\Application Data\rifdgbgk.exe
C:\Documents and Settings\HP_Administrator\Application Data\rcaemtf.exe
C:\Documents and Settings\HP_Administrator\Application Data\qiksmniobd.exe
C:\Documents and Settings\HP_Administrator\Application Data\qhpxlrjtomr.exe
C:\Documents and Settings\HP_Administrator\Application Data\ovmznz.exe
C:\Documents and Settings\HP_Administrator\Application Data\oeswra.exe
C:\Documents and Settings\HP_Administrator\Application Data\nkw.exe
C:\Documents and Settings\HP_Administrator\Application Data\mrhtz.exe
C:\Documents and Settings\HP_Administrator\Application Data\lznhlfnwzne.exe
C:\Documents and Settings\HP_Administrator\Application Data\lxsxd.exe
C:\Documents and Settings\HP_Administrator\Application Data\lrcydnitin.exe
C:\Documents and Settings\HP_Administrator\Application Data\lnadvfmtepgq.exe
C:\Documents and Settings\HP_Administrator\Application Data\lfxhmdn.exe
C:\Documents and Settings\HP_Administrator\Application Data\lehqapom.exe
C:\Documents and Settings\HP_Administrator\Application Data\lanclx.exe
C:\Documents and Settings\HP_Administrator\Application Data\koxfnbfufsdx.exe
C:\Documents and Settings\HP_Administrator\Application Data\jpdk.exe
C:\Documents and Settings\HP_Administrator\Application Data\jmd.exe
C:\Documents and Settings\HP_Administrator\Application Data\jlnhp.exe
C:\Documents and Settings\HP_Administrator\Application Data\izpbgmrmczvb.exe
C:\Documents and Settings\HP_Administrator\Application Data\izanw.exe
C:\Documents and Settings\HP_Administrator\Application Data\iytbnk.exe
C:\Documents and Settings\HP_Administrator\Application Data\ifjxjsroud.exe
C:\Documents and Settings\HP_Administrator\Application Data\heti.exe
C:\Documents and Settings\HP_Administrator\Application Data\gtyxwurgj.exe
C:\Documents and Settings\HP_Administrator\Application Data\glzwk.exe
C:\Documents and Settings\HP_Administrator\Application Data\ggaryoxfce.exe
C:\Documents and Settings\HP_Administrator\Application Data\gbpdouyylnu.exe
C:\Documents and Settings\HP_Administrator\Application Data\fqlo.exe
C:\Documents and Settings\HP_Administrator\Application Data\famkk.exe
C:\Documents and Settings\HP_Administrator\Application Data\esux.exe
C:\Documents and Settings\HP_Administrator\Application Data\ekk.exe
C:\Documents and Settings\HP_Administrator\Application Data\efjkbsuqe.exe
C:\Documents and Settings\HP_Administrator\Application Data\dwewbmll.exe
C:\Documents and Settings\HP_Administrator\Application Data\dlncmvly.exe
C:\Documents and Settings\HP_Administrator\Application Data\djcbcot.exe
C:\Documents and Settings\HP_Administrator\Application Data\dcqr.exe
C:\Documents and Settings\HP_Administrator\Application Data\cnxs.exe
C:\Documents and Settings\HP_Administrator\Application Data\cdlzdpployvp.exe
C:\Documents and Settings\HP_Administrator\Application Data\bvbkaj.exe
C:\Documents and Settings\HP_Administrator\Application Data\azaumhm.exe
C:\Documents and Settings\HP_Administrator\Application Data\akl.exe
C:\Documents and Settings\HP_Administrator\Application Data\ablyankpg.exe
C:\WINDOWS\system32\Info.exe
C:\WINDOWS\system32\protect.ed
D:\WINDOWS\system32\Info.exe
D:\WINDOWS\system32\protect.ed
C:\protect.ed

DirLook::
C:\Presets

Driver::
AFW
itheioe6ecz1x5c
AvFlt
PavSRK.sys
PavTPK.sys
ShldDrv
PavProc

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsft Windows Adapter 5.1.3013"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

5. Additonally, ComboFix will generate the following files on your desktop
  • A zipped file on your desktop called Submit [Date Time].zip
  • And another file named - CF-Submit.htm
6. ComboFix may need to reboot to finish its work. Let it.

7. When CF has finished its run, it will generate ComboFix.log which will appear on your screen.

8. Next, a window will popup prompting you to "Submit Files for further analysis". Click "OK"

9. Your system's browser will automatically respond by loading the CF-Submit.htm file and open a window :
  • Click the "Browse" button and locate the Submit [Date Time].zip file on your desktop.
  • Click on the file to Select it.
  • Submit the file by clicking "OK"
10. Once the file has been submitted, you may DELETE both files on your desktop.

11. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.


Please do an online scan with Kaspersky WebScanner

Follow this link in Internet Explorer (Note: You must use Internet explorer to use Kaspersky): Kaspersky WebScanner

You will be prompted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    o Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)

    o Scan Options:
    Scan Archives Scan Mail Bases

  • Click OK
  • Now under select a target to scan:
    Select My Computer
  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    o Now click on the Save as Text button:
  • Save the file to your desktop.

Please post the results of the Kaspersky scan in your next reply, and describe how the computer is running at the moment.

Thanks.
Here's the log from the Combo Fix thing;;;;;;;;;;;;;;;;;;;;;;;;


:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

ComboFix 08-02-15.1 - HP_Administrator 2008-02-16 15:01:37.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.474 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\HP_Administrator\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\Documents and Settings\HP_Administrator\Application Data\00b4e654d2b925c42d7b002cb9b6f8edf6374330f80ba1e2bc.dat
C:\Documents and Settings\HP_Administrator\Application Data\ablyankpg.exe
C:\Documents and Settings\HP_Administrator\Application Data\afy.exe
C:\Documents and Settings\HP_Administrator\Application Data\akl.exe
C:\Documents and Settings\HP_Administrator\Application Data\awhfzzsxn.exe
C:\Documents and Settings\HP_Administrator\Application Data\awymcf.exe
C:\Documents and Settings\HP_Administrator\Application Data\azaumhm.exe
C:\Documents and Settings\HP_Administrator\Application Data\bvbkaj.exe
C:\Documents and Settings\HP_Administrator\Application Data\bypqztrokzm.exe
C:\Documents and Settings\HP_Administrator\Application Data\cdlzdpployvp.exe
C:\Documents and Settings\HP_Administrator\Application Data\cnxs.exe
C:\Documents and Settings\HP_Administrator\Application Data\cwzcdjlq.exe
C:\Documents and Settings\HP_Administrator\Application Data\dcqr.exe
C:\Documents and Settings\HP_Administrator\Application Data\dhcmcqvs.exe
C:\Documents and Settings\HP_Administrator\Application Data\djcbcot.exe
C:\Documents and Settings\HP_Administrator\Application Data\dlncmvly.exe
C:\Documents and Settings\HP_Administrator\Application Data\doiagxv.exe
C:\Documents and Settings\HP_Administrator\Application Data\dwewbmll.exe
C:\Documents and Settings\HP_Administrator\Application Data\efjkbsuqe.exe
C:\Documents and Settings\HP_Administrator\Application Data\ekk.exe
C:\Documents and Settings\HP_Administrator\Application Data\entlkntkudn.exe
C:\Documents and Settings\HP_Administrator\Application Data\esux.exe
C:\Documents and Settings\HP_Administrator\Application Data\famkk.exe
C:\Documents and Settings\HP_Administrator\Application Data\fipgdst.exe
C:\Documents and Settings\HP_Administrator\Application Data\flhtvlqff.exe
C:\Documents and Settings\HP_Administrator\Application Data\fqjun.exe
C:\Documents and Settings\HP_Administrator\Application Data\fqlo.exe
C:\Documents and Settings\HP_Administrator\Application Data\ftnyqar.exe
C:\Documents and Settings\HP_Administrator\Application Data\gayxjubr.exe
C:\Documents and Settings\HP_Administrator\Application Data\gbpdouyylnu.exe
C:\Documents and Settings\HP_Administrator\Application Data\ggaryoxfce.exe
C:\Documents and Settings\HP_Administrator\Application Data\gggxofzhs.exe
C:\Documents and Settings\HP_Administrator\Application Data\ggqg.exe
C:\Documents and Settings\HP_Administrator\Application Data\glzwk.exe
C:\Documents and Settings\HP_Administrator\Application Data\gtyxwurgj.exe
C:\Documents and Settings\HP_Administrator\Application Data\hedyrkqqkjpn.exe
C:\Documents and Settings\HP_Administrator\Application Data\heti.exe
C:\Documents and Settings\HP_Administrator\Application Data\hhtjpimzgr.exe
C:\Documents and Settings\HP_Administrator\Application Data\icfh.exe
C:\Documents and Settings\HP_Administrator\Application Data\ifjxjsroud.exe
C:\Documents and Settings\HP_Administrator\Application Data\ijdpswev.exe
C:\Documents and Settings\HP_Administrator\Application Data\iytbnk.exe
C:\Documents and Settings\HP_Administrator\Application Data\izanw.exe
C:\Documents and Settings\HP_Administrator\Application Data\izpbgmrmczvb.exe
C:\Documents and Settings\HP_Administrator\Application Data\jcyhjlitgo.exe
C:\Documents and Settings\HP_Administrator\Application Data\jlnhp.exe
C:\Documents and Settings\HP_Administrator\Application Data\jmd.exe
C:\Documents and Settings\HP_Administrator\Application Data\jpdk.exe
C:\Documents and Settings\HP_Administrator\Application Data\koxfnbfufsdx.exe
C:\Documents and Settings\HP_Administrator\Application Data\kquw.exe
C:\Documents and Settings\HP_Administrator\Application Data\kvwyka.exe
C:\Documents and Settings\HP_Administrator\Application Data\lanclx.exe
C:\Documents and Settings\HP_Administrator\Application Data\lehqapom.exe
C:\Documents and Settings\HP_Administrator\Application Data\lfxhmdn.exe
C:\Documents and Settings\HP_Administrator\Application Data\lnadvfmtepgq.exe
C:\Documents and Settings\HP_Administrator\Application Data\lrcydnitin.exe
C:\Documents and Settings\HP_Administrator\Application Data\lxsxd.exe
C:\Documents and Settings\HP_Administrator\Application Data\lznhlfnwzne.exe
C:\Documents and Settings\HP_Administrator\Application Data\mrhtz.exe
C:\Documents and Settings\HP_Administrator\Application Data\nkw.exe
C:\Documents and Settings\HP_Administrator\Application Data\oeswra.exe
C:\Documents and Settings\HP_Administrator\Application Data\ovmznz.exe
C:\Documents and Settings\HP_Administrator\Application Data\oyoaiydmazsq.exe
C:\Documents and Settings\HP_Administrator\Application Data\ozqurflwysq.exe
C:\Documents and Settings\HP_Administrator\Application Data\qhpxlrjtomr.exe
C:\Documents and Settings\HP_Administrator\Application Data\qiksmniobd.exe
C:\Documents and Settings\HP_Administrator\Application Data\qvghojxyf.exe
C:\Documents and Settings\HP_Administrator\Application Data\rcaemtf.exe
C:\Documents and Settings\HP_Administrator\Application Data\rgfehd.exe
C:\Documents and Settings\HP_Administrator\Application Data\rifdgbgk.exe
C:\Documents and Settings\HP_Administrator\Application Data\rmhywgehplsc.exe
C:\Documents and Settings\HP_Administrator\Application Data\shhupbcwzfo.exe
C:\Documents and Settings\HP_Administrator\Application Data\sinornq.exe
C:\Documents and Settings\HP_Administrator\Application Data\siwbozcvt.exe
C:\Documents and Settings\HP_Administrator\Application Data\sjf.exe
C:\Documents and Settings\HP_Administrator\Application Data\sqfadc.exe
C:\Documents and Settings\HP_Administrator\Application Data\srvp.exe
C:\Documents and Settings\HP_Administrator\Application Data\ssmm.exe
C:\Documents and Settings\HP_Administrator\Application Data\swncrht.exe
C:\Documents and Settings\HP_Administrator\Application Data\tjjvka.exe
C:\Documents and Settings\HP_Administrator\Application Data\tlsq.exe
C:\Documents and Settings\HP_Administrator\Application Data\tmedvvnupm.exe
C:\Documents and Settings\HP_Administrator\Application Data\tvcviexpwpbg.exe
C:\Documents and Settings\HP_Administrator\Application Data\tvsvksl.exe
C:\Documents and Settings\HP_Administrator\Application Data\uczqjfl.exe
C:\Documents and Settings\HP_Administrator\Application Data\ukhmqvah.exe
C:\Documents and Settings\HP_Administrator\Application Data\uldnqceywl.exe
C:\Documents and Settings\HP_Administrator\Application Data\vdguhwyel.exe
C:\Documents and Settings\HP_Administrator\Application Data\vdvwfo.exe
C:\Documents and Settings\HP_Administrator\Application Data\velwhcpmylt.exe
C:\Documents and Settings\HP_Administrator\Application Data\vljjorw.exe
C:\Documents and Settings\HP_Administrator\Application Data\vtvluq.exe
C:\Documents and Settings\HP_Administrator\Application Data\vuyuczp.exe
C:\Documents and Settings\HP_Administrator\Application Data\wgjvsl.exe
C:\Documents and Settings\HP_Administrator\Application Data\whglsxpsjtjs.exe
C:\Documents and Settings\HP_Administrator\Application Data\whqfnoslbg.exe
C:\Documents and Settings\HP_Administrator\Application Data\whxrvtyaz.exe
C:\Documents and Settings\HP_Administrator\Application Data\wuiqtpwba.exe
C:\Documents and Settings\HP_Administrator\Application Data\wwna.exe
C:\Documents and Settings\HP_Administrator\Application Data\wzrnaeznx.exe
C:\Documents and Settings\HP_Administrator\Application Data\xgbr.exe
C:\Documents and Settings\HP_Administrator\Application Data\xosdbhkicdu.exe
C:\Documents and Settings\HP_Administrator\Application Data\xsn.exe
C:\Documents and Settings\HP_Administrator\Application Data\xxhev.exe
C:\Documents and Settings\HP_Administrator\Application Data\ylfgciz.exe
C:\Documents and Settings\HP_Administrator\Application Data\yodv.exe
C:\Documents and Settings\HP_Administrator\Application Data\ysshg.exe
C:\Documents and Settings\HP_Administrator\Application Data\ytzapqwnzpvc.exe
C:\Documents and Settings\HP_Administrator\Application Data\yvtu.exe
C:\Documents and Settings\HP_Administrator\Application Data\yznp.exe
C:\Documents and Settings\HP_Administrator\Application Data\zjiwbnmkkqni.exe
C:\Documents and Settings\HP_Administrator\Application Data\zmrdbwkutl.exe
C:\Documents and Settings\HP_Administrator\Application Data\zmu.exe
C:\Documents and Settings\HP_Administrator\Application Data\znijd.exe
C:\Documents and Settings\HP_Administrator\Application Data\zqwmggm.exe
C:\Documents and Settings\HP_Administrator\Application Data\zynonssv.exe
C:\protect.ed
C:\sqmdata09.sqm
C:\sqmdata10.sqm
C:\sqmdata11.sqm
C:\sqmnoopt09.sqm
C:\sqmnoopt10.sqm
C:\sqmnoopt11.sqm
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\Info.exe
C:\WINDOWS\system32\protect.ed
D:\WINDOWS\system32\Info.exe
D:\WINDOWS\system32\protect.ed
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\HP_Administrator\Application Data\00b4e654d2b925c42d7b002cb9b6f8edf6374330f80ba1e2bc.dat
C:\Documents and Settings\HP_Administrator\Application Data\ablyankpg.exe
C:\Documents and Settings\HP_Administrator\Application Data\afy.exe
C:\Documents and Settings\HP_Administrator\Application Data\akl.exe
C:\Documents and Settings\HP_Administrator\Application Data\awhfzzsxn.exe
C:\Documents and Settings\HP_Administrator\Application Data\awymcf.exe
C:\Documents and Settings\HP_Administrator\Application Data\azaumhm.exe
C:\Documents and Settings\HP_Administrator\Application Data\bvbkaj.exe
C:\Documents and Settings\HP_Administrator\Application Data\bypqztrokzm.exe
C:\Documents and Settings\HP_Administrator\Application Data\cdlzdpployvp.exe
C:\Documents and Settings\HP_Administrator\Application Data\cnxs.exe
C:\Documents and Settings\HP_Administrator\Application Data\cwzcdjlq.exe
C:\Documents and Settings\HP_Administrator\Application Data\dcqr.exe
C:\Documents and Settings\HP_Administrator\Application Data\dhcmcqvs.exe
C:\Documents and Settings\HP_Administrator\Application Data\djcbcot.exe
C:\Documents and Settings\HP_Administrator\Application Data\dlncmvly.exe
C:\Documents and Settings\HP_Administrator\Application Data\doiagxv.exe
C:\Documents and Settings\HP_Administrator\Application Data\dwewbmll.exe
C:\Documents and Settings\HP_Administrator\Application Data\efjkbsuqe.exe
C:\Documents and Settings\HP_Administrator\Application Data\ekk.exe
C:\Documents and Settings\HP_Administrator\Application Data\entlkntkudn.exe
C:\Documents and Settings\HP_Administrator\Application Data\esux.exe
C:\Documents and Settings\HP_Administrator\Application Data\famkk.exe
C:\Documents and Settings\HP_Administrator\Application Data\fipgdst.exe
C:\Documents and Settings\HP_Administrator\Application Data\flhtvlqff.exe
C:\Documents and Settings\HP_Administrator\Application Data\fqjun.exe
C:\Documents and Settings\HP_Administrator\Application Data\fqlo.exe
C:\Documents and Settings\HP_Administrator\Application Data\ftnyqar.exe
C:\Documents and Settings\HP_Administrator\Application Data\gayxjubr.exe
C:\Documents and Settings\HP_Administrator\Application Data\gbpdouyylnu.exe
C:\Documents and Settings\HP_Administrator\Application Data\ggaryoxfce.exe
C:\Documents and Settings\HP_Administrator\Application Data\gggxofzhs.exe
C:\Documents and Settings\HP_Administrator\Application Data\ggqg.exe
C:\Documents and Settings\HP_Administrator\Application Data\glzwk.exe
C:\Documents and Settings\HP_Administrator\Application Data\gtyxwurgj.exe
C:\Documents and Settings\HP_Administrator\Application Data\hedyrkqqkjpn.exe
C:\Documents and Settings\HP_Administrator\Application Data\heti.exe
C:\Documents and Settings\HP_Administrator\Application Data\hhtjpimzgr.exe
C:\Documents and Settings\HP_Administrator\Application Data\icfh.exe
C:\Documents and Settings\HP_Administrator\Application Data\ifjxjsroud.exe
C:\Documents and Settings\HP_Administrator\Application Data\ijdpswev.exe
C:\Documents and Settings\HP_Administrator\Application Data\iytbnk.exe
C:\Documents and Settings\HP_Administrator\Application Data\izanw.exe
C:\Documents and Settings\HP_Administrator\Application Data\izpbgmrmczvb.exe
C:\Documents and Settings\HP_Administrator\Application Data\jcyhjlitgo.exe
C:\Documents and Settings\HP_Administrator\Application Data\jlnhp.exe
C:\Documents and Settings\HP_Administrator\Application Data\jmd.exe
C:\Documents and Settings\HP_Administrator\Application Data\jpdk.exe
C:\Documents and Settings\HP_Administrator\Application Data\koxfnbfufsdx.exe
C:\Documents and Settings\HP_Administrator\Application Data\kquw.exe
C:\Documents and Settings\HP_Administrator\Application Data\kvwyka.exe
C:\Documents and Settings\HP_Administrator\Application Data\lanclx.exe
C:\Documents and Settings\HP_Administrator\Application Data\lehqapom.exe
C:\Documents and Settings\HP_Administrator\Application Data\lfxhmdn.exe
C:\Documents and Settings\HP_Administrator\Application Data\lnadvfmtepgq.exe
C:\Documents and Settings\HP_Administrator\Application Data\lrcydnitin.exe
C:\Documents and Settings\HP_Administrator\Application Data\lxsxd.exe
C:\Documents and Settings\HP_Administrator\Application Data\lznhlfnwzne.exe
C:\Documents and Settings\HP_Administrator\Application Data\mrhtz.exe
C:\Documents and Settings\HP_Administrator\Application Data\nkw.exe
C:\Documents and Settings\HP_Administrator\Application Data\oeswra.exe
C:\Documents and Settings\HP_Administrator\Application Data\ovmznz.exe
C:\Documents and Settings\HP_Administrator\Application Data\oyoaiydmazsq.exe
C:\Documents and Settings\HP_Administrator\Application Data\ozqurflwysq.exe
C:\Documents and Settings\HP_Administrator\Application Data\qhpxlrjtomr.exe
C:\Documents and Settings\HP_Administrator\Application Data\qiksmniobd.exe
C:\Documents and Settings\HP_Administrator\Application Data\qvghojxyf.exe
C:\Documents and Settings\HP_Administrator\Application Data\rcaemtf.exe
C:\Documents and Settings\HP_Administrator\Application Data\rgfehd.exe
C:\Documents and Settings\HP_Administrator\Application Data\rifdgbgk.exe
C:\Documents and Settings\HP_Administrator\Application Data\rmhywgehplsc.exe
C:\Documents and Settings\HP_Administrator\Application Data\shhupbcwzfo.exe
C:\Documents and Settings\HP_Administrator\Application Data\sinornq.exe
C:\Documents and Settings\HP_Administrator\Application Data\siwbozcvt.exe
C:\Documents and Settings\HP_Administrator\Application Data\sjf.exe
C:\Documents and Settings\HP_Administrator\Application Data\sqfadc.exe
C:\Documents and Settings\HP_Administrator\Application Data\srvp.exe
C:\Documents and Settings\HP_Administrator\Application Data\ssmm.exe
C:\Documents and Settings\HP_Administrator\Application Data\swncrht.exe
C:\Documents and Settings\HP_Administrator\Application Data\tjjvka.exe
C:\Documents and Settings\HP_Administrator\Application Data\tlsq.exe
C:\Documents and Settings\HP_Administrator\Application Data\tmedvvnupm.exe
C:\Documents and Settings\HP_Administrator\Application Data\tvcviexpwpbg.exe
C:\Documents and Settings\HP_Administrator\Application Data\tvsvksl.exe
C:\Documents and Settings\HP_Administrator\Application Data\uczqjfl.exe
C:\Documents and Settings\HP_Administrator\Application Data\ukhmqvah.exe
C:\Documents and Settings\HP_Administrator\Application Data\uldnqceywl.exe
C:\Documents and Settings\HP_Administrator\Application Data\vdguhwyel.exe
C:\Documents and Settings\HP_Administrator\Application Data\vdvwfo.exe
C:\Documents and Settings\HP_Administrator\Application Data\velwhcpmylt.exe
C:\Documents and Settings\HP_Administrator\Application Data\vljjorw.exe
C:\Documents and Settings\HP_Administrator\Application Data\vtvluq.exe
C:\Documents and Settings\HP_Administrator\Application Data\vuyuczp.exe
C:\Documents and Settings\HP_Administrator\Application Data\wgjvsl.exe
C:\Documents and Settings\HP_Administrator\Application Data\whglsxpsjtjs.exe
C:\Documents and Settings\HP_Administrator\Application Data\whqfnoslbg.exe
C:\Documents and Settings\HP_Administrator\Application Data\whxrvtyaz.exe
C:\Documents and Settings\HP_Administrator\Application Data\wuiqtpwba.exe
C:\Documents and Settings\HP_Administrator\Application Data\wwna.exe
C:\Documents and Settings\HP_Administrator\Application Data\wzrnaeznx.exe
C:\Documents and Settings\HP_Administrator\Application Data\xgbr.exe
C:\Documents and Settings\HP_Administrator\Application Data\xosdbhkicdu.exe
C:\Documents and Settings\HP_Administrator\Application Data\xsn.exe
C:\Documents and Settings\HP_Administrator\Application Data\xxhev.exe
C:\Documents and Settings\HP_Administrator\Application Data\ylfgciz.exe
C:\Documents and Settings\HP_Administrator\Application Data\yodv.exe
C:\Documents and Settings\HP_Administrator\Application Data\ysshg.exe
C:\Documents and Settings\HP_Administrator\Application Data\ytzapqwnzpvc.exe
C:\Documents and Settings\HP_Administrator\Application Data\yvtu.exe
C:\Documents and Settings\HP_Administrator\Application Data\yznp.exe
C:\Documents and Settings\HP_Administrator\Application Data\zjiwbnmkkqni.exe
C:\Documents and Settings\HP_Administrator\Application Data\zmrdbwkutl.exe
C:\Documents and Settings\HP_Administrator\Application Data\zmu.exe
C:\Documents and Settings\HP_Administrator\Application Data\znijd.exe
C:\Documents and Settings\HP_Administrator\Application Data\zqwmggm.exe
C:\Documents and Settings\HP_Administrator\Application Data\zynonssv.exe
C:\info.exe
C:\JkLC.exe
C:\sqmdata09.sqm
C:\sqmdata10.sqm
C:\sqmdata11.sqm
C:\sqmnoopt09.sqm
C:\sqmnoopt10.sqm
C:\sqmnoopt11.sqm
C:\WINDOWS\pskt.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_AVFLT
——-\LEGACY_ITHEIOE6ECZ1X5C
——-\LEGACY_PAVPROC
——-\LEGACY_PAVSRK.SYS
——-\LEGACY_PAVTPK.SYS
——-\LEGACY_SHLDDRV
——-\AFW
——-\AvFlt
——-\itheioe6ecz1x5c
——-\PavProc
——-\PavSRK.sys
——-\PavTPK.sys
——-\ShldDrv


((((((((((((((((((((((((( Files Created from 2008-01-16 to 2008-02-16 )))))))))))))))))))))))))))))))
.

2008-02-16 13:35 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\ihkowkz.exe
2008-02-16 00:01 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\mcabsbaokmyp.exe
2008-02-15 22:12 . 2007-12-15 01:30 12,800 –a—— C:\Documents and Settings\HP_Administrator\Application Data\fltkgymya.exe
2008-02-15 16:54 . 2008-02-15 16:54 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-15 16:54 . 2008-02-15 16:54 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-10 09:03 . 2008-02-11 03:17 60,416 –a—— C:\WINDOWS\system32\drivers\ComboFix.sys
2008-02-01 00:35 . 2008-02-01 00:35 d——– C:\WINDOWS\system32\LogFiles
2008-01-16 10:49 . 2008-01-16 10:49 d——– C:\Presets

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-16 23:11 1,204 —-a-w C:\WINDOWS\system32\drivers\APPFLTR.CFG.bck
2008-02-16 23:11 1,204 —-a-w C:\WINDOWS\system32\drivers\APPFLTR.CFG
2008-02-16 21:37 297,276 —-a-w C:\WINDOWS\system32\drivers\APPFCONT.DAT.bck
2008-02-16 21:37 297,276 —-a-w C:\WINDOWS\system32\drivers\APPFCONT.DAT
2008-02-16 21:36 13,880 —-a-w C:\WINDOWS\system32\drivers\COMFiltr.sys
2008-02-08 17:35 ——— d—–w C:\Program Files\Ahead
2008-01-15 16:21 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
2008-01-11 05:18 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\DivX
2008-01-10 04:49 ——— d—–w C:\Program Files\DivX
2007-12-19 08:13 ——— d—–w C:\Program Files\Lavasoft
2007-12-18 21:50 ——— d—–w C:\Program Files\Trend Micro
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-17 08:16 ——— d—–w C:\Program Files\IObit
2007-12-16 10:34 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-16 10:29 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2007-11-02 20:41 40,516 —-a-w C:\Program Files\uninstal.log
2005-12-03 00:26 457 —-a-w C:\Program Files\INSTALL.LOG
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Presets —-



((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-25 07:57 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 04:00 15360]
"AIM"="C:\Program Files\AIM\aim.exe" [2005-08-05 14:08 67160]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 15:24 1694208]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2007-11-01 13:22 3317760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 10:04 59392]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 22:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-12-01 09:55 126976]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 21:34 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 12:54 253952]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-06-29 06:14 180269]
"APVXDWIN"="C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.exe" [2007-07-19 15:23 455984]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-06-29 06:24 98304]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-06 23:33 8720384]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-08-27 17:34:58 113664]
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-21 19:42:22 45056]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-05 01:28:24 258048]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
MiniMavis.lnk - C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Deluxe\MiniMavis.exe [2005-08-31 00:24:58 2392064]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2000-08-06 01:03:20 69632]
SpySubtract.lnk - C:\Program Files\InterMute\SpySubtract\sslaunch.exe [2005-06-29 06:26:37 73728]
TabUserW.lnk - C:\Program Files\Wacom\TabUserW.exe [2005-08-27 16:04:49 77824]
Updates from HP.lnk - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe [2005-06-29 06:27:39 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 2007-02-15 20:02 50736 C:\WINDOWS\system32\avldr.dll

R1 APPFLT;App Filter Plugin;C:\WINDOWS\system32\Drivers\APPFLT.SYS [2007-05-11 09:33]
R1 DSAFLT;DSA Filter Plugin;C:\WINDOWS\system32\Drivers\DSAFLT.SYS [2007-05-11 09:33]
R1 FNETMON;NetMon Filter Plugin;C:\WINDOWS\system32\Drivers\fnetmon.SYS [2007-05-11 09:33]
R1 IDSFLT;Ids Filter Plugin;C:\WINDOWS\system32\Drivers\IDSFLT.SYS [2007-07-11 11:39]
R1 NETFLTDI;Panda Net Driver [TDI Layer];C:\WINDOWS\system32\Drivers\NETFLTDI.SYS [2007-05-11 09:33]
R1 SMSFLT;SMS Filter Plugin;C:\WINDOWS\system32\Drivers\SMSFLT.SYS [2007-05-11 09:33]
R1 WNMFLT;Wifi Monitor Filter Plugin;C:\WINDOWS\system32\Drivers\WNMFLT.SYS [2007-05-11 09:33]
R2 cpoint;Panda CPoint Driver;C:\WINDOWS\system32\Drivers\cpoint.sys [2007-06-08 08:44]
R3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys []
R3 ComFiltr;Panda Anti-Dialer;C:\WINDOWS\system32\DRIVERS\COMFiltr.sys [2008-02-16 15:13]
R3 NETIMFLT;PANDA NDIS IM Filter Miniport;C:\WINDOWS\system32\DRIVERS\netimflt.sys [2007-04-24 15:43]
R3 PavTPK.sys;PavTPK.sys;C:\WINDOWS\system32\PavTPK.sys []
S3 PavSRK.sys;PavSRK.sys;C:\WINDOWS\system32\PavSRK.sys []

*Newly Created Service* - AVFLT
*Newly Created Service* - COMFILTR
*Newly Created Service* - PAVTPK.SYS
.
Contents of the 'Scheduled Tasks' folder
"2008-02-16 22:42:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-16 09:49:00 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-02-07 11:00:00 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-16 15:10:56
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwEnumerateKey, ZwClose, ZwEnumerateValueKey, ZwQueryValueKey, ZwOpenFile

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\AVENGINE.EXE
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-02-16 15:18:26 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-16 23:18:17
ComboFix2.txt 2008-02-15 23:44:33
.
2008-02-12 11:03:09 — E O F —


_——————————————————————–

And here's the Hijack Log ::




_____________________________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:30:35 PM, on 2/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\AVENGINE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Deluxe\MiniMavis.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Wacom\TabUserW.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ign.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MiniMavis.lnk = C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Deluxe\MiniMavis.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O4 - Global Startup: TabUserW.lnk = C:\Program Files\Wacom\TabUserW.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n035p/EN/install/gtdownlr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab?s6
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe

–
End of file - 11799 bytes


———————————————————–

And here is the Kaspersky:::::::::::::::::::::::::::::





——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Saturday, February 16, 2008 7:31:15 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/02/2008
Kaspersky Anti-Virus database records: 568182
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan Statistics:
Total number of scanned objects: 263385
Number of viruses found: 16
Number of infected objects: 209
Number of suspicious objects: 2
Duration of the scan process: 02:30:19

Infected Object Name / Virus Name / Last Action
C:\BXPA.0XE Infected: Trojan-Downloader.Win32.VB.bwb skipped
C:\Documents and Settings\Administrator\Desktop\catchme.zip/gebyyvt.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Administrator\Desktop\catchme.zip/pmkjj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Administrator\Desktop\catchme.zip ZIP: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\136fcbcb1074552c54e2ef25a2265f4f_2cd53ae6-ebb8-413c-94a5-66339957f33e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\sentinel\2.1\gwhashs.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZlobVideoAccessActiveXObject.zip/uninst.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZlobVideoAccessActiveXObject.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\HP_Administrator\Application Data\InterMute\SpySubtract\tmp\3 Object is locked skipped
C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\1culvyvo.default\cert8.db Object is locked skipped
C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\1culvyvo.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\1culvyvo.default\history.dat Object is locked skipped
C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\1culvyvo.default\key3.db Object is locked skipped
C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\1culvyvo.default\parent.lock Object is locked skipped
C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\1culvyvo.default\search.sqlite Object is locked skipped
C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\1culvyvo.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\HP_Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\HP_Administrator\Desktop\[4]-[removed]/info.exe Infected: Trojan-Downloader.Win32.Tiny.zg skipped
C:\Documents and Settings\HP_Administrator\Desktop\[4]-[removed]/JkLC.exe Infected: Trojan-Downloader.Win32.VB.bwb skipped
C:\Documents and Settings\HP_Administrator\Desktop\[4]-[removed] ZIP: infected - 2 skipped
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\1culvyvo.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\1culvyvo.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\1culvyvo.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\1culvyvo.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\temp\JET187B.tmp Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\temp\~DF1165.tmp Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\temp\~DFE254.tmp Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Administrator\ntuser.dat Object is locked skipped
C:\Documents and Settings\HP_Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\INFO.0XE Infected: Trojan-Downloader.Win32.VB.bwb skipped
C:\Program Files\Mozilla Firefox\keygen.exe Infected: Trojan-Downloader.Win32.Small.ieg skipped
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\cace2423dfb97c58fe7dd9f120557063PSK_NAMES Object is locked skipped
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\cace2423dfb97c58fe7dd9f120557063PSK_NAMES2 Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\chandir.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\chandir.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\chn.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\chn.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\D0000000.FCS Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\inuse.txt Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\L0000002.FCS Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\main.log Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_die.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_die.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_dnd.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_dnd.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_ext.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_ext.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_rcv.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_rcv.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\storydb.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\storydb.idx Object is locked skipped
C:\Program Files\Veoh Networks\Veoh\client.log Object is locked skipped
C:\Program Files\Veoh Networks\Veoh\upload.log Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ceasboqh.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\dpemhrss.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\gbsukwvf.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\igglbbec.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\moskymla.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\odkwmuja.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\tuvgetdo.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\veowjvon.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\wjimlevg.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP41\A0011175.exe Infected: Trojan-Downloader.Win32.Small.hvx skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP42\A0013205.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP42\A0013206.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP42\A0013207.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP42\A0013208.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP43\A0013277.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP43\A0013398.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP43\A0013403.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP44\A0014721.com Infected: Trojan.Win32.Pakes.btu skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP44\A0014736.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP44\A0015824.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP45\A0015868.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP45\A0015961.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP46\A0016070.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP47\A0016330.com Infected: Trojan.Win32.Pakes.btu skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP48\A0017207.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP48\A0017278.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP50\A0017307.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP50\A0017372.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP50\A0018541.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP51\A0018592.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP51\A0018623.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP51\A0018657.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP51\A0018710.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP51\A0018711.dll Infected: not-a-virus:AdWare.Win32.AdBand.e skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP51\A0018712.exe Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0018824.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0018987.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0018988.exe Infected: Trojan-Downloader.Win32.VB.bwb skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0018989.exe Infected: Trojan-Downloader.Win32.VB.bwb skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0018990.exe Infected: Trojan-Downloader.Win32.Agent.gat skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0018991.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0018992.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0018993.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0018994.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0018995.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0018996.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0018997.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0018998.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0018999.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0019000.exe Infected: Trojan.Win32.Pakes.btu skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0019001.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP52\A0019002.com Infected: Trojan.Win32.Pakes.btu skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP53\A0019097.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP53\A0019387.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP53\A0021563.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP53\A0021564.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP53\A0021641.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP53\A0021753.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022063.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022199.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022200.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022201.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022203.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022204.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022205.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022206.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022207.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022208.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022209.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022210.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022211.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022212.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022214.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022216.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022217.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022218.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022219.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022220.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022222.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022224.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022225.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022226.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022227.dll Infected: Trojan.Win32.Pakes.bwd skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022228.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022229.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022230.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022231.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022232.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022233.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022234.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022235.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022236.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022237.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bxe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022238.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022239.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022240.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022241.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.is skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022242.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022363.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP54\A0022444.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP55\A0023479.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP55\A0023611.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP55\A0024109.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP55\A0024110.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP57\A0024195.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP57\A0024377.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP58\A0024484.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP58\A0024611.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP59\A0024709.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP60\A0024781.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP61\A0024787.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP61\A0024831.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP62\A0024953.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP63\A0025038.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP63\A0025075.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP64\A0025080.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP65\A0025119.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP66\A0025221.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP68\A0025328.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP69\A0025438.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP71\A0025519.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP72\A0025661.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP72\A0025713.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP74\A0025759.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP75\A0025986.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP77\A0026508.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP77\A0026700.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP77\A0026703.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP77\A0026704.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP77\A0026705.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP77\A0026706.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP77\A0026707.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP77\A0026708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP77\A0026709.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP77\A0026710.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP77\A0026711.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP78\A0026948.exe/data.rar/crack.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP78\A0026948.exe/data.rar/keygen.exe Infected: Trojan-Downloader.Win32.Small.ieg skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP78\A0026948.exe/data.rar Infected: Trojan-Downloader.Win32.Small.ieg skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP78\A0026948.exe RarSFX: infected - 3 skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP78\A0026949.exe/data.rar/crack.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP78\A0026949.exe/data.rar/keygen.exe Infected: Trojan-Downloader.Win32.Small.ieg skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP78\A0026949.exe/data.rar Infected: Trojan-Downloader.Win32.Small.ieg skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP78\A0026949.exe RarSFX: infected - 3 skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP83\A0029513.exe Infected: Trojan-Downloader.Win32.Tiny.zg skipped
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP83\change.log Object is locked skipped
C:\VundoFix Backups\apekigtn.exe.bad Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\VundoFix Backups\aqajkisa.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\aradluwq.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\bryjdnul.exe.bad Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\VundoFix Backups\cudwnhbn.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\eeupwupy.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\ejngateq.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\emmorhdb.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\etcvphad.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\fkgfhhak.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\hafrdjqk.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\iayinpip.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\imwjkdxj.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\kwerdqmr.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\mbgxgwli.exe.bad Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\VundoFix Backups\mcxpkckp.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\mffkiyvl.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\mgubxaek.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\mnxlfeyl.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\pgvqagwp.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\pydbaopn.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\pyviknjq.exe.bad Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\VundoFix Backups\qdgqyiyw.exe.bad Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\VundoFix Backups\qgfakblk.dll.bad Infected: Trojan.Win32.Pakes.bwd skipped
C:\VundoFix Backups\rfakyjnt.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\rgufpojf.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\rnnuilmj.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\sfxdpntg.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\sfxfcsmw.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\smcxtyco.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\toawesbw.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\txarwqri.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\ujettroi.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\vturr.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.bxe skipped
C:\VundoFix Backups\waqgehum.exe.bad Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\VundoFix Backups\wltnlcbq.exe.bad Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\VundoFix Backups\xaywvcfy.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\xiepcggi.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\xkthfipm.dll.bad Infected: not-a-virus:AdWare.Win32.SuperJuan.is skipped
C:\VundoFix Backups\xywbhnnn.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\MROFINU72.0XE Infected: Trojan-Downloader.Win32.Agent.gat skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{F94A8686-BFFC-4C80-A798-A4D770BB0A50}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{4D2D4517-6384-422D-A7E6-C33669D98EA8}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\ASHABCBA.0XE Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\WINDOWS\system32\BJPVSPDQ.0LL Infected: Backdoor.Win32.Agent.dlj skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\EFEFLACA.0XE Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\WINDOWS\system32\EHHFKHJJ.0XE Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\hcvmeauv.exe.bak Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\WINDOWS\system32\hwlefryf.exe.bak Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\WINDOWS\system32\IPSCCMEW.0XE Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\WINDOWS\system32\LYOCETUV.0XE Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\WINDOWS\system32\UWXLYOIS.0XE Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\YAYCBHHG.0XE Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\WINDOWS\system32\YCFRWITG.0LL Infected: Backdoor.Win32.Agent.dlj skipped
C:\WINDOWS\system32\YOFBLO.0XE Infected: Trojan.Win32.Pakes.btu skipped
C:\WINDOWS\system32\YQBLGBKH.0XE Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\load.exe Infected: not-a-virus:FraudTool.Win32.Avola.b skipped
D:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP83\change.log Object is locked skipped

Scan process completed.
Hi

First of all, could you please tell me whether you are experiencing any problems or strange happenings with Panda Security Suite? Thanks.


1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\Documents and Settings\HP_Administrator\Application Data\ihkowkz.exe
C:\Documents and Settings\HP_Administrator\Application Data\mcabsbaokmyp.exe
C:\Documents and Settings\HP_Administrator\Application Data\fltkgymya.exe
C:\BXPA.0XE
C:\Documents and Settings\Administrator\Desktop\catchme.zip
C:\Documents and Settings\HP_Administrator\Desktop\[4]-[removed]
C:\INFO.0XE
C:\Program Files\Mozilla Firefox\keygen.exe
C:\WINDOWS\MROFINU72.0XE
C:\WINDOWS\system32\ASHABCBA.0XE
C:\WINDOWS\system32\BJPVSPDQ.0LL
C:\WINDOWS\system32\EFEFLACA.0XE
C:\WINDOWS\system32\EHHFKHJJ.0XE
C:\WINDOWS\system32\hcvmeauv.exe.bak
C:\WINDOWS\system32\hwlefryf.exe.bak
C:\WINDOWS\system32\IPSCCMEW.0XE
C:\WINDOWS\system32\LYOCETUV.0XE
C:\WINDOWS\system32\UWXLYOIS.0XE
C:\WINDOWS\system32\YAYCBHHG.0XE
C:\WINDOWS\system32\YCFRWITG.0LL
C:\WINDOWS\system32\YOFBLO.0XE
C:\WINDOWS\system32\YQBLGBKH.0XE
D:\load.exe


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.

Please describe how the computer is running now.

Thanks.
The only thing Panda has done is slow down my computer. from the moment I installed it. Why?




Here's Combo Fix


ComboFix 08-02-18.1 - HP_Administrator 2008-02-19 13:58:33.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.311 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Administrator\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\BXPA.0XE
C:\Documents and Settings\Administrator\Desktop\catchme.zip
C:\Documents and Settings\HP_Administrator\Application Data\fltkgymya.exe
C:\Documents and Settings\HP_Administrator\Application Data\ihkowkz.exe
C:\Documents and Settings\HP_Administrator\Application Data\mcabsbaokmyp.exe
C:\Documents and Settings\HP_Administrator\Desktop\[4]-[removed]
C:\INFO.0XE
C:\Program Files\Mozilla Firefox\keygen.exe
C:\WINDOWS\MROFINU72.0XE
C:\WINDOWS\system32\ASHABCBA.0XE
C:\WINDOWS\system32\BJPVSPDQ.0LL
C:\WINDOWS\system32\EFEFLACA.0XE
C:\WINDOWS\system32\EHHFKHJJ.0XE
C:\WINDOWS\system32\hcvmeauv.exe.bak
C:\WINDOWS\system32\hwlefryf.exe.bak
C:\WINDOWS\system32\IPSCCMEW.0XE
C:\WINDOWS\system32\LYOCETUV.0XE
C:\WINDOWS\system32\UWXLYOIS.0XE
C:\WINDOWS\system32\YAYCBHHG.0XE
C:\WINDOWS\system32\YCFRWITG.0LL
C:\WINDOWS\system32\YOFBLO.0XE
C:\WINDOWS\system32\YQBLGBKH.0XE
D:\load.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\BXPA.0XE
C:\Documents and Settings\Administrator\Desktop\catchme.zip
C:\Documents and Settings\HP_Administrator\Application Data\fltkgymya.exe
C:\Documents and Settings\HP_Administrator\Application Data\ihkowkz.exe
C:\Documents and Settings\HP_Administrator\Application Data\mcabsbaokmyp.exe
C:\Documents and Settings\HP_Administrator\Desktop\[4]-[removed]
C:\INFO.0XE
C:\Program Files\Mozilla Firefox\keygen.exe
C:\WINDOWS\MROFINU72.0XE
C:\WINDOWS\system32\ASHABCBA.0XE
C:\WINDOWS\system32\BJPVSPDQ.0LL
C:\WINDOWS\system32\EFEFLACA.0XE
C:\WINDOWS\system32\EHHFKHJJ.0XE
C:\WINDOWS\system32\hcvmeauv.exe.bak
C:\WINDOWS\system32\hwlefryf.exe.bak
C:\WINDOWS\system32\IPSCCMEW.0XE
C:\WINDOWS\system32\LYOCETUV.0XE
C:\WINDOWS\system32\UWXLYOIS.0XE
C:\WINDOWS\system32\YAYCBHHG.0XE
C:\WINDOWS\system32\YCFRWITG.0LL
C:\WINDOWS\system32\YOFBLO.0XE
C:\WINDOWS\system32\YQBLGBKH.0XE
D:\load.exe

.
((((((((((((((((((((((((( Files Created from 2008-01-19 to 2008-02-19 )))))))))))))))))))))))))))))))
.

2008-02-19 13:28 . 2008-02-19 13:28 d——– C:\Combo-Fix
2008-02-19 13:26 . 2008-02-19 13:26 d——– C:\Combo-Fix(2)
2008-02-16 22:53 . 2008-02-16 22:53 d——– C:\Documents and Settings\HP_Administrator\Application Data\Nero
2008-02-16 22:49 . 2008-02-16 22:49 d——– C:\Program Files\Nero
2008-02-16 22:49 . 2008-02-16 22:52 d——– C:\Program Files\Common Files\Nero
2008-02-16 22:49 . 2008-02-16 22:49 d——– C:\Documents and Settings\All Users\Application Data\Nero
2008-02-16 15:34 . 2008-02-16 15:34 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-02-16 15:34 . 2008-02-16 15:34 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-01 00:35 . 2008-02-01 00:35 d——– C:\WINDOWS\system32\LogFiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-19 21:57 1,204 —-a-w C:\WINDOWS\system32\drivers\APPFLTR.CFG.bck
2008-02-19 21:57 1,204 —-a-w C:\WINDOWS\system32\drivers\APPFLTR.CFG
2008-02-19 19:53 295,896 —-a-w C:\WINDOWS\system32\drivers\APPFCONT.DAT.bck
2008-02-19 19:53 295,896 —-a-w C:\WINDOWS\system32\drivers\APPFCONT.DAT
2008-02-19 19:53 13,880 —-a-w C:\WINDOWS\system32\drivers\COMFiltr.sys
2008-02-18 06:03 ——— d—–w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-02-17 10:02 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
2008-02-08 17:35 ——— d—–w C:\Program Files\Ahead
2008-01-11 05:18 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\DivX
2008-01-10 04:49 ——— d—–w C:\Program Files\DivX
2007-12-19 08:13 ——— d—–w C:\Program Files\Lavasoft
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-07 14:37 3,059,200 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 13:07 18,432 —-a-w C:\WINDOWS\system32\dllcache\iedw.exe
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-12-04 01:33 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-12-04 01:33 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2007-12-04 01:33 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2007-12-04 01:33 682,496 —-a-w C:\WINDOWS\system32\DivX.dll
2007-11-29 22:30 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2007-11-29 22:30 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 22:30 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2007-11-29 22:30 129,784 ——w C:\WINDOWS\system32\pxafs.dll
2007-11-29 22:30 120,056 ——w C:\WINDOWS\system32\pxcpyi64.exe
2007-11-29 22:30 118,520 ——w C:\WINDOWS\system32\pxinsi64.exe
2007-11-29 22:30 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2007-11-29 22:28 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2007-11-29 22:28 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2007-11-28 21:55 156,992 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-11-28 21:53 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-11-28 21:53 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2007-11-28 21:53 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-11-28 21:53 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2007-11-28 21:53 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2007-11-28 21:53 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
2007-11-28 21:52 12,288 —-a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-11-02 20:41 40,516 —-a-w C:\Program Files\uninstal.log
2005-12-03 00:26 457 —-a-w C:\Program Files\INSTALL.LOG
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-25 07:57 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 04:00 15360]
"AIM"="C:\Program Files\AIM\aim.exe" [2005-08-05 14:08 67160]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 15:24 1694208]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2007-11-01 13:22 3317760]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-08-03 12:51 202024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 10:04 59392]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 22:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-12-01 09:55 126976]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 21:34 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 12:54 253952]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-06-29 06:14 180269]
"APVXDWIN"="C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.exe" [2007-07-19 15:23 455984]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-06-29 06:24 98304]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 09:25 1828136]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-06 23:33 8720384]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-08-27 17:34:58 113664]
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-21 19:42:22 45056]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-05 01:28:24 258048]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
MiniMavis.lnk - C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Deluxe\MiniMavis.exe [2005-08-31 00:24:58 2392064]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2000-08-06 01:03:20 69632]
SpySubtract.lnk - C:\Program Files\InterMute\SpySubtract\sslaunch.exe [2005-06-29 06:26:37 73728]
TabUserW.lnk - C:\Program Files\Wacom\TabUserW.exe [2005-08-27 16:04:49 77824]
Updates from HP.lnk - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe [2005-06-29 06:27:39 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 2007-02-15 20:02 50736 C:\WINDOWS\system32\avldr.dll

R1 APPFLT;App Filter Plugin;C:\WINDOWS\system32\Drivers\APPFLT.SYS [2007-05-11 09:33]
R1 DSAFLT;DSA Filter Plugin;C:\WINDOWS\system32\Drivers\DSAFLT.SYS [2007-05-11 09:33]
R1 FNETMON;NetMon Filter Plugin;C:\WINDOWS\system32\Drivers\fnetmon.SYS [2007-05-11 09:33]
R1 IDSFLT;Ids Filter Plugin;C:\WINDOWS\system32\Drivers\IDSFLT.SYS [2007-07-11 11:39]
R1 NETFLTDI;Panda Net Driver [TDI Layer];C:\WINDOWS\system32\Drivers\NETFLTDI.SYS [2007-05-11 09:33]
R1 SMSFLT;SMS Filter Plugin;C:\WINDOWS\system32\Drivers\SMSFLT.SYS [2007-05-11 09:33]
R1 WNMFLT;Wifi Monitor Filter Plugin;C:\WINDOWS\system32\Drivers\WNMFLT.SYS [2007-05-11 09:33]
R2 cpoint;Panda CPoint Driver;C:\WINDOWS\system32\Drivers\cpoint.sys [2007-06-08 08:44]
R3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys []
R3 NETIMFLT;PANDA NDIS IM Filter Miniport;C:\WINDOWS\system32\DRIVERS\netimflt.sys [2007-04-24 15:43]
R3 PavSRK.sys;PavSRK.sys;C:\WINDOWS\system32\PavSRK.sys []
R3 PavTPK.sys;PavTPK.sys;C:\WINDOWS\system32\PavTPK.sys []

.
Contents of the 'Scheduled Tasks' folder
"2008-02-19 21:42:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-18 09:49:00 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-02-07 11:00:00 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-19 14:04:06
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-19 14:05:52
ComboFix-quarantined-files.txt 2008-02-19 22:05:49
ComboFix2.txt 2008-02-16 23:18:27
ComboFix3.txt 2008-02-15 23:44:33
.
2008-02-12 11:03:09 — E O F —


————————————————————————–

here's the HiJackLog

———————————————————————————————————————————————————————————-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:14:25 PM, on 2/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\AVENGINE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Deluxe\MiniMavis.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Wacom\TabUserW.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ign.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MiniMavis.lnk = C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Deluxe\MiniMavis.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O4 - Global Startup: TabUserW.lnk = C:\Program Files\Wacom\TabUserW.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n035p/EN/install/gtdownlr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab?s6
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe

–
End of file - 12673 bytes

——————————————————————————————

here's the Maleware scan

================================

Malwarebytes' Anti-Malware 1.03
Database version: 374

Scan type: Full Scan (C:\|D:\|G:\|H:\|I:\|J:\|K:\|)
Objects scanned: 305961
Time elapsed: 57 minute(s), 31 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 8

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\xflock (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\QooBox\Quarantine\C\Program Files\Mozilla Firefox\keygen.exe.vir (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Program Files\QdrDrive\qdrloader.exe.vir (Trojan.Agent) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Program Files\QdrPack\QdrPack11.exe.vir (Adware.ISMonitor) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP51\A0018712.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP77\A0026694.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP77\A0026696.exe (Adware.ISMonitor) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP88\A0030291.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Favorites\Online Security Test.url (Rogue.Link) -> Quarantined and deleted successfully.
Hi

Sorry about the delays, I was unexpectedly away from home for 2 days, without internet access.

The Panda Security Suite that you have may well slow down your computer a bit as it involves 2 on-access (i.e. real-time) scanners to protect your system. This is perfectly normal and will probably be slightly noticeable with any Anti-Virus/Firewall combination.


Your Java Runtime Environment is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 4.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 4, The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation, Multi-language and save it to your desktop.
  • Close any programs you may have running - especially any web browsers.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u4-windowsi586.exe to install the newest version.

In your next reply, please give a detailed description of how your computer is running and behaving at the moment, listing any remaining problems that you have. Include another HijackThis log as well please.

Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI