This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] My computer is infected by ZEDO and other pop ups!

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Unfortunately my computer seem to have been hijacked :( I've tried different kinds of malware and spyware programs to get rid of the infections, but nothing seems to work!

I saw that you're supposed to download hijackthis and post the log file… So here is mine. I would be sooo grateful if someone could help me!

//Sofia

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:01:15, on 2008-02-13
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\sony\VAIO Event Service\VESMgrSub.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\sony\ISB Utility\ISBMgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Azureus\Azureus.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe
C:\Program Files\Spyware Doctor\sdloader.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.superstart.se/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Norton Save and Restore 2.0] "C:\Program Files\Norton Save and Restore\Agent\VProTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NÄTVERKSTJÄNST')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: RegistryDefender.lnk = C:\Program Files\Registry Defender\RegistryDefender.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Save and Restore - Symantec Corporation - C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 14436 bytes
Hello Sofia,

Welcome, sorry for the delay. I basically am not looking at anything bad on your log, lets do a few things.

Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a Hijackthis log.


Post the Malwarebytes log and a new HJT log please
Hi!

Thank you for your help! But it seems it didn't work… :( The pop ups still keep showing up…
But during the hijackthis scan and also during the Anti-malware scan there was a message that showed up from my antivirus program.
It said:

Threat detected!
While opening file: C:\\Windows\system32\drivers\srvnett.sys
Trojan horse Agent.OPM

I tried to delete it, but "acess was denied" and the same thing happened when I tried to "move it to vault"… so I was forced to ignore it…

Also I checked the items you told me to and also fixed them, and when requested I "deleted or healed them", but they are still showing up on the log… don't know why…

Anyway, here´s my latest hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:44:36, on 2008-02-22
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\sony\ISB Utility\ISBMgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.superstart.se/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Norton Save and Restore 2.0] "C:\Program Files\Norton Save and Restore\Agent\VProTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NÄTVERKSTJÄNST')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: RegistryDefender.lnk = C:\Program Files\Registry Defender\RegistryDefender.exe
O4 - Startup: Skärmurklipp och start för OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Save and Restore - Symantec Corporation - C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 11967 bytes


And here's my Anti-malware log:

Malwarebytes' Anti-Malware 1.05
Database version: 394

Scan type: Quick Scan
Objects scanned: 24695
Time elapsed: 3 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0d987fb6-2cb1-4189-b6a1-5e8185e9a899} (Rogue.Registry.Defender) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\Registry Defender (Rogue.Registry.Defender) -> Quarantined and deleted successfully.


Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Windows\System32\x64 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registry Defender (Rogue.Registry.Defender) -> Quarantined and deleted successfully.

Files Infected:
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registry Defender\Help.lnk (Rogue.Registry.Defender) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registry Defender\Registry Defender.lnk (Rogue.Registry.Defender) -> Quarantined and deleted successfully.
C:\Windows\System32\drivers\core.cache.dsk (Malware.Trace) -> Delete on reboot.
C:\Users\Sofia\Desktop\Registry Defender.lnk (Rogue.Registry.Defender) -> Quarantined and deleted successfully.
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RegistryDefender.lnk (Rogue.Registry.Defender) -> Quarantined and deleted successfully.
Hello Sophia. :)

Registry Defender is a Rogue program that gives you false reports and will let you fix them for a fee.

MalwareBytes removed some bad stuff but also gave us a clue to the problem, I need you to run these programs please, it looks like your infected with the Vundo Trojan. I know running these programs are time consuming but this trojan spreads itself all over your system and there are a few variants of it, so these should get it all.



Please download SuperAntiSpyware Free
Install the program
  • Run SuperAntiSpyware and click: Check for updates
  • Once the update is finished, on the main screen, click: Scan your computer
  • Check: Perform Complete Scan
  • Click Next to start the scan.
Superantispyware scans the computer, and when finished, lists all the infections found.
Make sure everything found has a check next to it, and press: Next <– Important
Then, click Finish

It is possible that the program asks to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
  • Click: Preferences
  • Click the Statistics/Logs tab
  • Under Scanner Logs, double-click SuperAntiSpyware Scan Log
It opens in your default text editor (such as Notepad)

Please provide the SuperAntiSpyware log in your reply, as well as a new HijackThis log.





Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.



1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net


2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.




I need to see …..

1. SAS log
2. Combofix log
3. New HJT log
Hi Ken!

I can't thank you enough for helping me out!!! It seems like it worked!!! :) The combofix program seems to have taken care of all the pop ups! :) Thank God!!! They were driving me bananas! :) I'm a little scared they'll come back though… And the AVG anti-virus program is still warning me about a trojan that can't be removed… The one I wrote about in my last reply…

By the way, do you know of any good (free) anti-virus programs? I only have this AVG on trial, so I need to find another one pretty quickly…

I don't know if you need to see the logs now that you asked for, but here they are just in case…

Again, thank you!!! :thumbup: You are the best!!! :notworthy: Where do I send the check? ;)

//Sofia


SAS log:


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/23/2008 at 06:04 PM

Application Version : 3.9.1008

Core Rules Database Version : 3408
Trace Rules Database Version: 1400

Scan type : Complete Scan
Total Scan Time : 01:10:01

Memory items scanned : 682
Memory threats detected : 0
Registry items scanned : 8715
Registry threats detected : 0
File items scanned : 138804
File threats detected : 124

Adware.Tracking Cookie
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\sofia@serving-sys[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\sofia@tradedoubler[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\[removed]-sys[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\sofia@imrworldwide[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\sofia@atdmt[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\sofia@doubleclick[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@adbrite[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@adbrite[3].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@adinterax[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][3].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed].e-planning[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@adultadworld[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@advertising[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@apmebf[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@atdmt[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed]-sys[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@casalemedia[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@clickaider[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@clickaider[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@clickbank[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@clickintext[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@clicksor[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@clicktorrent[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][3].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][4].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@directtrack[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@doubleclick[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@dvd-and-media[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@enhancedhealing[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@eroticlick[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@fastclick[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@findarticles[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@findwhat[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@fuckzilla[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@hardpornvids[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@hardporn[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@hitbox[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@imrworldwide[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@indextools[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@msnportal.112.2o7[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@optimost[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@pacificpoker[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@pacificpoker[3].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@partygaming.122.2o7[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@partypoker[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@partypoker[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@porndirt[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@pornpornmovies[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@porntube[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@revsci[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@serving-sys[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@sexreactor[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@sexytimez[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@sjab.112.2o7[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@specificclick[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@statcounter[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@stats.1stmarketingtraffic[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@stockholmmediaweek[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@toplist[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@tradedoubler[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@tribalfusion[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@tripod[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@valueclick[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@valueclick[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@vidisex[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@waterfrontmedia.112.2o7[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][5].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][3].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed]-counter[1].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\sofia@yousextube[2].txt
C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt

RootKit.TnCore/Trace
C:\Windows\system32\drivers\core.cache.dsk




—————————————————————————————————-


ComboFix log:


ComboFix 08-02-24.2 - Sofia 2008-02-23 23:14:57.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1053.18.1067 [GMT 1:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Windows\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-01-24 to 2008-02-24 )))))))))))))))))))))))))))))))
.

2008-02-23 16:50 . 2008-02-23 16:50 d——– C:\Users\Sofia\AppData\Roaming\SUPERAntiSpyware.com
2008-02-23 16:50 . 2008-02-23 16:50 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-02-23 16:50 . 2008-02-23 16:53 d——– C:\Program Files\SUPERAntiSpyware
2008-02-22 23:47 . 2008-02-22 23:47 d——– C:\Users\Sofia\AppData\Roaming\Malwarebytes
2008-02-22 23:47 . 2008-02-22 23:47 d——– C:\ProgramData\Malwarebytes
2008-02-22 23:47 . 2008-02-23 00:06 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-22 23:38 . 2008-02-22 23:38 d——– C:\Users\Sofia\AppData\Roaming\Download Manager
2008-02-15 20:55 . 2008-01-10 06:50 1,244,672 –a—— C:\Windows\System32\mcmde.dll
2008-02-14 03:13 . 2008-02-14 03:13 194,560 –a—— C:\Windows\System32\WebClnt.dll
2008-02-14 03:13 . 2008-02-14 03:13 110,080 –a—— C:\Windows\System32\drivers\mrxdav.sys
2008-02-14 03:08 . 2008-02-14 03:08 3,504,696 –a—— C:\Windows\System32\ntkrnlpa.exe
2008-02-14 03:08 . 2008-02-14 03:08 3,470,392 –a—— C:\Windows\System32\ntoskrnl.exe
2008-02-14 03:08 . 2008-02-14 03:08 154,624 –a—— C:\Windows\System32\drivers\nwifi.sys
2008-02-14 03:08 . 2008-02-14 03:08 109,624 –a—— C:\Windows\System32\drivers\ataport.sys
2008-02-14 03:08 . 2008-02-14 03:08 45,112 –a—— C:\Windows\System32\drivers\pciidex.sys
2008-02-14 03:08 . 2008-02-14 03:08 21,560 –a—— C:\Windows\System32\drivers\atapi.sys
2008-02-14 03:08 . 2008-02-14 03:08 17,464 –a—— C:\Windows\System32\drivers\intelide.sys
2008-02-14 03:07 . 2008-02-14 03:07 4,247,552 –a—— C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-14 03:07 . 2008-02-14 03:07 1,686,528 –a—— C:\Windows\System32\gameux.dll
2008-02-14 03:07 . 2008-02-14 03:07 803,328 –a—— C:\Windows\System32\drivers\tcpip.sys
2008-02-14 03:07 . 2008-02-14 03:07 216,632 –a—— C:\Windows\System32\drivers\netio.sys
2008-02-14 03:07 . 2008-02-14 03:07 167,424 –a—— C:\Windows\System32\tcpipcfg.dll
2008-02-14 03:07 . 2008-02-14 03:07 24,064 –a—— C:\Windows\System32\netcfg.exe
2008-02-14 03:07 . 2008-02-14 03:07 22,016 –a—— C:\Windows\System32\netiougc.exe
2008-02-13 20:00 . 2008-02-13 20:00 d——– C:\Program Files\Trend Micro
2008-02-12 19:06 . 2008-02-12 20:58 d——– C:\Program Files\a-squared Free
2008-02-12 18:59 . 2008-02-12 18:59 d——– C:\Program Files\Sophos
2008-02-12 18:37 . 2008-02-12 19:00 d-a—— C:\ProgramData\TEMP
2008-02-12 18:37 . 2007-12-10 14:53 81,288 –a—— C:\Windows\System32\drivers\iksyssec.sys
2008-02-12 18:37 . 2007-12-10 14:53 66,952 –a—— C:\Windows\System32\drivers\iksysflt.sys
2008-02-12 18:37 . 2007-12-10 14:53 41,864 –a—— C:\Windows\System32\drivers\ikfilesec.sys
2008-02-12 18:37 . 2007-12-10 14:53 29,576 –a—— C:\Windows\System32\drivers\kcom.sys
2008-02-12 18:36 . 2008-02-12 18:36 d——– C:\Users\Sofia\AppData\Roaming\PC Tools
2008-02-12 18:36 . 2008-02-12 18:52 d——– C:\Program Files\Spyware Doctor
2008-02-09 16:15 . 2008-02-09 16:15 d——– C:\Program Files\Opera
2008-02-09 16:01 . 2008-02-09 16:01 d——– C:\Program Files\InterMute
2008-02-09 16:01 . 2004-10-20 11:42 328,488 –a—— C:\Users\Sofia\CWSInstall.exe
2008-02-08 19:52 . 2008-02-08 19:54 d——– C:\ProgramData\Lavasoft
2008-02-08 19:52 . 2008-02-08 19:52 d——– C:\Program Files\Lavasoft
2008-02-08 19:51 . 2008-02-23 16:49 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-07 20:54 . 2008-02-23 18:37 d——– C:\Users\Sofia\AppData\Roaming\AVG7
2008-02-07 20:53 . 2008-02-07 20:53 d——– C:\ProgramData\Grisoft
2008-02-07 20:53 . 2008-02-07 20:53 9,216 –a—— C:\Windows\System32\avgwlntf.dll
2008-02-07 20:44 . 2008-02-08 19:04 d——– C:\ProgramData\Avg7
2008-02-07 20:37 . 2008-02-07 20:37 167,545 –a—— C:\Windows\System32\drivers\core.cache.dsk
2008-02-07 20:37 . 2008-02-07 20:37 86,144 –a—— C:\Windows\System32\drivers\srvnett.sys
2008-02-02 23:05 . 2008-02-02 23:05 d——– C:\Program Files\Microsoft Visual Studio 8
2008-02-02 22:38 . 2008-02-02 22:38 d——– C:\Program Files\MagicISO
2008-02-01 18:50 . 2008-02-01 18:50 d——– C:\Program Files\Mirror of Beauty
2008-01-27 23:19 . 2008-01-27 23:19 d——– C:\Users\Sofia\AppData\Roaming\Acoustica
2008-01-27 23:19 . 2003-02-24 17:17 299,552 –a—— C:\Windows\wmsysprx.prx
2008-01-27 23:18 . 2008-01-27 23:19 d——– C:\Program Files\Acoustica CD Label Maker
2008-01-27 22:01 . 2008-01-27 22:01 d——– C:\Program Files\Easy CD & DVD Cover Creator
2008-01-27 21:28 . 2008-01-27 21:28 d——– C:\Program Files\Label Maker Wizard
2008-01-27 21:22 . 2008-01-27 21:22 d——– C:\Users\Sofia\AppData\Roaming\Preclick
2008-01-27 18:55 . 2008-01-27 18:56 d——– C:\Users\Sofia\AppData\Roaming\Printer Info Cache
2008-01-27 18:55 . 2008-01-27 21:51 d——– C:\Users\Sofia\AppData\Roaming\Image Zone Express
2008-01-27 17:58 . 2008-01-27 17:58 d——– C:\ProgramData\WEBREG
2008-01-27 13:57 . 2008-01-27 18:55 d——– C:\Users\Sofia\AppData\Roaming\HP
2008-01-27 13:56 . 2008-01-27 13:56 d——– C:\ProgramData\HPSSUPPLY
2008-01-27 13:51 . 2008-01-27 13:51 d——– C:\Program Files\Hewlett-Packard
2008-01-27 13:51 . 2008-01-27 13:51 d——– C:\Program Files\Common Files\Hewlett-Packard
2008-01-27 13:50 . 2008-01-27 13:55 d——– C:\Program Files\Common Files\HP
2008-01-27 13:48 . 2008-01-27 13:48 d——– C:\ProgramData\Hewlett-Packard
2008-01-27 13:30 . 2006-12-16 07:19 897,024 –a—— C:\Windows\System32\hpotiop1.dll
2008-01-27 13:30 . 2006-12-16 07:19 675,840 –a—— C:\Windows\System32\hpowiav1.dll
2008-01-27 13:30 . 2006-12-16 07:19 303,104 –a—— C:\Windows\System32\hpovst01.dll
2008-01-27 13:29 . 2007-02-01 09:24 258,048 –a—— C:\Windows\System32\hpzids01.dll
2008-01-27 13:29 . 2007-02-01 09:24 258,048 –a—— C:\hpzids01.dll
2008-01-27 13:29 . 2005-06-20 14:33 163,840 –a—— C:\Windows\System32\HPJCMN2U.DLL
2008-01-27 13:29 . 2007-02-02 11:27 117,760 –a—— C:\Windows\System32\hpz3l4v2.dll
2008-01-27 13:29 . 2005-06-20 14:33 94,208 –a—— C:\Windows\System32\HPJIPX1U.DLL
2008-01-27 13:28 . 2006-06-06 14:20 241,721 –a—— C:\Windows\System32\HPBMINI.DLL
2008-01-27 13:28 . 2005-06-20 14:33 49,152 –a—— C:\Windows\System32\HPBNRAC2.DLL
2008-01-27 13:28 . 2006-11-16 19:16 38,912 –a—— C:\Windows\System32\HPBPRO.DLL
2008-01-27 13:28 . 2006-11-16 19:15 25,600 –a—— C:\Windows\System32\HPBOID.DLL
2008-01-27 13:28 . 2006-11-16 19:16 24,576 –a—— C:\Windows\System32\HPBMIAPI.DLL
2008-01-27 13:28 . 2006-11-02 19:32 18,747 –a—— C:\Windows\System32\HPCEAC06.HPI
2008-01-27 13:28 . 2006-11-16 19:16 7,680 –a—— C:\Windows\System32\HPBPROPS.DLL
2008-01-27 13:28 . 2006-11-16 19:16 7,680 –a—— C:\Windows\System32\HPBOIDPS.DLL
2008-01-27 13:27 . 2008-01-27 13:56 d——– C:\Program Files\HP
2008-01-27 13:06 . 2008-01-27 17:59 139,414 –a—— C:\Windows\hpoins18.dat
2008-01-27 13:04 . 2008-01-27 18:55 d——– C:\ProgramData\HP
2008-01-27 11:41 . 2008-01-27 11:41 d——– C:\Users\Sofia\AppData\Roaming\vlc
2008-01-27 11:31 . 2008-01-27 11:31 d——– C:\Program Files\VideoLAN

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 22:34 ——— d—–w C:\Users\Sofia\AppData\Roaming\Azureus
2008-02-14 02:08 ——— d—–w C:\ProgramData\Microsoft Help
2008-02-14 02:07 537,600 —-a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-14 02:07 449,536 —-a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-14 02:07 2,144,256 —-a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-14 02:07 173,056 —-a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-14 02:04 824,832 —-a-w C:\Windows\System32\wininet.dll
2008-02-14 02:04 56,320 —-a-w C:\Windows\System32\iesetup.dll
2008-02-14 02:04 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-14 02:04 26,624 —-a-w C:\Windows\System32\ieUnatt.exe
2008-02-07 19:34 ——— d—–w C:\ProgramData\Symantec
2008-02-07 19:34 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-03 13:03 ——— d—–w C:\ProgramData\Roxio
2008-02-02 22:11 ——— d—–w C:\Program Files\MSBuild
2008-01-27 10:41 ——— d—–w C:\Users\Sofia\AppData\Roaming\vlc
2008-01-13 22:30 ——— d—–w C:\Users\Sofia\AppData\Roaming\Roxio
2008-01-10 02:11 ——— d—–w C:\Program Files\Windows Mail
2008-01-10 02:02 211,000 —-a-w C:\Windows\system32\drivers\volsnap.sys
2008-01-10 02:02 1,060,920 —-a-w C:\Windows\system32\drivers\ntfs.sys
2008-01-10 02:02 ——— d—–w C:\Program Files\Windows Sidebar
2008-01-10 02:01 11,776 —-a-w C:\Windows\System32\sbunattend.exe
2007-12-27 20:47 ——— d—–w C:\Program Files\Azureus
2007-12-14 10:32 12,632 —-a-w C:\Windows\System32\lsdelete.exe
2007-12-12 02:06 9,728 —-a-w C:\Windows\System32\LAPRXY.DLL
2007-12-12 02:06 223,232 —-a-w C:\Windows\System32\WMASF.DLL
2007-12-12 02:06 1,327,104 —-a-w C:\Windows\System32\quartz.dll
2007-11-17 21:41 174 –sha-w C:\Program Files\desktop.ini
2007-11-17 21:45 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-11-17 21:45 32,768 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-11-17 21:45 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 03:01 1232896]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:35 5724184]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-08-21 19:18 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-08 03:33 4423680 C:\Windows\RtHDVCpl.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-10 02:58 835584]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-06-30 02:08 137752]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-06-30 02:07 154136]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-06-30 02:07 133656]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 11:06 40048]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2007-06-12 02:27 317560]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-21 22:54 1831424]
"Norton Save and Restore 2.0"="C:\Program Files\Norton Save and Restore\Agent\VProTray.exe" [2007-02-14 02:57 2020968]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 21:52 49152]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-07 20:53 579072]
"Malwarebytes Anti-Malware Reboot"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [2008-02-21 19:50 605904]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-07 20:53 219136]

C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Sk„rmurklipp och start f”r OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-27 04:24:54 98632]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2008-02-07 20:53 9216 C:\Windows\System32\avgwlntf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2007-07-25 03:26 98304 C:\Windows\System32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{68A39EE3-66CA-47C4-8288-8C00FBF3FA68}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{6FECA5CF-FB64-4A10-958C-9D549F65FD6B}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{BA8F7637-1196-4845-9FA9-5050DA3863BB}"= UDP:C:\Program Files\Google\Google Talk\googletalk.exe:Google Talk
"{471DDC08-D391-4C56-A25F-F5B1DF5E6C17}"= TCP:C:\Program Files\Google\Google Talk\googletalk.exe:Google Talk
"{F34D4B24-D82F-4A2D-A1A1-72452A82BE00}"= Disabled:UDP:C:\Program Files\sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{47783E44-0CA5-4AD7-A4E2-B09D3FB6D5FD}"= Disabled:TCP:C:\Program Files\sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{F45E71EB-45F4-494B-90A0-FA5C30859925}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{09C11461-2A22-4C66-A373-12F0576E5501}"= Disabled:UDP:C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{7224D204-EF71-4D0A-B033-C36D1221A3C8}"= Disabled:TCP:C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{A254833E-C9B1-46AC-8CC0-CA2696B255CC}"= Disabled:UDP:F:\setup\HPZNUI01.EXE:hpznui01.exe
"{FCDEC41D-A74C-4FBA-B49B-C32E5C6CC2E9}"= Disabled:TCP:F:\setup\HPZNUI01.EXE:hpznui01.exe
"{F3AD9BA8-2EAF-4F5C-AC3C-70729B2E72FC}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{9F296501-D0C9-48AB-897C-32E4041C5E81}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{1A2AF5F4-5521-49E6-8241-4E627FE2D25A}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"TCP Query User{694634A9-ECE4-45D9-B502-6F5D9189C809}C:\program files\azureus\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"UDP Query User{285F4D73-51DE-44DC-8677-E821DA2AF0F5}C:\program files\azureus\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"TCP Query User{73AD90BA-15CE-4E61-935E-70546F2CDE6E}C:\program files\internet explorer\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer|Desc=Internet Explorer
"UDP Query User{1853AA5B-CFCC-49E1-9EB6-4C5E99DDE39B}C:\program files\internet explorer\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer|Desc=Internet Explorer

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R2 HPSLPSVC;HP Network Devices Support;C:\Windows\system32\svchost.exe [2006-11-02 10:45]
R2 regi;regi;C:\Windows\system32\drivers\regi.sys [2007-04-18 04:09]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-26 05:55]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-06-16 01:17]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2007-05-30 19:14]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-06-30 02:07]
R3 NETw4v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-06-30 12:04]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;C:\Windows\system32\Drivers\R5U870FLx86.sys [2007-04-20 01:01]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;C:\Windows\system32\Drivers\R5U870FUx86.sys [2007-04-20 01:01]
R3 RTL8169;Realtek 8169 NT Driver;C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-07-06 11:27]
R3 ti21sony;ti21sony;C:\Windows\system32\drivers\ti21sony.sys [2007-06-06 01:00]
S3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-07-07 01:10]
S3 Norton Save and Restore;Norton Save and Restore;C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe [2007-02-14 02:57]
S3 TcUsb;TC USB Kernel Driver;C:\Windows\system32\Drivers\tcusb.sys [2007-05-29 01:01]
S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;C:\Program Files\sony\VAIO Media Integrated Server\UCLS.exe [2007-01-11 00:51]
S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);"C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-UCLS-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" []
S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-06-20 23:34]
S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;"C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe" [2007-07-06 03:12]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;"C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe" [2007-07-06 01:43]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0cbd5228-9788-11dc-a7c7-001bfb867597}]
\shell\AutoRun\command - H:\setupSNK.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-24 22:20:01 C:\Windows\Tasks\At1.job"
- C:\Windows\system32\kmd.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-24 23:22:00
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\sony\VAIO Event Service\VESMgrSub.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Windows\system32\conime.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Windows\ehome\ehmsas.exe
C:\\?\C:\Windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2008-02-24 23:26:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-24 22:26:09
.
2008-02-17 02:01:11 — E O F —



————————————————————————————————–

Hijackthis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:33:05, on 2008-02-24
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Windows\system32\conime.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\sony\ISB Utility\ISBMgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\Explorer.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.superstart.se/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Norton Save and Restore 2.0] "C:\Program Files\Norton Save and Restore\Agent\VProTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NÄTVERKSTJÄNST')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Skärmurklipp och start för OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Save and Restore - Symantec Corporation - C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 12130 bytes
Hello Sophia,

Thanks for being so patient, we need to remove the file you posted about and the file that's related to it.

Open Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::

File::
C:\Windows\System32\drivers\core.cache.dsk
C:\Windows\System32\drivers\srvnett.sys

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.
Hi again Ken! :)

I did what you asked and here are the logs. My computer is working great now! Thanks a million!! Wish I could give you a big hug!!! :woot:

//Sofia


Combofix log:


ComboFix 08-02-24.2 - Sofia 2008-02-25 2:22:28.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1053.18.1002 [GMT 1:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Users\Sofia\Desktop\CFscript.txt
* Created a new restore point

FILE ::
C:\Windows\System32\drivers\core.cache.dsk
C:\Windows\System32\drivers\srvnett.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Windows\System32\drivers\core.cache.dsk
C:\Windows\System32\drivers\srvnett.sys

.
((((((((((((((((((((((((( Files Created from 2008-01-25 to 2008-02-25 )))))))))))))))))))))))))))))))
.

2008-02-23 16:50 . 2008-02-23 16:50 d——– C:\Users\Sofia\AppData\Roaming\SUPERAntiSpyware.com
2008-02-23 16:50 . 2008-02-23 16:50 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-02-23 16:50 . 2008-02-24 23:37 d——– C:\Program Files\SUPERAntiSpyware
2008-02-22 23:47 . 2008-02-22 23:47 d——– C:\Users\Sofia\AppData\Roaming\Malwarebytes
2008-02-22 23:47 . 2008-02-22 23:47 d——– C:\ProgramData\Malwarebytes
2008-02-22 23:47 . 2008-02-23 00:06 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-22 23:38 . 2008-02-22 23:38 d——– C:\Users\Sofia\AppData\Roaming\Download Manager
2008-02-15 20:55 . 2008-01-10 06:50 1,244,672 –a—— C:\Windows\System32\mcmde.dll
2008-02-14 03:13 . 2008-02-14 03:13 194,560 –a—— C:\Windows\System32\WebClnt.dll
2008-02-14 03:13 . 2008-02-14 03:13 110,080 –a—— C:\Windows\System32\drivers\mrxdav.sys
2008-02-14 03:08 . 2008-02-14 03:08 3,504,696 –a—— C:\Windows\System32\ntkrnlpa.exe
2008-02-14 03:08 . 2008-02-14 03:08 3,470,392 –a—— C:\Windows\System32\ntoskrnl.exe
2008-02-14 03:08 . 2008-02-14 03:08 154,624 –a—— C:\Windows\System32\drivers\nwifi.sys
2008-02-14 03:08 . 2008-02-14 03:08 109,624 –a—— C:\Windows\System32\drivers\ataport.sys
2008-02-14 03:08 . 2008-02-14 03:08 45,112 –a—— C:\Windows\System32\drivers\pciidex.sys
2008-02-14 03:08 . 2008-02-14 03:08 21,560 –a—— C:\Windows\System32\drivers\atapi.sys
2008-02-14 03:08 . 2008-02-14 03:08 17,464 –a—— C:\Windows\System32\drivers\intelide.sys
2008-02-14 03:07 . 2008-02-14 03:07 4,247,552 –a—— C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-14 03:07 . 2008-02-14 03:07 1,686,528 –a—— C:\Windows\System32\gameux.dll
2008-02-14 03:07 . 2008-02-14 03:07 803,328 –a—— C:\Windows\System32\drivers\tcpip.sys
2008-02-14 03:07 . 2008-02-14 03:07 216,632 –a—— C:\Windows\System32\drivers\netio.sys
2008-02-14 03:07 . 2008-02-14 03:07 167,424 –a—— C:\Windows\System32\tcpipcfg.dll
2008-02-14 03:07 . 2008-02-14 03:07 24,064 –a—— C:\Windows\System32\netcfg.exe
2008-02-14 03:07 . 2008-02-14 03:07 22,016 –a—— C:\Windows\System32\netiougc.exe
2008-02-13 20:00 . 2008-02-13 20:00 d——– C:\Program Files\Trend Micro
2008-02-12 19:06 . 2008-02-12 20:58 d——– C:\Program Files\a-squared Free
2008-02-12 18:59 . 2008-02-12 18:59 d——– C:\Program Files\Sophos
2008-02-12 18:37 . 2008-02-12 19:00 d-a—— C:\ProgramData\TEMP
2008-02-12 18:37 . 2007-12-10 14:53 81,288 –a—— C:\Windows\System32\drivers\iksyssec.sys
2008-02-12 18:37 . 2007-12-10 14:53 66,952 –a—— C:\Windows\System32\drivers\iksysflt.sys
2008-02-12 18:37 . 2007-12-10 14:53 41,864 –a—— C:\Windows\System32\drivers\ikfilesec.sys
2008-02-12 18:37 . 2007-12-10 14:53 29,576 –a—— C:\Windows\System32\drivers\kcom.sys
2008-02-12 18:36 . 2008-02-12 18:36 d——– C:\Users\Sofia\AppData\Roaming\PC Tools
2008-02-12 18:36 . 2008-02-12 18:52 d——– C:\Program Files\Spyware Doctor
2008-02-09 16:15 . 2008-02-09 16:15 d——– C:\Program Files\Opera
2008-02-09 16:01 . 2008-02-09 16:01 d——– C:\Program Files\InterMute
2008-02-09 16:01 . 2004-10-20 11:42 328,488 –a—— C:\Users\Sofia\CWSInstall.exe
2008-02-08 19:52 . 2008-02-08 19:54 d——– C:\ProgramData\Lavasoft
2008-02-08 19:52 . 2008-02-08 19:52 d——– C:\Program Files\Lavasoft
2008-02-08 19:51 . 2008-02-23 16:49 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-07 20:54 . 2008-02-24 23:27 d——– C:\Users\Sofia\AppData\Roaming\AVG7
2008-02-07 20:53 . 2008-02-07 20:53 d——– C:\ProgramData\Grisoft
2008-02-07 20:53 . 2008-02-07 20:53 9,216 –a—— C:\Windows\System32\avgwlntf.dll
2008-02-07 20:44 . 2008-02-08 19:04 d——– C:\ProgramData\Avg7
2008-02-02 23:05 . 2008-02-02 23:05 d——– C:\Program Files\Microsoft Visual Studio 8
2008-02-02 22:38 . 2008-02-02 22:38 d——– C:\Program Files\MagicISO
2008-02-01 18:50 . 2008-02-01 18:50 d——– C:\Program Files\Mirror of Beauty
2008-01-27 23:19 . 2008-01-27 23:19 d——– C:\Users\Sofia\AppData\Roaming\Acoustica
2008-01-27 23:19 . 2003-02-24 17:17 299,552 –a—— C:\Windows\wmsysprx.prx
2008-01-27 23:18 . 2008-01-27 23:19 d——– C:\Program Files\Acoustica CD Label Maker
2008-01-27 22:01 . 2008-01-27 22:01 d——– C:\Program Files\Easy CD & DVD Cover Creator
2008-01-27 21:28 . 2008-01-27 21:28 d——– C:\Program Files\Label Maker Wizard
2008-01-27 21:22 . 2008-01-27 21:22 d——– C:\Users\Sofia\AppData\Roaming\Preclick
2008-01-27 18:55 . 2008-01-27 18:56 d——– C:\Users\Sofia\AppData\Roaming\Printer Info Cache
2008-01-27 18:55 . 2008-01-27 21:51 d——– C:\Users\Sofia\AppData\Roaming\Image Zone Express
2008-01-27 17:58 . 2008-01-27 17:58 d——– C:\ProgramData\WEBREG
2008-01-27 13:57 . 2008-01-27 18:55 d——– C:\Users\Sofia\AppData\Roaming\HP
2008-01-27 13:56 . 2008-01-27 13:56 d——– C:\ProgramData\HPSSUPPLY
2008-01-27 13:51 . 2008-01-27 13:51 d——– C:\Program Files\Hewlett-Packard
2008-01-27 13:51 . 2008-01-27 13:51 d——– C:\Program Files\Common Files\Hewlett-Packard
2008-01-27 13:50 . 2008-01-27 13:55 d——– C:\Program Files\Common Files\HP
2008-01-27 13:48 . 2008-01-27 13:48 d——– C:\ProgramData\Hewlett-Packard
2008-01-27 13:30 . 2006-12-16 07:19 897,024 –a—— C:\Windows\System32\hpotiop1.dll
2008-01-27 13:30 . 2006-12-16 07:19 675,840 –a—— C:\Windows\System32\hpowiav1.dll
2008-01-27 13:30 . 2006-12-16 07:19 303,104 –a—— C:\Windows\System32\hpovst01.dll
2008-01-27 13:29 . 2007-02-01 09:24 258,048 –a—— C:\Windows\System32\hpzids01.dll
2008-01-27 13:29 . 2007-02-01 09:24 258,048 –a—— C:\hpzids01.dll
2008-01-27 13:29 . 2005-06-20 14:33 163,840 –a—— C:\Windows\System32\HPJCMN2U.DLL
2008-01-27 13:29 . 2007-02-02 11:27 117,760 –a—— C:\Windows\System32\hpz3l4v2.dll
2008-01-27 13:29 . 2005-06-20 14:33 94,208 –a—— C:\Windows\System32\HPJIPX1U.DLL
2008-01-27 13:28 . 2006-06-06 14:20 241,721 –a—— C:\Windows\System32\HPBMINI.DLL
2008-01-27 13:28 . 2005-06-20 14:33 49,152 –a—— C:\Windows\System32\HPBNRAC2.DLL
2008-01-27 13:28 . 2006-11-16 19:16 38,912 –a—— C:\Windows\System32\HPBPRO.DLL
2008-01-27 13:28 . 2006-11-16 19:15 25,600 –a—— C:\Windows\System32\HPBOID.DLL
2008-01-27 13:28 . 2006-11-16 19:16 24,576 –a—— C:\Windows\System32\HPBMIAPI.DLL
2008-01-27 13:28 . 2006-11-02 19:32 18,747 –a—— C:\Windows\System32\HPCEAC06.HPI
2008-01-27 13:28 . 2006-11-16 19:16 7,680 –a—— C:\Windows\System32\HPBPROPS.DLL
2008-01-27 13:28 . 2006-11-16 19:16 7,680 –a—— C:\Windows\System32\HPBOIDPS.DLL
2008-01-27 13:27 . 2008-01-27 13:56 d——– C:\Program Files\HP
2008-01-27 13:06 . 2008-01-27 17:59 139,414 –a—— C:\Windows\hpoins18.dat
2008-01-27 13:04 . 2008-01-27 18:55 d——– C:\ProgramData\HP
2008-01-27 11:41 . 2008-01-27 11:41 d——– C:\Users\Sofia\AppData\Roaming\vlc
2008-01-27 11:31 . 2008-01-27 11:31 d——– C:\Program Files\VideoLAN

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 22:34 ——— d—–w C:\Users\Sofia\AppData\Roaming\Azureus
2008-02-14 02:08 ——— d—–w C:\ProgramData\Microsoft Help
2008-02-14 02:07 537,600 —-a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-14 02:07 449,536 —-a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-14 02:07 2,144,256 —-a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-14 02:07 173,056 —-a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-14 02:04 824,832 —-a-w C:\Windows\System32\wininet.dll
2008-02-14 02:04 56,320 —-a-w C:\Windows\System32\iesetup.dll
2008-02-14 02:04 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-14 02:04 26,624 —-a-w C:\Windows\System32\ieUnatt.exe
2008-02-07 19:34 ——— d—–w C:\ProgramData\Symantec
2008-02-07 19:34 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-03 13:03 ——— d—–w C:\ProgramData\Roxio
2008-02-02 22:11 ——— d—–w C:\Program Files\MSBuild
2008-01-27 10:41 ——— d—–w C:\Users\Sofia\AppData\Roaming\vlc
2008-01-13 22:30 ——— d—–w C:\Users\Sofia\AppData\Roaming\Roxio
2008-01-10 02:11 ——— d—–w C:\Program Files\Windows Mail
2008-01-10 02:02 211,000 —-a-w C:\Windows\system32\drivers\volsnap.sys
2008-01-10 02:02 1,060,920 —-a-w C:\Windows\system32\drivers\ntfs.sys
2008-01-10 02:02 ——— d—–w C:\Program Files\Windows Sidebar
2008-01-10 02:01 11,776 —-a-w C:\Windows\System32\sbunattend.exe
2007-12-27 20:47 ——— d—–w C:\Program Files\Azureus
2007-12-14 10:32 12,632 —-a-w C:\Windows\System32\lsdelete.exe
2007-12-12 02:06 9,728 —-a-w C:\Windows\System32\LAPRXY.DLL
2007-12-12 02:06 223,232 —-a-w C:\Windows\System32\WMASF.DLL
2007-12-12 02:06 1,327,104 —-a-w C:\Windows\System32\quartz.dll
2007-11-17 21:41 174 –sha-w C:\Program Files\desktop.ini
2007-11-17 21:45 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-11-17 21:45 32,768 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-11-17 21:45 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 03:01 1232896]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:35 5724184]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-08-21 19:18 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-08 03:33 4423680 C:\Windows\RtHDVCpl.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-10 02:58 835584]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-06-30 02:08 137752]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-06-30 02:07 154136]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-06-30 02:07 133656]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 11:06 40048]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2007-06-12 02:27 317560]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-21 22:54 1831424]
"Norton Save and Restore 2.0"="C:\Program Files\Norton Save and Restore\Agent\VProTray.exe" [2007-02-14 02:57 2020968]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 21:52 49152]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-07 20:53 579072]
"Malwarebytes Anti-Malware Reboot"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [2008-02-21 19:50 605904]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-07 20:53 219136]

C:\Users\Sofia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Sk„rmurklipp och start f”r OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-27 04:24:54 98632]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2008-02-07 20:53 9216 C:\Windows\System32\avgwlntf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2007-07-25 03:26 98304 C:\Windows\System32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{68A39EE3-66CA-47C4-8288-8C00FBF3FA68}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{6FECA5CF-FB64-4A10-958C-9D549F65FD6B}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{BA8F7637-1196-4845-9FA9-5050DA3863BB}"= UDP:C:\Program Files\Google\Google Talk\googletalk.exe:Google Talk
"{471DDC08-D391-4C56-A25F-F5B1DF5E6C17}"= TCP:C:\Program Files\Google\Google Talk\googletalk.exe:Google Talk
"{F34D4B24-D82F-4A2D-A1A1-72452A82BE00}"= Disabled:UDP:C:\Program Files\sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{47783E44-0CA5-4AD7-A4E2-B09D3FB6D5FD}"= Disabled:TCP:C:\Program Files\sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{F45E71EB-45F4-494B-90A0-FA5C30859925}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{09C11461-2A22-4C66-A373-12F0576E5501}"= Disabled:UDP:C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{7224D204-EF71-4D0A-B033-C36D1221A3C8}"= Disabled:TCP:C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{A254833E-C9B1-46AC-8CC0-CA2696B255CC}"= Disabled:UDP:F:\setup\HPZNUI01.EXE:hpznui01.exe
"{FCDEC41D-A74C-4FBA-B49B-C32E5C6CC2E9}"= Disabled:TCP:F:\setup\HPZNUI01.EXE:hpznui01.exe
"{F3AD9BA8-2EAF-4F5C-AC3C-70729B2E72FC}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{9F296501-D0C9-48AB-897C-32E4041C5E81}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{1A2AF5F4-5521-49E6-8241-4E627FE2D25A}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"TCP Query User{694634A9-ECE4-45D9-B502-6F5D9189C809}C:\program files\azureus\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"UDP Query User{285F4D73-51DE-44DC-8677-E821DA2AF0F5}C:\program files\azureus\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"TCP Query User{73AD90BA-15CE-4E61-935E-70546F2CDE6E}C:\program files\internet explorer\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer|Desc=Internet Explorer
"UDP Query User{1853AA5B-CFCC-49E1-9EB6-4C5E99DDE39B}C:\program files\internet explorer\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer|Desc=Internet Explorer

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R2 HPSLPSVC;HP Network Devices Support;C:\Windows\system32\svchost.exe [2006-11-02 10:45]
R2 regi;regi;C:\Windows\system32\drivers\regi.sys [2007-04-18 04:09]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-26 05:55]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-06-16 01:17]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2007-05-30 19:14]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-06-30 02:07]
R3 NETw4v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-06-30 12:04]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;C:\Windows\system32\Drivers\R5U870FLx86.sys [2007-04-20 01:01]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;C:\Windows\system32\Drivers\R5U870FUx86.sys [2007-04-20 01:01]
R3 RTL8169;Realtek 8169 NT Driver;C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-07-06 11:27]
R3 ti21sony;ti21sony;C:\Windows\system32\drivers\ti21sony.sys [2007-06-06 01:00]
S3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-07-07 01:10]
S3 Norton Save and Restore;Norton Save and Restore;C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe [2007-02-14 02:57]
S3 TcUsb;TC USB Kernel Driver;C:\Windows\system32\Drivers\tcusb.sys [2007-05-29 01:01]
S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;C:\Program Files\sony\VAIO Media Integrated Server\UCLS.exe [2007-01-11 00:51]
S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);"C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-UCLS-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" []
S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-06-20 23:34]
S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;"C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe" [2007-07-06 03:12]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;"C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe" [2007-07-06 01:43]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0cbd5228-9788-11dc-a7c7-001bfb867597}]
\shell\AutoRun\command - H:\setupSNK.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-24 22:20:01 C:\Windows\Tasks\At1.job"
- C:\Windows\system32\kmd.exe
"2008-02-25 01:25:58 C:\Windows\Tasks\At2.job"
- C:\Windows\system32\kmd.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-25 02:30:04
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\sony\VAIO Event Service\VESMgrSub.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Windows\system32\conime.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Windows\ehome\ehmsas.exe
C:\\?\C:\Windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2008-02-25 2:33:41 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-25 01:33:38
ComboFix2.txt 2008-02-24 22:26:14
.
2008-02-17 02:01:11 — E O F —




——————————————————————————————————-







Hijackthis log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:36:34, on 2008-02-25
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\sony\ISB Utility\ISBMgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\Explorer.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.superstart.se/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Norton Save and Restore 2.0] "C:\Program Files\Norton Save and Restore\Agent\VProTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NÄTVERKSTJÄNST')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Skärmurklipp och start för OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Save and Restore - Symantec Corporation - C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 12172 bytes
Sophia,

I did what you asked and here are the logs. My computer is working great now! Thanks a million!! Wish I could give you a big hug!!! :blush:

Your log looks great :thumbup: You need to update your Java as the older versions may leave holes for the bad guys to get in.

  • Your Java is out of date and leaving your system vulnerable.
  • Go to your Add-Remove Programs in the Control Panel and uninstall any previous versions of Java (J2SE Runtime Environment)
  • It should have an icon next to it:
    [external image: Posted Image]
    Select it and click Remove.
  • Reboot your system.
  • Then go to the Sun Microsystems and install the update
  • Java Runtime Environment (JRE) 6 Update 4 <–This is what you need to download and install.
  • If you chose the online installation, it will prompt you to run the program.
  • If you chose the offline installation, you will be prompted to save the file and you can run it from wherever you saved it.
  • Then after install you can verify your installation here Sun Java Verify
I like to to do the offline installation and save the setup file in case I may need it in the future



I am going to link you to some free programs to install to help keep you more secure, you may have to check when you download them as with Vista being new some may not work.

Free Anti Virus Programs, you just need one so uninstall any you may have before you install one of these, more than one AV is overkill and will slow up your system




A Firewall also should be installed, these are all free, like AV, you just need one.




  • How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • WhattheTech
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports


Glad things are well for you, be careful on the internet, there are some serious threats going around as you now know.

Ken :)
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI