This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected with Setthetrend, etc

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi. I have ran Ad-Aware, Spybot, Stinger…still infected. Would be very grateful if someone could help me get rid of this. Thank you for your time. Following is my HJT log.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:12:42 AM, on 2/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\end user\My Documents\olivia\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1634C762-D91C-430F-9362-C8E5DEEE36A6} - C:\WINDOWS\system32\mllmm.dll
O2 - BHO: {4240b663-8f40-98b8-08c4-3f073e88d4c2} - {2c4d88e3-70f3-4c80-8b89-04f8366b0424} - C:\WINDOWS\system32\sjlbprot.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [d8ced1a8] rundll32.exe "C:\WINDOWS\system32\vvwaurum.dll",b
O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\ENDUSE~1\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Web-Based Email Tools - http://email.secureserver.net/Download.CAB
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {75565ED2-1560-4F15-B841-20358DE6A0D1} (ImageControl Class) - http://c.ancestry.com/cab/ImageViewer/MFImgVwr.cab
O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - http://clubgames.pogo.com/online2/pogop/ma…mesLauncher.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - http://a248.e.akamai.net/f/248/5462/2h/www…ol/SymDlBrg.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin.cab
O20 - Winlogon Notify: ssqnolj - ssqnolj.dll (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DBISAM Database Server - DBSRVR (DBSRVR) - Unknown owner - C:\CCWIN\dbsrvr.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O24 - Desktop Component 0: (no name) - C:\Documents and Settings\end user\My Documents\My Pictures\Mom33.JPG
O24 - Desktop Component 1: (no name) - C:\Documents and Settings\end user\My Documents\My Pictures\stairwaytoHeavenv.JPG
O24 - Desktop Component 10: (no name) - C:\Documents and Settings\end user\My Documents\plaid.html
O24 - Desktop Component 11: (no name) - C:\Documents and Settings\end user\My Documents\lily.html
O24 - Desktop Component 12: (no name) - C:\Documents and Settings\end user\My Documents\daisy.html
O24 - Desktop Component 13: (no name) - C:\Documents and Settings\end user\My Documents\baby.html
O24 - Desktop Component 3: (no name) - C:\Documents and Settings\end user\My Documents\two.html
O24 - Desktop Component 4: (no name) - C:\Documents and Settings\end user\My Documents\bd.html
O24 - Desktop Component 5: (no name) - C:\Documents and Settings\end user\My Documents\grpa.html
O24 - Desktop Component 6: (no name) - C:\Documents and Settings\end user\My Documents\job.html
O24 - Desktop Component 7: (no name) - C:\Documents and Settings\end user\My Documents\sue.html
O24 - Desktop Component 8: (no name) - C:\Documents and Settings\end user\My Documents\april.html
O24 - Desktop Component 9: (no name) - C:\Documents and Settings\end user\My Documents\august.html.html

–
End of file - 9608 bytes
Hello, and welcome to the forum.

My name is Simon V., and I'll be glad to help you with your computer problems.

Step 1

Please download and install CCleaner.

Open CCleaner. On the Windows tab, leave the default options alone.

  • On the Applications tab, check (tick) all the boxes except Saved Form Information. This will remove all your saved passwords if you leave this box checked.
  • Click on the Run Cleaner button at the bottom right hand corner.
  • When the cleaner has completed, click Tools in the Left Pane.
  • Verify that Uninstall is highlighted in color, or click on it.
  • In the lower right, click Save to Text File.
  • Pull down the arrow at the top of the Save dialog and choose Desktop as the location.
  • You can leave the filename as install.txt.
  • Click Save, then exit Ccleaner.

Step 2

Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Post the log from ComboFix (C:\Combofix.txt) when you've accomplished that, along with a new HijackThis log and the CCleaner Uninstall List (install.txt
Simon,
Hi. Thank you sooo much for helping me. Following are the logs you requested:

ComboFix 08-02-18.1 - end user 2008-02-18 10:11:05.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.219 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\b122.exe
C:\WINDOWS\system32\awvvs.dll
C:\WINDOWS\system32\ddayy.dll
C:\WINDOWS\system32\mllmm.dll
C:\check_LSA7.txt
C:\Program Files\Temporary
C:\Temp\isgTi19
C:\Temp\tpBe12
C:\WINDOWS\b122.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\awvvs.dll
C:\WINDOWS\system32\bpwkrmdd.dll
C:\WINDOWS\system32\cybvqsre.ini
C:\WINDOWS\system32\ddayy.dll
C:\WINDOWS\system32\ddmrkwpb.ini
C:\WINDOWS\system32\fmrlpxfy.dll
C:\WINDOWS\system32\fxactfxr.dll
C:\WINDOWS\system32\gcewpcac.ini
C:\WINDOWS\system32\gkhlaibg.dll
C:\WINDOWS\system32\gvidipgc.dll
C:\WINDOWS\system32\ixryrchn.dll
C:\WINDOWS\system32\mllmm.dll
C:\WINDOWS\system32\mmllm.bak1
C:\WINDOWS\system32\mmllm.bak2
C:\WINDOWS\system32\mmllm.ini
C:\WINDOWS\system32\mmllm.ini2
C:\WINDOWS\system32\mmllm.tmp
C:\WINDOWS\system32\mmllm.tmp2
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\nqsrkuhf.dll
C:\WINDOWS\system32\nxfxreqk.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\qhelqkph.dll
C:\WINDOWS\system32\rggaedqb.dll
C:\WINDOWS\system32\rkixgnyg.dll
C:\WINDOWS\system32\rulyetkl.ini
C:\WINDOWS\system32\svvwa.bak1
C:\WINDOWS\system32\svvwa.bak2
C:\WINDOWS\system32\svvwa.ini
C:\WINDOWS\system32\svvwa.ini2
C:\WINDOWS\system32\svvwa.tmp
C:\WINDOWS\system32\uninstall.exe
C:\WINDOWS\system32\vlnkjxhg.ini
C:\WINDOWS\system32\vudujthk.dll
C:\WINDOWS\system32\wojbacfd.ini
C:\WINDOWS\system32\yrydgtlm.dll
C:\WINDOWS\system32\yyadd.bak1
C:\WINDOWS\system32\yyadd.bak2
C:\WINDOWS\system32\yyadd.ini
C:\WINDOWS\system32\yyadd.ini2
C:\WINDOWS\system32\yyadd.tmp

.
((((((((((((((((((((((((( Files Created from 2008-01-18 to 2008-02-18 )))))))))))))))))))))))))))))))
.

2008-02-18 09:37 . 2008-02-18 09:37 d——– C:\Program Files\CCleaner
2008-02-18 09:31 . 2008-02-18 09:31 14,103 –a—— C:\IDLTEMP.JPG
2008-02-15 15:02 . 2008-02-15 15:56 1,494 –ahs—- C:\WINDOWS\system32\kxmpykkf.ini
2008-02-15 14:22 . 2008-02-15 15:01 1,374 –ahs—- C:\WINDOWS\system32\kucuquem.ini
2008-02-15 13:47 . 2008-02-15 14:16 1,254 –ahs—- C:\WINDOWS\system32\vyujnalf.ini
2008-02-15 13:24 . 2008-02-15 13:44 954 –ahs—- C:\WINDOWS\system32\jcnbpgci.ini
2008-02-15 13:20 . 2008-02-15 13:24 834 –ahs—- C:\WINDOWS\system32\jvjbeagn.ini
2008-02-12 10:00 . 2008-02-12 09:58 294 –ahs—- C:\WINDOWS\system32\ctpoixtm.ini
2008-02-12 09:59 . 2008-02-12 09:59 93,248 –a—— C:\WINDOWS\system32\vunpocgc.dll
2008-02-12 09:58 . 2008-02-12 09:58 93,248 –a—— C:\WINDOWS\system32\sjlbprot.dll
2008-02-12 09:58 . 2008-02-15 09:04 714 –ahs—- C:\WINDOWS\system32\muruawvv.ini
2008-02-09 11:51 . 2008-02-09 11:51 89,664 –a—— C:\WINDOWS\system32\ptjbofvy.dll
2008-02-09 11:51 . 2008-02-09 11:51 294 –ahs—- C:\WINDOWS\system32\yvfobjtp.ini
2008-02-08 12:19 . 2008-02-08 12:19 354 –ahs—- C:\WINDOWS\system32\cqkjxmcd.ini
2008-02-08 12:18 . 2008-02-08 12:18 94,784 –a—— C:\WINDOWS\system32\mniluttl.dll
2008-02-08 12:18 . 2008-02-08 12:18 88,640 –a—— C:\WINDOWS\system32\dcmxjkqc.dll
2008-02-07 12:16 . 2008-02-08 12:16 294 –ahs—- C:\WINDOWS\system32\pyvufnqm.ini
2008-02-07 11:29 . 2008-02-07 11:29 d——– C:\Documents and Settings\end user\Application Data\MSN6
2008-02-07 11:29 . 2008-02-07 11:29 d——– C:\Documents and Settings\All Users\Application Data\MSN6
2008-02-07 01:05 . 2008-02-07 01:05 474 –ahs—- C:\WINDOWS\system32\oojgompv.ini
2008-02-07 01:04 . 2008-02-07 01:04 88,640 –a—— C:\WINDOWS\system32\vpmogjoo.dll
2008-02-06 10:54 . 2008-02-07 01:05 414 –ahs—- C:\WINDOWS\system32\gndswiyo.ini
2008-02-06 10:53 . 2008-02-06 10:53 92,224 –a—— C:\WINDOWS\system32\ialaqdmv.dll
2008-02-06 01:06 . 2008-02-06 01:06 90,688 –a—— C:\WINDOWS\system32\cacpwecg.dll
2008-02-06 01:03 . 2008-02-06 01:03 94,272 –a—— C:\WINDOWS\system32\dguicfcy.dll
2008-02-04 12:50 . 2008-02-04 12:51 40,960 –a—— C:\WINDOWS\system32\wvurrsq.dll
2008-02-04 12:50 . 2008-02-04 12:51 40,960 –a—— C:\WINDOWS\system32\qomnlij.dll
2008-02-04 09:50 . 2008-02-09 09:10 d——– C:\Program Files\Drmupgds
2008-02-04 09:50 . 2008-02-04 09:50 93,248 –a—— C:\WINDOWS\system32\vwhkkncy.dll
2008-02-03 22:10 . 2008-02-03 22:10 92,736 –a—— C:\WINDOWS\system32\aqpinpmr.dll
2008-02-02 22:10 . 2008-02-02 22:10 96,832 –a—— C:\WINDOWS\system32\vrdgmlra.dll
2008-02-01 22:10 . 2008-02-01 22:10 92,736 –a—— C:\WINDOWS\system32\koxfdhpx.dll
2008-02-01 10:01 . 2008-02-01 10:01 38,400 –a—— C:\WINDOWS\system32\wvuvvus.dll
2008-02-01 09:56 . 2008-02-01 09:57 38,400 –a—— C:\WINDOWS\system32\wvuttrs.dll
2008-02-01 09:56 . 2008-02-01 09:57 38,400 –a—— C:\WINDOWS\system32\khfdayw.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-18 15:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-15 23:31 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-09 17:55 ——— d—–w C:\Program Files\McAfee
2008-02-04 15:57 ——— d—–w C:\Program Files\Oberon Media
2008-02-04 15:55 ——— d—–w C:\Program Files\Skype
2008-02-04 15:53 ——— d—–w C:\Program Files\Kazaa
2008-02-04 15:52 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-16 19:45 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-07 16:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-01-07 16:55 ——— d—–w C:\Documents and Settings\end user\Application Data\Viewpoint
2008-01-07 16:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-07 16:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-20 21:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\SpinTop Games
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2005-04-07 15:25 31,645 —-a-w C:\WINDOWS\Fonts\ennobled.zip
2005-03-28 17:53 65,015 —-a-w C:\WINDOWS\Fonts\ropemf.zip
2005-03-28 17:52 81,721 —-a-w C:\WINDOWS\Fonts\howdy.zip
2005-03-28 17:52 172,672 —-a-w C:\WINDOWS\Fonts\boundaoe.zip
2005-01-29 17:21 2,084,888 —-a-w C:\Program Files\reglite.exe
2004-01-27 19:23 3,149 —-a-w C:\Program Files\Common Files\remove_tools.html
2004-12-19 01:16 3,547 –sha-w C:\WINDOWS\gdxly.dat
2005-01-04 10:11 3,547 –sha-w C:\WINDOWS\llqwx.dat
2004-12-06 18:36 0 –sha-w C:\WINDOWS\n_dtgqye.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 17:30 517768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"DELDIR0.EXE"="C:\DOCUME~1\ENDUSE~1\LOCALS~1\Temp\DELDIR0.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-03-06 23:06 5181440]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Documents and Settings\end user\My Documents\My Pictures\Mom33.JPG
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= C:\Documents and Settings\end user\My Documents\My Pictures\stairwaytoHeavenv.JPG
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\10]
Source= C:\Documents and Settings\end user\My Documents\plaid.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\11]
Source= C:\Documents and Settings\end user\My Documents\lily.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\12]
Source= C:\Documents and Settings\end user\My Documents\daisy.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\13]
Source= C:\Documents and Settings\end user\My Documents\baby.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\3]
Source= C:\Documents and Settings\end user\My Documents\two.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\4]
Source= C:\Documents and Settings\end user\My Documents\bd.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\5]
Source= C:\Documents and Settings\end user\My Documents\grpa.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\6]
Source= C:\Documents and Settings\end user\My Documents\job.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\7]
Source= C:\Documents and Settings\end user\My Documents\sue.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\8]
Source= C:\Documents and Settings\end user\My Documents\april.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\9]
Source= C:\Documents and Settings\end user\My Documents\august.html.html
FriendlyName=

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnolj]
ssqnolj.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digimax Viewer 2.0.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digimax Viewer 2.0.lnk
backup=C:\WINDOWS\pss\Digimax Viewer 2.0.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^end user^Start Menu^Programs^Startup^AbsoluteShield Internet Eraser.lnk]
path=C:\Documents and Settings\end user\Start Menu\Programs\Startup\AbsoluteShield Internet Eraser.lnk
backup=C:\WINDOWS\pss\AbsoluteShield Internet Eraser.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^end user^Start Menu^Programs^Startup^Autoup.lnk]
path=C:\Documents and Settings\end user\Start Menu\Programs\Startup\Autoup.lnk
backup=C:\WINDOWS\pss\Autoup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\PROGRA~1\AIM\aim.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2006-04-12 10:30 53408 C:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey]
–a—— 2005-01-11 08:42 477184 C:\WINDOWS\mHotkey.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\d8ced1a8]
–a—— 2008-02-09 11:51 89664 C:\WINDOWS\system32\ptjbofvy.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dit]
–a—— 2005-01-16 18:53 69632 C:\WINDOWS\Dit.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Drmupgds]
C:\Program Files\Drmupgds\Drmupgds.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
–a—— 2007-07-25 15:02 563984 C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
–a—— 2007-07-25 15:06 2027792 C:\Program Files\Logitech\QuickCam\Quickcam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-01-19 12:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
–a—— 2007-03-06 23:06 5181440 C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pop up Blocker]
C:\Program Files\Pop up Blocker\pd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PopupEliminator]
C:\Program Files\SurfSecret\Popup Eliminator\Popup Eliminator TRIAL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2007-04-16 14:28 577536 C:\WINDOWS\soundman.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
C:\Program Files\Spyware Doctor\spydoctor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware-Cop]
C:\PROGRA~1\SPYWAR~1\Spyware-Cop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-07-12 03:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
C:\PROGRA~1\SYMNET~1\SNDMon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
–a—— 2007-07-30 11:40 125504 C:\WINDOWS\system32\jalbmnxd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2007-08-28 12:13 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wben]
C:\Program Files\Starfield\Desktop Notifier\wben.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2002-07-23 10:58 12288 C:\Program Files\Winamp3\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2006-11-30 21:49 4662776 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"KodakCCS"=2 (0x2)

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 15:38]
S2 DBSRVR;DBISAM Database Server - DBSRVR;C:\CCWIN\dbsrvr.exe []

.
Contents of the 'Scheduled Tasks' folder
"2008-02-16 02:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - end user.job"
- C:\PROGRA~1\NORTON~2\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-18 10:19:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
DELDIR0.EXE = "C:\DOCUME~1\ENDUSE~1\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"??????????|????H???l??|q??|???????|????$??? ??|???????|x??|????q??|?o?w`??????????|????,???Q??|?? ?m??|????????????????????????????????????v???C?:?\?P?r?o?g?r?a?m? ?F?i?l?e?s?\?M?c?A?f?e?e?\?M?c?????e?e? ?S?h?a?r?e?d? ?C?o?m?p?o?n?e?n??? ?\?G?u?a?r?d?i?a?n?\?????????p??????????????|p??|????m??|????x???~y?wT???????????????????03??

scanning hidden files …

C:\WINDOWS\SchedLgU.Txt:pnhae 11534 bytes executable
C:\WINDOWS\wiaservc.log:cjwih 10105 bytes executable
C:\WINDOWS\wiaservc.log:coaiev 11534 bytes executable
C:\WINDOWS\wiaservc.log:kunzk 10752 bytes executable

scan completed successfully
hidden files: 4

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2008-02-18 10:23:14 - machine was rebooted [end user]
ComboFix-quarantined-files.txt 2008-02-18 16:23:05
ComboFix2.txt 2007-08-03 14:39:08
.
2008-02-13 09:04:38 — E O F —






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:25:39 AM, on 2/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\end user\My Documents\olivia\HijackThis.exe
C:\Program Files\Norton AntiVirus\NAVW32.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\ENDUSE~1\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Web-Based Email Tools - http://email.secureserver.net/Download.CAB
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1A26F07F-0D60-4835-91CF-1E1766A0EC56} (WebInstall Class) - http://scanner2.malware-scan.com/setup/webinst.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {75565ED2-1560-4F15-B841-20358DE6A0D1} (ImageControl Class) - http://c.ancestry.com/cab/ImageViewer/MFImgVwr.cab
O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - http://clubgames.pogo.com/online2/pogop/ma…mesLauncher.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - http://a248.e.akamai.net/f/248/5462/2h/www…ol/SymDlBrg.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin.cab
O20 - Winlogon Notify: ssqnolj - ssqnolj.dll (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DBISAM Database Server - DBSRVR (DBSRVR) - Unknown owner - C:\CCWIN\dbsrvr.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O24 - Desktop Component 0: (no name) - C:\Documents and Settings\end user\My Documents\My Pictures\Mom33.JPG
O24 - Desktop Component 1: (no name) - C:\Documents and Settings\end user\My Documents\My Pictures\stairwaytoHeavenv.JPG
O24 - Desktop Component 10: (no name) - C:\Documents and Settings\end user\My Documents\plaid.html
O24 - Desktop Component 11: (no name) - C:\Documents and Settings\end user\My Documents\lily.html
O24 - Desktop Component 12: (no name) - C:\Documents and Settings\end user\My Documents\daisy.html
O24 - Desktop Component 13: (no name) - C:\Documents and Settings\end user\My Documents\baby.html
O24 - Desktop Component 3: (no name) - C:\Documents and Settings\end user\My Documents\two.html
O24 - Desktop Component 4: (no name) - C:\Documents and Settings\end user\My Documents\bd.html
O24 - Desktop Component 5: (no name) - C:\Documents and Settings\end user\My Documents\grpa.html
O24 - Desktop Component 6: (no name) - C:\Documents and Settings\end user\My Documents\job.html
O24 - Desktop Component 7: (no name) - C:\Documents and Settings\end user\My Documents\sue.html
O24 - Desktop Component 8: (no name) - C:\Documents and Settings\end user\My Documents\april.html
O24 - Desktop Component 9: (no name) - C:\Documents and Settings\end user\My Documents\august.html.html

–
End of file - 9498 bytes




56Kbps Internal Modem
Ad-Aware SE Personal
Adobe Download Manager 2.0 (Remove Only)
Adobe Flash Player 9 ActiveX
Adobe Reader 7.0.7
Belarc Advisor 7.2
ccCommon
CCleaner (remove only)
CCScore
Digimax Master
Drmupgds
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
essvatgt
Family Tree Maker 9.0
HijackThis 2.0.2
Intel® 82845G Graphics Driver Software
Internet Worm Protection
IrfanView (remove only)
Jasc Paint Shop Pro 8 Dell Edition
Java™ 6 Update 2
kgcbase
Kodak EasyShare software
KSU
LiveUpdate 3.0 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Logitech QuickCam
Logitech® Camera Driver
Macromedia Shockwave Player
Mag-Tek MICRImage Demo
Microsoft Data Access Components KB870669
Microsoft Money 2003
Microsoft Money 2003 System Pack
Microsoft Office 2000 Professional
Microsoft Windows Journal Viewer
Microsoft Word Viewer 97
Microsoft Works 7.0
Move Networks Media Player for Internet Explorer
Mozilla Firefox (2.0.0.9)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
Multi-Card Reader / Flash Disk
Multimedia Keyboard Driver Ver1.0 (KB-0108)
MVision
MySpaceIM
NAVShortcut
netbrdg
Norton AntiVirus 2006
Norton AntiVirus 2006 (Symantec Corporation)
Norton AntiVirus Help
Norton AntiVirus Parent MSI
Norton AntiVirus SYMLT MSI
Norton Protection Center
Norton WMI Update
Notifier
OfotoXMI
RealPlayer
Realtek AC'97 Audio
Registrar Lite 2.00
Samsung USB Driver
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB946026)
SFR
SFR2
SHASTA
Shockwave
SKIN0001
SKINXSDK
SPBBC
Spybot - Search & Destroy 1.3
staticcr
Symantec
Symantec KB-DocID:2003093015493306
Symantec Technical Support Web Controls
SymNet
TimeStationPC
tooltips
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Viewpoint Manager (Remove Only)
Viewpoint Media Player
VPRINTOL
WebEx
WebFldrs XP
Winamp (remove only)
Winamp3 (remove only)
Windows Backup Utility
Windows Installer 3.1 (KB893803)
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WIRELESS
XviD 1.1 final uninstall
Yahoo! Install Manager
Yahoo! Messenger


I am awaiting your next instructions. Thanks again.
Hi :)

Go to Start > Control Panel > Display Properties > Desktop > Customize Desktop… > Web tab.
Uncheck and Delete everything you find in there. (Except for "My Current Home Page")

———————————————————————————-

Go to Microsoft's website => http://support.microsoft.com/kb/310994
Select the download that's appropriate for your Operating System

[external image: Posted Image]

Download the file & save it as it's originally named, next to ComboFix.exe.

[external image: Posted Image]

Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please post the contents of that log.

Please do not reboot your machine until we have reviewed the log.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
Hi :)

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

That's looking good. You can now reboot if you wish to do so.

Norton AntiVirus 2006

Is your Norton subscription up to date?

Step 1

Click on Start, then Control Panel. Double click on Add or Remove Programs.

Please remove the following program(s):

Java™ 6 Update 2
Viewpoint Media Player
<– Only remove this program if you haven't installed it yourself.

Then download and install Java Runtime Environment (JRE) 6 Update 4.

Step 2

Open Notepad (Go to Start > Run, type Notepad and hit Enter), and copy/paste the text in the quotebox below into it:

File::

C:\WINDOWS\system32\kxmpykkf.ini
C:\WINDOWS\system32\kucuquem.ini
C:\WINDOWS\system32\vyujnalf.ini
C:\WINDOWS\system32\jcnbpgci.ini
C:\WINDOWS\system32\jvjbeagn.ini
C:\WINDOWS\system32\ctpoixtm.ini
C:\WINDOWS\system32\vunpocgc.dll
C:\WINDOWS\system32\sjlbprot.dll
C:\WINDOWS\system32\muruawvv.ini
C:\WINDOWS\system32\ptjbofvy.dll
C:\WINDOWS\system32\yvfobjtp.ini
C:\WINDOWS\system32\cqkjxmcd.ini
C:\WINDOWS\system32\mniluttl.dll
C:\WINDOWS\system32\dcmxjkqc.dll
C:\WINDOWS\system32\pyvufnqm.ini
C:\WINDOWS\system32\oojgompv.ini
C:\WINDOWS\system32\vpmogjoo.dll
C:\WINDOWS\system32\gndswiyo.ini
C:\WINDOWS\system32\ialaqdmv.dll
C:\WINDOWS\system32\cacpwecg.dll
C:\WINDOWS\system32\dguicfcy.dll
C:\WINDOWS\system32\wvurrsq.dll
C:\WINDOWS\system32\qomnlij.dll
C:\WINDOWS\system32\vwhkkncy.dll
C:\WINDOWS\system32\aqpinpmr.dll
C:\WINDOWS\system32\vrdgmlra.dll
C:\WINDOWS\system32\koxfdhpx.dll
C:\WINDOWS\system32\wvuvvus.dll
C:\WINDOWS\system32\wvuttrs.dll
C:\WINDOWS\system32\khfdayw.dll
C:\WINDOWS\Fonts\ennobled.zip
C:\WINDOWS\Fonts\ropemf.zip
C:\WINDOWS\Fonts\howdy.zip
C:\WINDOWS\Fonts\boundaoe.zip
C:\WINDOWS\gdxly.dat
C:\WINDOWS\llqwx.dat
C:\WINDOWS\n_dtgqye.dat

Folder::

C:\Program Files\Drmupgds

Registry::

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"DELDIR0.EXE"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnolj]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\d8ced1a8]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Drmupgds]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pop up Blocker]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PopupEliminator]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware-Cop]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wben]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]

Click on File > Save as….

In the File Name box, copy/paste CFScript.txt (Note: Do not change the filename!)

Click Save (Save the CFScript in the same location as Combofix.exe)

Close any open windows.

Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix.

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe.
It will create a log. Be sure to save it to a convenient location.

Step 3

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • You can also access the log by doing the following:

  • Click on the Malwarebytes' Anti-Malware icon to launch the program.
  • Click on the Logs tab.
  • Click on the log at the bottom of those listed to highlight it.
  • Click Open.

Step 4

In your next reply, please post:

  • the Combofix log (C:\Combofix.txt)
  • the Malwarebytes' Anti-Malware log
  • a new HijackThis log
Combofix:

ComboFix 08-02-18.1 - end user 2008-02-18 13:32:52.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.229 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\end user\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\Fonts\boundaoe.zip
C:\WINDOWS\Fonts\ennobled.zip
C:\WINDOWS\Fonts\howdy.zip
C:\WINDOWS\Fonts\ropemf.zip
C:\WINDOWS\gdxly.dat
C:\WINDOWS\llqwx.dat
C:\WINDOWS\n_dtgqye.dat
C:\WINDOWS\system32\aqpinpmr.dll
C:\WINDOWS\system32\cacpwecg.dll
C:\WINDOWS\system32\cqkjxmcd.ini
C:\WINDOWS\system32\ctpoixtm.ini
C:\WINDOWS\system32\dcmxjkqc.dll
C:\WINDOWS\system32\dguicfcy.dll
C:\WINDOWS\system32\gndswiyo.ini
C:\WINDOWS\system32\ialaqdmv.dll
C:\WINDOWS\system32\jcnbpgci.ini
C:\WINDOWS\system32\jvjbeagn.ini
C:\WINDOWS\system32\khfdayw.dll
C:\WINDOWS\system32\koxfdhpx.dll
C:\WINDOWS\system32\kucuquem.ini
C:\WINDOWS\system32\kxmpykkf.ini
C:\WINDOWS\system32\mniluttl.dll
C:\WINDOWS\system32\muruawvv.ini
C:\WINDOWS\system32\oojgompv.ini
C:\WINDOWS\system32\ptjbofvy.dll
C:\WINDOWS\system32\pyvufnqm.ini
C:\WINDOWS\system32\qomnlij.dll
C:\WINDOWS\system32\sjlbprot.dll
C:\WINDOWS\system32\vpmogjoo.dll
C:\WINDOWS\system32\vrdgmlra.dll
C:\WINDOWS\system32\vunpocgc.dll
C:\WINDOWS\system32\vwhkkncy.dll
C:\WINDOWS\system32\vyujnalf.ini
C:\WINDOWS\system32\wvurrsq.dll
C:\WINDOWS\system32\wvuttrs.dll
C:\WINDOWS\system32\wvuvvus.dll
C:\WINDOWS\system32\yvfobjtp.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\aqpinpmr.dll
C:\WINDOWS\system32\cacpwecg.dll
C:\WINDOWS\system32\dcmxjkqc.dll
C:\WINDOWS\system32\dguicfcy.dll
C:\WINDOWS\system32\ialaqdmv.dll
C:\WINDOWS\system32\khfdayw.dll
C:\WINDOWS\system32\koxfdhpx.dll
C:\WINDOWS\system32\mniluttl.dll
C:\WINDOWS\system32\ptjbofvy.dll
C:\WINDOWS\system32\qomnlij.dll
C:\WINDOWS\system32\sjlbprot.dll
C:\WINDOWS\system32\vpmogjoo.dll
C:\WINDOWS\system32\vrdgmlra.dll
C:\WINDOWS\system32\vunpocgc.dll
C:\WINDOWS\system32\vwhkkncy.dll
C:\WINDOWS\system32\wvurrsq.dll
C:\WINDOWS\system32\wvuttrs.dll
C:\WINDOWS\system32\wvuvvus.dll
C:\Program Files\Drmupgds
C:\WINDOWS\Fonts\boundaoe.zip
C:\WINDOWS\Fonts\ennobled.zip
C:\WINDOWS\Fonts\howdy.zip
C:\WINDOWS\Fonts\ropemf.zip
C:\WINDOWS\gdxly.dat
C:\WINDOWS\llqwx.dat
C:\WINDOWS\n_dtgqye.dat
C:\WINDOWS\system32\aqpinpmr.dll
C:\WINDOWS\system32\cacpwecg.dll
C:\WINDOWS\system32\cqkjxmcd.ini
C:\WINDOWS\system32\ctpoixtm.ini
C:\WINDOWS\system32\dcmxjkqc.dll
C:\WINDOWS\system32\dguicfcy.dll
C:\WINDOWS\system32\gndswiyo.ini
C:\WINDOWS\system32\ialaqdmv.dll
C:\WINDOWS\system32\jcnbpgci.ini
C:\WINDOWS\system32\jvjbeagn.ini
C:\WINDOWS\system32\khfdayw.dll
C:\WINDOWS\system32\koxfdhpx.dll
C:\WINDOWS\system32\kucuquem.ini
C:\WINDOWS\system32\kxmpykkf.ini
C:\WINDOWS\system32\mniluttl.dll
C:\WINDOWS\system32\muruawvv.ini
C:\WINDOWS\system32\oojgompv.ini
C:\WINDOWS\system32\ptjbofvy.dll
C:\WINDOWS\system32\pyvufnqm.ini
C:\WINDOWS\system32\qomnlij.dll
C:\WINDOWS\system32\sjlbprot.dll
C:\WINDOWS\system32\vpmogjoo.dll
C:\WINDOWS\system32\vrdgmlra.dll
C:\WINDOWS\system32\vunpocgc.dll
C:\WINDOWS\system32\vwhkkncy.dll
C:\WINDOWS\system32\vyujnalf.ini
C:\WINDOWS\system32\wvurrsq.dll
C:\WINDOWS\system32\wvuttrs.dll
C:\WINDOWS\system32\wvuvvus.dll
C:\WINDOWS\system32\yvfobjtp.ini

.
((((((((((((((((((((((((( Files Created from 2008-01-18 to 2008-02-18 )))))))))))))))))))))))))))))))
.

2008-02-18 13:28 . 2008-02-18 13:28 d——– C:\Program Files\Sun
2008-02-18 13:28 . 2007-12-14 01:59 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-02-18 13:17 . 2008-02-18 13:17 d——– C:\Program Files\Common Files\Java
2008-02-18 09:37 . 2008-02-18 09:37 d——– C:\Program Files\CCleaner
2008-02-07 11:29 . 2008-02-07 11:29 d——– C:\Documents and Settings\end user\Application Data\MSN6
2008-02-07 11:29 . 2008-02-07 11:29 d——– C:\Documents and Settings\All Users\Application Data\MSN6

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-18 19:28 ——— d—–w C:\Program Files\Java
2008-02-18 19:16 ——— d—–w C:\Documents and Settings\end user\Application Data\Viewpoint
2008-02-18 19:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-18 19:15 ——— d—–w C:\Program Files\Viewpoint
2008-02-18 15:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-15 23:31 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-09 17:55 ——— d—–w C:\Program Files\McAfee
2008-02-04 15:57 ——— d—–w C:\Program Files\Oberon Media
2008-02-04 15:55 ——— d—–w C:\Program Files\Skype
2008-02-04 15:53 ——— d—–w C:\Program Files\Kazaa
2008-02-04 15:52 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-16 19:45 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-07 16:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-01-07 16:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-20 21:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\SpinTop Games
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2005-01-29 17:21 2,084,888 —-a-w C:\Program Files\reglite.exe
2004-01-27 19:23 3,149 —-a-w C:\Program Files\Common Files\remove_tools.html
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 17:30 517768]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-03-06 23:06 5181440]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= C:\Documents and Settings\end user\My Documents\two.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\10]
Source= C:\Documents and Settings\end user\My Documents\daisy.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\11]
Source= C:\Documents and Settings\end user\My Documents\baby.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
Source= C:\Documents and Settings\end user\My Documents\bd.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\3]
Source= C:\Documents and Settings\end user\My Documents\grpa.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\4]
Source= C:\Documents and Settings\end user\My Documents\job.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\5]
Source= C:\Documents and Settings\end user\My Documents\sue.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\6]
Source= C:\Documents and Settings\end user\My Documents\april.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\7]
Source= C:\Documents and Settings\end user\My Documents\august.html.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\8]
Source= C:\Documents and Settings\end user\My Documents\plaid.html
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\9]
Source= C:\Documents and Settings\end user\My Documents\lily.html
FriendlyName=

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digimax Viewer 2.0.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digimax Viewer 2.0.lnk
backup=C:\WINDOWS\pss\Digimax Viewer 2.0.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^end user^Start Menu^Programs^Startup^AbsoluteShield Internet Eraser.lnk]
path=C:\Documents and Settings\end user\Start Menu\Programs\Startup\AbsoluteShield Internet Eraser.lnk
backup=C:\WINDOWS\pss\AbsoluteShield Internet Eraser.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^end user^Start Menu^Programs^Startup^Autoup.lnk]
path=C:\Documents and Settings\end user\Start Menu\Programs\Startup\Autoup.lnk
backup=C:\WINDOWS\pss\Autoup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2006-04-12 10:30 53408 C:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey]
–a—— 2005-01-11 08:42 477184 C:\WINDOWS\mHotkey.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dit]
–a—— 2005-01-16 18:53 69632 C:\WINDOWS\Dit.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
–a—— 2007-07-25 15:02 563984 C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
–a—— 2007-07-25 15:06 2027792 C:\Program Files\Logitech\QuickCam\Quickcam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-01-19 12:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
–a—— 2007-03-06 23:06 5181440 C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2007-04-16 14:28 577536 C:\WINDOWS\soundman.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
–a—— 2007-07-30 11:40 125504 C:\WINDOWS\system32\jalbmnxd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2007-08-28 12:13 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2002-07-23 10:58 12288 C:\Program Files\Winamp3\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2006-11-30 21:49 4662776 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"KodakCCS"=2 (0x2)

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 15:38]
S2 DBSRVR;DBISAM Database Server - DBSRVR;C:\CCWIN\dbsrvr.exe []

.
Contents of the 'Scheduled Tasks' folder
"2008-02-16 02:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - end user.job"
- C:\PROGRA~1\NORTON~2\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-18 13:42:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

C:\WINDOWS\SchedLgU.Txt:pnhae 11534 bytes executable
C:\WINDOWS\wiaservc.log:cjwih 10105 bytes executable
C:\WINDOWS\wiaservc.log:coaiev 11534 bytes executable
C:\WINDOWS\wiaservc.log:kunzk 10752 bytes executable

scan completed successfully
hidden files: 4

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2008-02-18 13:45:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-18 19:45:39
ComboFix2.txt 2008-02-18 16:23:15
ComboFix3.txt 2007-08-03 14:39:08
.
2008-02-13 09:04:38 — E O F —



Malwarebytes:
Malwarebytes' Anti-Malware 1.03
Database version: 374

Scan type: Quick Scan
Objects scanned: 26144
Time elapsed: 6 minute(s), 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 15
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 34

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\malwarealarm.webinstall (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\malwarealarm.webinstall.1 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1a26f07f-0d60-4835-91cf-1e1766a0ec56} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1a26f07f-0d60-4835-91cf-1e1766a0ec56} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{7543fbd5-2279-4d03-8f29-eb21531fa2fe} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{edc4193f-34ad-4d07-aa87-e3fdb89e3e76} (Spyware.Comet.Cursor) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{4a3d609a-43b8-4406-b793-84f244246325} (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\webinst.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\kernelexe (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\dwsaiwqw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wqwiaswd.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\enhtviuo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ouivthne.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fxnitqix.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xiqtinxf.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gdaaclyt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tylcaadg.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ghxwqkpl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lpkqwxhg.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hqcvflxc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cxlfvcqh.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ifhbclqe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\eqlcbhfi.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jalbmnxd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dxnmblaj.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jkdcxvhm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mhvxcdkj.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\moekrbgk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kgbrkeom.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mwqfcxbi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ibxcfqwm.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rcnxhgju.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ujghxncr.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rxrdvieh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\heivdrxr.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tnwkwydo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\odywkwnt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vhwjnjwk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kwjnjwhv.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vnkrslgu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uglsrknv.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xebixkbl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lbkxibex.ini (Trojan.Vundo) -> Quarantined and deleted successfully.


HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:07:04 PM, on 2/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\end user\My Documents\olivia\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Web-Based Email Tools - http://email.secureserver.net/Download.CAB
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {75565ED2-1560-4F15-B841-20358DE6A0D1} (ImageControl Class) - http://c.ancestry.com/cab/ImageViewer/MFImgVwr.cab
O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - http://clubgames.pogo.com/online2/pogop/ma…mesLauncher.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - http://a248.e.akamai.net/f/248/5462/2h/www…ol/SymDlBrg.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin.cab
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DBISAM Database Server - DBSRVR (DBSRVR) - Unknown owner - C:\CCWIN\dbsrvr.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O24 - Desktop Component 1: (no name) - C:\Documents and Settings\end user\My Documents\two.html
O24 - Desktop Component 10: (no name) - C:\Documents and Settings\end user\My Documents\daisy.html
O24 - Desktop Component 11: (no name) - C:\Documents and Settings\end user\My Documents\baby.html
O24 - Desktop Component 2: (no name) - C:\Documents and Settings\end user\My Documents\bd.html
O24 - Desktop Component 3: (no name) - C:\Documents and Settings\end user\My Documents\grpa.html
O24 - Desktop Component 4: (no name) - C:\Documents and Settings\end user\My Documents\job.html
O24 - Desktop Component 5: (no name) - C:\Documents and Settings\end user\My Documents\sue.html
O24 - Desktop Component 6: (no name) - C:\Documents and Settings\end user\My Documents\april.html
O24 - Desktop Component 7: (no name) - C:\Documents and Settings\end user\My Documents\august.html.html
O24 - Desktop Component 8: (no name) - C:\Documents and Settings\end user\My Documents\plaid.html
O24 - Desktop Component 9: (no name) - C:\Documents and Settings\end user\My Documents\lily.html

–
End of file - 8979 bytes
:thumbup: :woot: It is running sooo much better now! Thank you so much for taking time to help me. I have one more computer that is messed up-do I need to post a new subject for that one? Again, thank you very much.

:thumbup: :woot: It is running sooo much better now! Thank you so much for taking time to help me. I have one more computer that is messed up-do I need to post a new subject for that one? Again, thank you very much.

You can post a HijackThis log for that computer in this thread.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:49:24 PM, on 2/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Canon\DIAS\CnxDIAS.exe
C:\WINDOWS\VVNFUg\command.exe
C:\Program Files\Cobian Backup 8\cbService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Cobian Backup 8\cbInterface.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\ICROSO~1.NET\javaw.exe
C:\Program Files\Common Files\?racle\r?ndll32.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Documents and Settings\USER\Application Data\Microsoft\Windows\cofcevl.exe
C:\PROGRA~1\COMMON~1\wwmr\wwmrm.exe
C:\AutoUp\Autoup.exe
C:\Program Files\RABCO\X_RABCOse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\USER\Application Data\WinTouch\WinTouch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\CCWIN\dbsrvr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\xInsIDE\xInsIDE.exe
C:\WINDOWS\system32\service.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cobian Backup 8 interface] "C:\Program Files\Cobian Backup 8\cbInterface.exe" -service
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu572.exe 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C88332017491394661A64DB7
C8F0287E55E246220D9E728F9FC17D446BC57D5375FB0FB68AD6
O4 - HKLM\..\Run: [vipoduvel] C:\Program Files\Outlook Express\vipoduvel77798.exe
O4 - HKLM\..\Run: [MDNS] C:\WINDOWS\system32\service.exe
O4 - HKLM\..\Run: [34bc3beb] rundll32.exe "C:\WINDOWS\system32\uynqdtiq.dll",b
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [Aida] "C:\WINDOWS\ICROSO~1.NET\javaw.exe" -vt yazb
O4 - HKCU\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.8.8\webbuying.exe
O4 - HKCU\..\Run: [Iapnq] "C:\Program Files\Common Files\?racle\r?ndll32.exe"
O4 - HKCU\..\Run: [Drmupgds] C:\Program Files\Drmupgds\Drmupgds.exe
O4 - HKCU\..\Run: [xInsIDE] C:\Program Files\xInsIDE\xInsIDE.exe
O4 - HKCU\..\Run: [Router] C:\Program Files\Router\Router.exe
O4 - HKCU\..\Run: [WinTouch] C:\Documents and Settings\USER\Application Data\WinTouch\WinTouch.exe
O4 - HKCU\..\Run: [SfKg6w] C:\Documents and Settings\USER\Application Data\Microsoft\Windows\cofcevl.exe
O4 - HKCU\..\Run: [wwmr] C:\PROGRA~1\COMMON~1\wwmr\wwmrm.exe
O4 - Startup: Autoup.lnk = C:\AutoUp\Autoup.exe
O4 - Startup: RABCO - Auto Update.lnk = C:\Program Files\RABCO\RABCOse.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.onerateld.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{97C8D1F9-3003-4BDF-A36F-7860B6780F75}: NameServer = 192.168.1.1
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Canon Driver Information Assist Service - CANON INC. - C:\Program Files\Canon\DIAS\CnxDIAS.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\VVNFUg\command.exe
O23 - Service: Cobian Backup 8 service (CobBMService) - Luis Cobian - C:\Program Files\Cobian Backup 8\cbService.exe
O23 - Service: DBISAM Database Server - DBSRVR (DBSRVR) - Elevate Software - C:\CCWIN\dbsrvr.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\microsoft frontpage\dicovus.html

–
End of file - 5758 bytes
Hi :)

Yes, that's quite the malware collection you've got there! Instructions will be rather similar ;)

Please download and install CCleaner.

Open CCleaner. On the Windows tab, leave the default options alone.

  • On the Applications tab, check (tick) all the boxes except Saved Form Information. This will remove all your saved passwords if you leave this box checked.
  • Click on the Run Cleaner button at the bottom right hand corner.
  • When the cleaner has completed, click Tools in the Left Pane.
  • Verify that Uninstall is highlighted in color, or click on it.
  • In the lower right, click Save to Text File.
  • Pull down the arrow at the top of the Save dialog and choose Desktop as the location.
  • You can leave the filename as install.txt.
  • Click Save, then exit Ccleaner.
________________________________

Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Post the log from ComboFix (C:\Combofix.txt) when you've accomplished that, along with a new HijackThis log and the CCleaner Uninstall List (install.txt).
Combofix:

ComboFix 08-02-18.1 - USER 2008-02-18 16:14:02.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.247 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\check_LSA7.txt
C:\Documents and Settings\USER\Application Data\WinTouch\WinTouch.exe
C:\Program Files\Common Files\wwmr\wwmrm.lck
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\seriall.sys
C:\WINDOWS\system32\jkkli.dll
C:\WINDOWS\system32\qommkhh.dll
C:\WINDOWS\system32\zpkbiebi.dll
C:\check_LSA7.txt
C:\Documents and Settings\LocalService\Application Data\Install.dat
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\NetworkService\Application Data\install.dat
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt
C:\Documents and Settings\NetworkService\Application Data\WinTouch
C:\Documents and Settings\NetworkService\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\USER\Application Data\install.dat
C:\Documents and Settings\USER\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\USER\Application Data\WinTouch\WinTouch.exe
C:\Documents and Settings\USER\Application Data\WinTouch\WTUninstaller.exe
C:\Documents and Settings\USER\err.log
C:\Documents and Settings\USER\spooldr.ini
C:\Documents and Settings\USER\Start Menu\Programs\Outerinfo
C:\Documents and Settings\USER\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\USER\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Program Files\Common Files\racle~1
C:\Program Files\Common Files\racle~1\r?ndll32.exe
C:\Program Files\Common Files\wwmr\wwmra.exe
C:\Program Files\Common Files\wwmr\wwmra.lck
C:\Program Files\Common Files\wwmr\wwmrd\class-barrel
C:\Program Files\Common Files\wwmr\wwmrd\vocabulary
C:\Program Files\Common Files\wwmr\wwmrd\wwmrc.dll
C:\Program Files\Common Files\wwmr\wwmrh
C:\Program Files\Common Files\wwmr\wwmrl.exe
C:\Program Files\Common Files\wwmr\wwmrl.lck
C:\Program Files\Common Files\wwmr\wwmrm.exe
C:\Program Files\Common Files\wwmr\wwmrm.lck
C:\Program Files\Common Files\wwmr\wwmrp.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\inetget2
C:\Program Files\microsoft frontpage\dicovus.html
C:\Program Files\microsoft frontpage\zysihyz.dll
C:\Program Files\microsoft frontpage\zysihyz196.dll
C:\Program Files\network monitor
C:\Program Files\network monitor\netmon.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\Router
C:\Program Files\Router\Router.exe
C:\Program Files\Router\UnInstall.exe
C:\Program Files\Temporary
C:\Program Files\Temporary\InsiDERInst.exe
C:\temp\0c2
C:\temp\0c2\tmpFF.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\Temp\isgTi19
C:\Temp\isgTi19\lPig.log
C:\temp\tn3
C:\WINDOWS\b103.exe
C:\WINDOWS\b104.exe
C:\WINDOWS\b111.exe
C:\WINDOWS\b116.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\b138.exe
C:\WINDOWS\b151.exe
C:\WINDOWS\b153.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\UGA6P_0001_N122M0611NetInstaller.exe
C:\WINDOWS\Free Online Dating.ico
C:\WINDOWS\icroso~1.net
C:\WINDOWS\icroso~1.net\?icrosoft.NET\
C:\WINDOWS\icroso~1.net\javaw.exe
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\system32\ac1
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\brtgfsfd.dll
C:\WINDOWS\SYSTEM32\bydcslrt.ini
C:\WINDOWS\system32\cbxvwts.dll
C:\WINDOWS\SYSTEM32\cghcucwo.ini
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\seriall.sys
C:\WINDOWS\system32\efbl.dll
C:\WINDOWS\system32\fanceiaj.dll
C:\WINDOWS\SYSTEM32\fhwvecss.ini
C:\WINDOWS\system32\fssqqrd.dll
C:\WINDOWS\system32\galpaaog.dll
C:\WINDOWS\system32\gebbxyw.dll
C:\WINDOWS\system32\hxsvjiub.dll
C:\WINDOWS\SYSTEM32\ilkkj.bak1
C:\WINDOWS\SYSTEM32\ilkkj.bak2
C:\WINDOWS\SYSTEM32\ilkkj.ini
C:\WINDOWS\system32\jkkli.dll
C:\WINDOWS\system32\jyddpjvt.dll
C:\WINDOWS\system32\kaweyisy.dll
C:\WINDOWS\system32\kdkhmqjw.dll
C:\WINDOWS\system32\kr_done1
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\SYSTEM32\mhojvswv.ini
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\nGpxx01\nGpxx011065.exe
C:\WINDOWS\system32\opnnoon.dll
C:\WINDOWS\system32\otnnnjsb.dll
C:\WINDOWS\system32\oujwihsu.dll
C:\WINDOWS\system32\owcuchgc.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\SYSTEM32\qitdqnyu.ini
C:\WINDOWS\system32\qommkhh.dll
C:\WINDOWS\system32\service.exe
C:\WINDOWS\system32\sviaqwny.dll
C:\WINDOWS\SYSTEM32\tmkncudu.ini
C:\WINDOWS\system32\uynqdtiq.dll
C:\WINDOWS\SYSTEM32\vjauxehp.ini
C:\WINDOWS\system32\windows
C:\WINDOWS\SYSTEM32\xkwhmphc.ini
C:\WINDOWS\system32\zpkbiebi.dll
C:\WINDOWS\system32\zpkbiebi.dllbox
C:\WINDOWS\tk58.exe
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\VVNFUg\
C:\WINDOWS\VVNFUg\\asappsrv.dll
C:\WINDOWS\VVNFUg\\command.exe
C:\WINDOWS\VVNFUg\\pphIo0.vbs
C:\WINDOWS\VVNFUg\command.exe
C:\WINDOWS\wwmr
C:\WINDOWS\wwmr\wu
C:\WINDOWS\wwmr\wwmr.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\LEGACY_SERIALL
——-\cmdService
——-\Network Monitor
——-\seriall


((((((((((((((((((((((((( Files Created from 2008-01-18 to 2008-02-18 )))))))))))))))))))))))))))))))
.

2008-02-18 15:35 . 2008-02-18 15:35 d——– C:\Program Files\CCleaner
2008-02-15 09:05 . 2008-02-15 09:05 14,103 –a—— C:\IDLTEMP.JPG
2008-02-13 16:39 . 2007-11-02 19:04 385,024 –a—— C:\WINDOWS\SYSTEM32\WinNB57.dll
2008-02-13 15:24 . 2008-02-16 10:51 d——– C:\Program Files\xInsIDE
2008-02-09 09:18 . 2008-02-09 09:18 1,624 –a—— C:\WINDOWS\SYSTEM32\tmp.reg
2008-02-09 09:17 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\SYSTEM32\VCCLSID.exe
2008-02-09 09:17 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\SYSTEM32\SrchSTS.exe
2008-02-09 09:17 . 2008-02-08 23:55 85,504 –a—— C:\WINDOWS\SYSTEM32\VACFix.exe
2008-02-09 09:17 . 2008-02-08 10:37 82,432 –a—— C:\WINDOWS\SYSTEM32\IEDFix.exe
2008-02-09 09:17 . 2003-06-05 20:13 53,248 –a—— C:\WINDOWS\SYSTEM32\Process.exe
2008-02-09 09:17 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\SYSTEM32\dumphive.exe
2008-02-09 09:17 . 2007-10-03 23:36 25,600 –a—— C:\WINDOWS\SYSTEM32\WS2Fix.exe
2008-02-09 09:12 . 2004-06-22 10:06 d——– C:\Documents and Settings\Administrator\Application Data\Symantec
2008-02-09 09:12 . 2004-06-22 10:05 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-02-08 14:55 . 2008-02-08 14:57 d——– C:\Program Files\RABCO
2008-02-08 14:55 . 2008-02-08 14:55 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-02-08 14:54 . 2008-02-08 14:54 d——– C:\WINDOWS\SYSTEM32\za7
2008-02-08 14:54 . 2008-02-08 14:54 d——– C:\WINDOWS\SYSTEM32\wd11
2008-02-08 14:54 . 2008-02-08 15:18 d——– C:\WINDOWS\SYSTEM32\mv3
2008-02-08 14:54 . 2008-02-08 14:54 d——– C:\WINDOWS\SYSTEM32\kp9
2008-02-08 14:54 . 2008-02-08 14:54 d——– C:\WINDOWS\SYSTEM32\bk5
2008-01-20 21:31 . 2008-01-20 21:31 d——– C:\Program Files\Cobian Backup 8

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-18 22:24 ——— d—–w C:\Program Files\microsoft frontpage
2008-02-18 21:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-13 21:40 10 —-a-w C:\Program Files\.autoreg
2008-02-09 00:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-08 20:54 ——— d—–w C:\Program Files\WordPerfect Office 11
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-11-14 15:50 46,752 —-a-w C:\Documents and Settings\USER\Application Data\GDIPFONTCACHEV1.DAT
2004-09-09 20:42 561,152 —-a-w C:\Documents and Settings\USER\chatlnk.exe
2004-08-04 07:56 47,140 –sha-r C:\WINDOWS\SYSTEM32\cmdsvlic.exe
2007-08-03 20:31 6,507 –sha-w C:\WINDOWS\SYSTEM32\uvvwa.bak1
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0CB79274-27F5-426D-842B-5057076E3D25}]
2008-02-07 19:07 217088 –a—— C:\Program Files\WordPerfect Office 11\qucejus89104.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ABC5E790-1CAF-4DD2-588E-27922885F101}]
2008-02-18 16:44 70144 –a—— C:\Program Files\microsoft frontpage\zysihyz.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-11 18:16 4670968]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 10:37 2321600]
"Iapnq"="C:\Program Files\Common Files\?racle\r?ndll32.exe" [ ]
"Drmupgds"="C:\Program Files\Drmupgds\Drmupgds.exe" [ ]
"xInsIDE"="C:\Program Files\xInsIDE\xInsIDE.exe" [2008-02-13 15:24 57344]
"Router"="C:\Program Files\Router\Router.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-06-22 10:02 77824]
"Cobian Backup 8 interface"="C:\Program Files\Cobian Backup 8\cbInterface.exe" [2007-09-27 12:37 2425856]
"vipoduvel"="C:\Program Files\Outlook Express\vipoduvel77798.exe" [2007-08-07 14:30 163840]

C:\Documents and Settings\USER\Start Menu\Programs\Startup\
Autoup.lnk - C:\AutoUp\Autoup.exe [2003-09-19 17:33:42 2200576]
RABCO - Auto Update.lnk - C:\Program Files\RABCO\RABCOse.exe [2008-02-08 14:54:53 183216]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]

R2 DBSRVR;DBISAM Database Server - DBSRVR;C:\CCWIN\dbsrvr.exe [2003-11-20 12:45]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-18 16:44:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

C:\WINDOWS\tk58.exe 135168 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\RABCO\X_RABCOse.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Canon\DIAS\CnxDIAS.exe
C:\Program Files\Cobian Backup 8\cbService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2008-02-18 16:47:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-18 22:47:05
.
2008-02-13 09:03:16 — E O F —



Uninstall list:

Ad-Aware 2007
Adobe Flash Player ActiveX
Adobe Reader 8.1.0
Adobe® Photoshop® Album Starter Edition 3.2
Banctec Service Agreement
Belarc Advisor 7.2
Broadcom Management Programs
BroadJump Client Foundation
CCleaner (remove only)
Cobian Backup 8
Command
Dell Digital Jukebox Driver
Dell Media Experience
Dell Networking Guide
Dell Solution Center
Dell Support
Drmupgds
EarthLink Setup Files
getPlus®_ocx
Help and Support Customization
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 2.0.2
Hotfix for Windows XP (KB896344)
Ideal Check Cashing Release 5.3.2.0 HF4
Intel® Extreme Graphics Driver
Internet Explorer Default Page
IrfanView (remove only)
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
Learn2 Player (Uninstall Only)
Mag-Tek MICRImage Demo
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Data Access Components KB870669
Microsoft Encarta Encyclopedia Standard 2004
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft Office XP Professional with FrontPage
Microsoft Word Viewer 97
Move Networks Player for Internet Explorer
Mozilla Firefox (2.0.0.5)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MUSICMATCH® Jukebox
Network Monitor
Outerinfo
QuickTime
RABCO
RealPlayer Basic
Router
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB946026)
Shockwave
Spybot - Search & Destroy 1.4
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB900930)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Viewpoint Media Player
VNC Free Edition 4.1.2
WebEx
WebFldrs XP
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Media Connect
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB887797
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinTouch
WordPerfect Office 11
xInsIDE
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger



HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:57:33 PM, on 2/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cobian Backup 8\cbInterface.exe
C:\Program Files\Outlook Express\vipoduvel77798.exe
C:\Program Files\xInsIDE\xInsIDE.exe
C:\AutoUp\Autoup.exe
C:\Program Files\RABCO\X_RABCOse.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Canon\DIAS\CnxDIAS.exe
C:\Program Files\Cobian Backup 8\cbService.exe
C:\CCWIN\dbsrvr.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0CB79274-27F5-426D-842B-5057076E3D25} - C:\Program Files\WordPerfect Office 11\qucejus89104.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: 0 - {ABC5E790-1CAF-4DD2-588E-27922885F101} - C:\Program Files\microsoft frontpage\zysihyz.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cobian Backup 8 interface] "C:\Program Files\Cobian Backup 8\cbInterface.exe" -service
O4 - HKLM\..\Run: [vipoduvel] C:\Program Files\Outlook Express\vipoduvel77798.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [Iapnq] "C:\Program Files\Common Files\?racle\r?ndll32.exe"
O4 - HKCU\..\Run: [Drmupgds] C:\Program Files\Drmupgds\Drmupgds.exe
O4 - HKCU\..\Run: [xInsIDE] C:\Program Files\xInsIDE\xInsIDE.exe
O4 - HKCU\..\Run: [Router] C:\Program Files\Router\Router.exe
O4 - Startup: Autoup.lnk = C:\AutoUp\Autoup.exe
O4 - Startup: RABCO - Auto Update.lnk = C:\Program Files\RABCO\RABCOse.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.onerateld.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{97C8D1F9-3003-4BDF-A36F-7860B6780F75}: NameServer = 192.168.1.1
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Canon Driver Information Assist Service - CANON INC. - C:\Program Files\Canon\DIAS\CnxDIAS.exe
O23 - Service: Cobian Backup 8 service (CobBMService) - Luis Cobian - C:\Program Files\Cobian Backup 8\cbService.exe
O23 - Service: DBISAM Database Server - DBSRVR (DBSRVR) - Elevate Software - C:\CCWIN\dbsrvr.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

–
End of file - 4486 bytes
Hi :)

Step 1

Click on Start, then Control Panel. Double click on Add or Remove Programs.

Please remove the following program(s):

Java 2 Runtime Environment, SE v1.4.2
Outerinfo
RABCO
Router
Viewpoint Media Player
<– Only remove this program if you haven't installed it yourself.
WinTouch

Then download and install Java Runtime Environment (JRE) 6 Update 4.

Step 2

Open Notepad (Go to Start > Run, type Notepad and hit Enter), and copy/paste the text in the quotebox below into it:

File::

C:\WINDOWS\SYSTEM32\cmdsvlic.exe
C:\WINDOWS\SYSTEM32\uvvwa.bak1
C:\Program Files\WordPerfect Office 11\qucejus89104.dll
C:\Program Files\microsoft frontpage\zysihyz.dll
C:\Program Files\Outlook Express\vipoduvel77798.exe

Folder::

C:\Program Files\RABCO
C:\WINDOWS\SYSTEM32\za7
C:\WINDOWS\SYSTEM32\wd11
C:\WINDOWS\SYSTEM32\mv3
C:\WINDOWS\SYSTEM32\kp9
C:\WINDOWS\SYSTEM32\bk5

Registry::

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0CB79274-27F5-426D-842B-5057076E3D25}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ABC5E790-1CAF-4DD2-588E-27922885F101}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Iapnq"=-
"Drmupgds"=-
"Router"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vipoduvel"=-

Rootkit::

C:\WINDOWS\tk58.exe

Click on File > Save as….

In the File Name box, copy/paste CFScript.txt (Note: Do not change the filename!)

Click Save (Save the CFScript in the same location as Combofix.exe)

Close any open windows.

Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix.

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe.
It will create a log. Be sure to save it to a convenient location.

Step 3

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • You can also access the log by doing the following:

  • Click on the Malwarebytes' Anti-Malware icon to launch the program.
  • Click on the Logs tab.
  • Click on the log at the bottom of those listed to highlight it.
  • Click Open.

Step 4

In your next reply, please post:

  • the Combofix log (C:\Combofix.txt)
  • the Malwarebytes' Anti-Malware log
  • a new HijackThis log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI