This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] URL.ADTRGT Making compute unusable

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The barrage of Pop-ups mostly going to URL.ADTRGT is making our computer almost unusable. We're running Trend Micro internet security 14 and blocking most sites, so they don't connect. I haven't found any fixes that will clean this. PLEASE HELP! Here is my HiJack This log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:01:44 AM, on 2/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\DOCUME~1\Rick\LOCALS~1\Temp\clclean.0001
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/sp?r=al&cf=sp&…amp;O=I&UT=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 64.136.29.30;64.136.21.30;64.136.29.34;searchap.untd.com;127.0.0.1;localhost;*mi
crosoft.com;*windowsupdate.com;*wustat.windows.com;*.pogo.com;*.worldwinner.com;*
test-speed.com;liveupdate.symantecliveupdate.com;*symantec.com;*.nai.com;*.networkass
ociates.com;*photosite.com;*.dir.untd.com;*.prod.untd.com;
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: Nick - {A30B8EF5-82CA-4789-B77F-9C1C20DF53CB} - C:\Documents and Settings\Andrew\Application Data\LaunchPad Toolbar\launchpadtoolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [c4f0c336] rundll32.exe "C:\WINDOWS\system32\cmckkusj.dll",b
O4 - HKLM\..\Run: [BMc7c3f0aa] Rundll32.exe "C:\WINDOWS\system32\jcdhljrh.dll",s
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Simple Star PhotoShow Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.21\ShoppingReport.dll (file missing)
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.21\ShoppingReport.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://wildcat.speedlinetech.com/iNotes6W.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolor.com/ClarkActivia.cab
O16 - DPF: {47CEF84E-92D8-4C4A-86D7-CB982889DCC0} (Oberon Media Network Optimizer) - http://mp1.mplay.oberon-media.com/client/flashnet.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.24.18/ttinst.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem…GameManager.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

–
End of file - 12885 bytes
Hello RickG3 and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.


Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • ComboFix will automatically start. Any monitoring programs will be shut down like your antivirus, antispyware programs for example.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Trevuren,
Thanks for looking at my problem here is the Combofix log. HJT log is at bottom.

ComboFix 08-02-16.2 - Rick 2008-02-16 10:33:10.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1298 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\pmnno.dll
C:\Documents and Settings\Andrew\err.log
C:\Documents and Settings\Andrew\ResErrors.log
C:\Documents and Settings\Ann Marie\Application Data\HbTools_Icons
C:\Documents and Settings\Ann Marie\Application Data\HbTools_Icons\Registryrepair.ico
C:\Documents and Settings\Ann Marie\Application Data\HbTools_Icons\Software_Online_8.ico
C:\Documents and Settings\Ann Marie\Desktop\Free PC Wallpapers.lnk
C:\Documents and Settings\Ann Marie\err.log
C:\Documents and Settings\Ann Marie\ResErrors.log
C:\Documents and Settings\Rick\err.log
C:\Documents and Settings\Rick\ResErrors.log
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ahckbnbj.dll
C:\WINDOWS\system32\aorsyrfo.dll
C:\WINDOWS\system32\bnhglbbk.dll
C:\WINDOWS\system32\cmckkusj.dll
C:\WINDOWS\system32\cmlkistb.dll
C:\WINDOWS\system32\dihbygyn.dll
C:\WINDOWS\system32\dthdeohg.dll
C:\WINDOWS\system32\dvrlknel.ini
C:\WINDOWS\system32\fjufxttd.dll
C:\WINDOWS\system32\fkgcktgk.dll
C:\WINDOWS\system32\fmrpjjex.dll
C:\WINDOWS\system32\gifldxhr.dll
C:\WINDOWS\system32\hxnfbgxm.dll
C:\WINDOWS\system32\iwcrdaxj.dll
C:\WINDOWS\system32\ixiehtdv.ini
C:\WINDOWS\system32\jcdhljrh.dll
C:\WINDOWS\system32\jsiebnsw.dll
C:\WINDOWS\system32\jsjqcowd.dll
C:\WINDOWS\system32\jsukkcmc.ini
C:\WINDOWS\system32\kvvxxola.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mptfbvnr.dll
C:\WINDOWS\system32\msuldfnk.dll
C:\WINDOWS\system32\nlamlhxb.dll
C:\WINDOWS\system32\ojweevab.ini
C:\WINDOWS\system32\onnmp.ini
C:\WINDOWS\system32\onnmp.ini2
C:\WINDOWS\system32\pfouryss.dll
C:\WINDOWS\system32\phtlssvc.dll
C:\WINDOWS\system32\pmnno.dll
C:\WINDOWS\system32\poiqfubf.dll
C:\WINDOWS\system32\qypwhkvy.dll
C:\WINDOWS\system32\rkeefrlt.ini
C:\WINDOWS\system32\sjhrvwnq.dll
C:\WINDOWS\system32\snrcsofy.dll
C:\WINDOWS\system32\ssucqotg.ini
C:\WINDOWS\system32\sxfmlgpc.dll
C:\WINDOWS\system32\sygfsbqi.dll
C:\WINDOWS\system32\tbtjtibn.dll
C:\WINDOWS\system32\uuciicsl.dll
C:\WINDOWS\system32\uvjesoly.dll
C:\WINDOWS\system32\uvqtiosd.dll
C:\WINDOWS\system32\uwkpxldo.dll
C:\WINDOWS\system32\whextphx.dll
C:\WINDOWS\system32\wlcllxcc.dll
C:\WINDOWS\system32\wphmwdum.dll
C:\WINDOWS\system32\wswenlea.dll
C:\WINDOWS\system32\xefybmjp.dll
C:\WINDOWS\system32\xutqvahx.ini
C:\WINDOWS\system32\xxjxtiqv.dll
C:\WINDOWS\system32\ydnrilqt.dll
C:\WINDOWS\system32\yhbftaui.dll
C:\WINDOWS\system32\ypiuvfuv.dll
C:\WINDOWS\system32\yqoynlef.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE


((((((((((((((((((((((((( Files Created from 2008-01-16 to 2008-02-16 )))))))))))))))))))))))))))))))
.

2008-02-16 10:27 . 2004-08-10 05:00 388,608 –a—— C:\kmd.exe
2008-02-16 09:44 . 2008-02-16 09:44 5,187 –a—— C:\WINDOWS\system32\uymufxxj.dll
2008-02-16 09:44 . 2008-02-16 09:44 5,180 –a—— C:\WINDOWS\system32\etvokxvb.dll
2008-02-14 12:59 . 2008-02-14 12:59 5,187 –a—— C:\WINDOWS\system32\dqumhnng.dll
2008-02-14 12:57 . 2008-02-14 12:57 5,191 –a—— C:\WINDOWS\system32\klaqepek.dll
2008-02-13 09:23 . 2008-02-13 09:23 5,191 –a—— C:\WINDOWS\system32\sloltldh.dll
2008-02-13 09:23 . 2008-02-13 09:23 5,187 –a—— C:\WINDOWS\system32\pamgwicb.dll
2008-02-12 17:12 . 2008-02-12 17:12 5,198 –a—— C:\WINDOWS\system32\dbtmetgi.dll
2008-02-12 17:11 . 2008-02-12 17:11 5,202 –a—— C:\WINDOWS\system32\gcogoxxv.dll
2008-02-11 11:08 . 2008-02-11 11:08 5,198 –a—— C:\WINDOWS\system32\yguylrsa.dll
2008-02-11 11:01 . 2008-02-11 11:01 5,202 –a—— C:\WINDOWS\system32\igbaevdj.dll
2008-02-10 10:34 . 2008-02-10 10:34 5,198 –a—— C:\WINDOWS\system32\ntvanncp.dll
2008-02-10 10:31 . 2008-02-10 10:31 5,202 –a—— C:\WINDOWS\system32\oelqqasr.dll
2008-02-09 08:04 . 2008-02-09 08:04 d——– C:\Documents and Settings\Rick\Application Data\MSNInstaller
2008-02-09 08:04 . 2008-02-09 08:04 d——– C:\DOCUME~1\Rick\APPLIC~1\MSNInstaller
2008-02-09 08:04 . 2008-02-09 08:04 d——– C:\DOCUME~1\Rick\APPLIC~1\MSNInstaller
2008-02-09 07:59 . 2008-02-09 07:59 5,198 –a—— C:\WINDOWS\system32\gnhglaef.dll
2008-02-09 07:58 . 2008-02-09 07:58 5,202 –a—— C:\WINDOWS\system32\qtpfpptk.dll
2008-02-08 06:58 . 2008-02-08 06:58 5,202 –a—— C:\WINDOWS\system32\kuaamrtg.dll
2008-02-07 07:50 . 2008-02-07 07:50 5,202 –a—— C:\WINDOWS\system32\pmfanxfk.dll
2008-02-07 07:50 . 2008-02-07 07:50 5,198 –a—— C:\WINDOWS\system32\gidmhvje.dll
2008-02-04 08:11 . 2008-02-04 08:11 5,198 –a—— C:\WINDOWS\system32\ntlnmxnn.dll
2008-02-04 08:07 . 2008-02-04 08:07 5,202 –a—— C:\WINDOWS\system32\rskhixrc.dll
2008-02-02 11:39 . 2008-02-02 11:39 d—-c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\SupportSoft
2008-02-02 11:38 . 2008-02-02 11:38 d——– C:\Program Files\Dell Support Center
2008-02-02 11:38 . 2008-02-02 11:38 d——– C:\Program Files\Common Files\supportsoft
2008-02-02 11:28 . 2008-02-02 11:28 5,198 –a—— C:\WINDOWS\system32\lyhpgbgk.dll
2008-02-02 11:23 . 2008-02-02 11:23 5,202 –a—— C:\WINDOWS\system32\usbbpvce.dll
2008-01-31 18:59 . 2008-01-31 18:59 5,198 –a—— C:\WINDOWS\system32\jwjfwmax.dll
2008-01-31 18:57 . 2008-01-31 18:57 5,202 –a—— C:\WINDOWS\system32\uvkepaum.dll
2008-01-30 14:49 . 2008-01-30 14:49 5,198 –a—— C:\WINDOWS\system32\cjixnior.dll
2008-01-29 14:11 . 2008-01-29 14:11 5,184 –a—— C:\WINDOWS\system32\hkpemiks.dll
2008-01-28 08:37 . 2008-02-02 11:36 d—-c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\Dell
2008-01-28 08:08 . 2008-01-28 08:12 d——– C:\Documents and Settings\Rick\Application Data\Intuit
2008-01-28 08:08 . 2008-01-28 08:12 d——– C:\DOCUME~1\Rick\APPLIC~1\Intuit
2008-01-28 08:08 . 2008-01-28 08:12 d——– C:\DOCUME~1\Rick\APPLIC~1\Intuit
2008-01-28 07:55 . 2008-01-28 07:55 5,184 –a—— C:\WINDOWS\system32\fwqydcop.dll
2008-01-27 11:20 . 2008-01-27 11:20 5,184 –a—— C:\WINDOWS\system32\ldpwtivx.dll
2008-01-26 09:50 . 2008-01-26 09:50 5,184 –a—— C:\WINDOWS\system32\tgsyawxd.dll
2008-01-25 08:04 . 2008-01-25 08:04 5,184 –a—— C:\WINDOWS\system32\ikwaqfmh.dll
2008-01-24 07:06 . 2008-01-24 07:06 5,184 –a—— C:\WINDOWS\system32\vdicrexc.dll
2008-01-23 07:07 . 2008-01-23 07:07 5,184 –a—— C:\WINDOWS\system32\fdfygmru.dll
2008-01-21 07:48 . 2008-01-21 07:48 5,184 –a—— C:\WINDOWS\system32\vrfuxfca.dll
2008-01-19 13:02 . 2008-01-19 13:02 d——– C:\Program Files\iPod
2008-01-19 12:42 . 2008-02-16 09:42 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-19 12:42 . 2008-01-19 12:42 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-19 11:53 . 2008-01-19 12:01 d——– C:\WINDOWS\system32\ActiveScan
2008-01-19 11:53 . 2008-01-19 11:53 30,590 –a—— C:\WINDOWS\system32\pavas.ico
2008-01-19 11:53 . 2008-01-19 11:53 2,550 –a—— C:\WINDOWS\system32\Uninstall.ico
2008-01-19 11:53 . 2008-01-19 11:53 1,406 –a—— C:\WINDOWS\system32\Help.ico
2008-01-19 09:04 . 2008-01-19 09:04 5,184 –a—— C:\WINDOWS\system32\abwpccdn.dll
2008-01-19 09:01 . 2008-02-16 09:43 6,112 –a—— C:\WINDOWS\BMc7c3f0aa.xml
2008-01-19 09:01 . 2008-02-16 09:42 22 –a—— C:\WINDOWS\pskt.ini
2008-01-18 07:45 . 2008-01-18 07:45 5,184 –a—— C:\WINDOWS\system32\vkbqakbg.dll
2008-01-18 07:42 . 2008-01-18 07:42 5,165 –a—— C:\WINDOWS\system32\welmnvou.dll
2008-01-16 19:31 . 2008-01-16 19:31 5,184 –a—— C:\WINDOWS\system32\iohqhhsa.dll
2008-01-16 19:28 . 2008-01-16 19:28 5,165 –a—— C:\WINDOWS\system32\hbunfthh.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-16 14:49 ——— d—–w C:\Documents and Settings\Rick\Application Data\Skype
2008-02-16 14:49 ——— d—–w C:\DOCUME~1\Rick\APPLIC~1\Skype
2008-02-16 14:49 ——— d—–w C:\DOCUME~1\Rick\APPLIC~1\Skype
2008-02-15 16:36 ——— d—–w C:\Program Files\SpongeBob SquarePants Diner Dash
2008-02-15 16:28 ——— d—–w C:\Program Files\Fairly Odd Parents Information Stupor Highway
2008-02-15 14:01 ——— d—–w C:\Program Files\Trend Micro
2008-02-14 22:30 ——— d—–w C:\Program Files\Diegos Rescue Adventure
2008-02-11 16:13 ——— d—–w C:\Documents and Settings\Andrew\Application Data\Intuit
2008-01-28 13:06 ——— d—–w C:\Program Files\Common Files\AnswerWorks 4.0
2008-01-28 13:05 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-28 12:49 ——— d—–w C:\Program Files\TurboTax
2008-01-19 18:03 ——— d—–w C:\Program Files\iTunes
2008-01-19 18:00 ——— d—–w C:\Program Files\QuickTime
2008-01-17 22:33 ——— dc–a-w C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-12-28 20:29 ——— d—–w C:\Documents and Settings\Ann Marie\Application Data\Skype
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-18 00:56 ——— d—–w C:\Program Files\MalwareAlarm
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{100EB1FD-D03E-47FD-81F3-EE91287F9465}]
C:\Program Files\ShoppingReport\Bin\2.0.21\ShoppingReport.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetDefaultMIDI"="MIDIDef.exe" [2004-12-22 17:40 24576 C:\WINDOWS\MIDIDEF.EXE]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23 102400]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-23 11:55 68856]
"Simple Star PhotoShow Media Manager"="C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe" [2006-01-13 16:22 233472]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-01-22 15:23 25368104]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09 460784]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 05:00 15360]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 09:23 202544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 14:01 67584]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 20:49 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 20:46 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 20:50 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 17:48 32881]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 03:12 94208]
"CTSysVol"="C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-09-15 09:47 57344]
"MBMon"="CTMBHA.DLL" [2005-05-19 08:54 1345520 C:\WINDOWS\system32\CTMBHA.DLL]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00 90112]
"VoiceCenter"="C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" [2005-09-19 07:42 1159168]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 07:58 213936]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-05-16 07:58 86960]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 05:20 122940]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-13 16:33 1838592]
"Lexmark X5100 Series"="C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe" [2003-03-04 07:49 86100]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 07:58 213936]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe" [2006-12-15 17:51 1807960]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384]

C:\Documents and Settings\Andrew\Start Menu\Programs\Startup\
Trend Micro Anti-Spyware.lnk - C:\Program Files\Trend Micro\Tmasy\Tmasy.exe [2007-07-24 20:45:39 1406480]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-03-06 10:44:57 24576]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxurss]
cbxurss.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Andrew^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
path=C:\Documents and Settings\Andrew\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c4f0c336]
–a—— 2007-12-12 19:21 85568 C:\WINDOWS\system32\divegbvt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dcsm]
C:\Program Files\Common Files\DriveCleaner Free\dcsm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
–a—— 2007-03-15 10:09 460784 C:\Program Files\DellSupport\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
–a—— 2005-09-08 19:20 8192 C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2006-03-06 10:50 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOL ACS"=2 (0x2)
"DSBrokerService"=3 (0x3)
"iPod Service"=3 (0x3)
"GameConsoleService"=3 (0x3)

R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
S4 GameConsoleService;GameConsoleService;"C:\Program Files\WildTangent\Apps\Dell Game Console\GameConsoleService.exe" [2007-08-28 18:06]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-16 10:50:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\Rundll32.exe
C:\DOCUME~1\Rick\LOCALS~1\Temp\clclean.0001
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-02-16 10:58:46 - machine was rebooted [Rick]
ComboFix-quarantined-files.txt 2008-02-16 15:58:43
.
2008-02-13 14:36:24 — E O F —

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:00:38 AM, on 2/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\DOCUME~1\Rick\LOCALS~1\Temp\clclean.0001
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/sp?r=al&cf=sp&…amp;O=I&UT=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 64.136.29.30;64.136.21.30;64.136.29.34;searchap.untd.com;127.0.0.1;localhost;*mi
crosoft.com;*windowsupdate.com;*wustat.windows.com;*.pogo.com;*.worldwinner.com;*
test-speed.com;liveupdate.symantecliveupdate.com;*symantec.com;*.nai.com;*.networkass
ociates.com;*photosite.com;*.dir.untd.com;*.prod.untd.com;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.0.21\ShoppingReport.dll (file missing)
O2 - BHO: NickToolbarInstall Class - {11AF48E4-CA6C-45ee-A181-282CD7A5BFCD} - C:\Documents and Settings\Andrew\Application Data\LaunchPad Toolbar\launchpadtoolbar.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\x1IEBHO.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: Nick - {A30B8EF5-82CA-4789-B77F-9C1C20DF53CB} - C:\Documents and Settings\Andrew\Application Data\LaunchPad Toolbar\launchpadtoolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Simple Star PhotoShow Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://wildcat.speedlinetech.com/iNotes6W.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolor.com/ClarkActivia.cab
O16 - DPF: {47CEF84E-92D8-4C4A-86D7-CB982889DCC0} (Oberon Media Network Optimizer) - http://mp1.mplay.oberon-media.com/client/flashnet.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.24.18/ttinst.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem…GameManager.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: cbxurss - cbxurss.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

–
End of file - 13196 bytes
A. Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6u4.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u4-windowsi586-p.exe to install the newest version.


Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon.
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.


B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\system32\uymufxxj.dll
C:\WINDOWS\system32\etvokxvb.dll
C:\WINDOWS\system32\dqumhnng.dll
C:\WINDOWS\system32\klaqepek.dll
C:\WINDOWS\system32\sloltldh.dll
C:\WINDOWS\system32\pamgwicb.dll
C:\WINDOWS\system32\dbtmetgi.dll
C:\WINDOWS\system32\gcogoxxv.dll
C:\WINDOWS\system32\yguylrsa.dll
C:\WINDOWS\system32\igbaevdj.dll
C:\WINDOWS\system32\ntvanncp.dll
C:\WINDOWS\system32\oelqqasr.dll
C:\WINDOWS\system32\gnhglaef.dll
C:\WINDOWS\system32\qtpfpptk.dll
C:\WINDOWS\system32\kuaamrtg.dll
C:\WINDOWS\system32\pmfanxfk.dll
C:\WINDOWS\system32\gidmhvje.dll
C:\WINDOWS\system32\ntlnmxnn.dll
C:\WINDOWS\system32\rskhixrc.dll
C:\WINDOWS\system32\lyhpgbgk.dll
C:\WINDOWS\system32\usbbpvce.dll
C:\WINDOWS\system32\jwjfwmax.dll
C:\WINDOWS\system32\uvkepaum.dll
C:\WINDOWS\system32\cjixnior.dll
C:\WINDOWS\system32\hkpemiks.dll
C:\WINDOWS\system32\fwqydcop.dll
C:\WINDOWS\system32\ldpwtivx.dll
C:\WINDOWS\system32\tgsyawxd.dll
C:\WINDOWS\system32\ikwaqfmh.dll
C:\WINDOWS\system32\vdicrexc.dll
C:\WINDOWS\system32\fdfygmru.dll
C:\WINDOWS\system32\vrfuxfca.dll
C:\WINDOWS\system32\pavas.ico
C:\WINDOWS\system32\Uninstall.ico
C:\WINDOWS\system32\Help.ico
C:\WINDOWS\system32\abwpccdn.dll
C:\WINDOWS\BMc7c3f0aa.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\vkbqakbg.dll
C:\WINDOWS\system32\welmnvou.dll
C:\WINDOWS\system32\iohqhhsa.dll
C:\WINDOWS\system32\hbunfthh.dll
C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup
C:\WINDOWS\system32\divegbvt.dll
E:\setup.exe

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{100EB1FD-D03E-47FD-81F3-EE91287F9465}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxurss]
[-HKLM\~\startupfolder\C:^Documents and Settings^Andrew^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c4f0c336]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dcsm]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



C. I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
OK. Most Pop-ups have now stopped. Here are the logs

ComboFix 08-02-16.2 - Rick 2008-02-16 10:33:10.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1298 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\pmnno.dll
C:\Documents and Settings\Andrew\err.log
C:\Documents and Settings\Andrew\ResErrors.log
C:\Documents and Settings\Ann Marie\Application Data\HbTools_Icons
C:\Documents and Settings\Ann Marie\Application Data\HbTools_Icons\Registryrepair.ico
C:\Documents and Settings\Ann Marie\Application Data\HbTools_Icons\Software_Online_8.ico
C:\Documents and Settings\Ann Marie\Desktop\Free PC Wallpapers.lnk
C:\Documents and Settings\Ann Marie\err.log
C:\Documents and Settings\Ann Marie\ResErrors.log
C:\Documents and Settings\Rick\err.log
C:\Documents and Settings\Rick\ResErrors.log
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ahckbnbj.dll
C:\WINDOWS\system32\aorsyrfo.dll
C:\WINDOWS\system32\bnhglbbk.dll
C:\WINDOWS\system32\cmckkusj.dll
C:\WINDOWS\system32\cmlkistb.dll
C:\WINDOWS\system32\dihbygyn.dll
C:\WINDOWS\system32\dthdeohg.dll
C:\WINDOWS\system32\dvrlknel.ini
C:\WINDOWS\system32\fjufxttd.dll
C:\WINDOWS\system32\fkgcktgk.dll
C:\WINDOWS\system32\fmrpjjex.dll
C:\WINDOWS\system32\gifldxhr.dll
C:\WINDOWS\system32\hxnfbgxm.dll
C:\WINDOWS\system32\iwcrdaxj.dll
C:\WINDOWS\system32\ixiehtdv.ini
C:\WINDOWS\system32\jcdhljrh.dll
C:\WINDOWS\system32\jsiebnsw.dll
C:\WINDOWS\system32\jsjqcowd.dll
C:\WINDOWS\system32\jsukkcmc.ini
C:\WINDOWS\system32\kvvxxola.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mptfbvnr.dll
C:\WINDOWS\system32\msuldfnk.dll
C:\WINDOWS\system32\nlamlhxb.dll
C:\WINDOWS\system32\ojweevab.ini
C:\WINDOWS\system32\onnmp.ini
C:\WINDOWS\system32\onnmp.ini2
C:\WINDOWS\system32\pfouryss.dll
C:\WINDOWS\system32\phtlssvc.dll
C:\WINDOWS\system32\pmnno.dll
C:\WINDOWS\system32\poiqfubf.dll
C:\WINDOWS\system32\qypwhkvy.dll
C:\WINDOWS\system32\rkeefrlt.ini
C:\WINDOWS\system32\sjhrvwnq.dll
C:\WINDOWS\system32\snrcsofy.dll
C:\WINDOWS\system32\ssucqotg.ini
C:\WINDOWS\system32\sxfmlgpc.dll
C:\WINDOWS\system32\sygfsbqi.dll
C:\WINDOWS\system32\tbtjtibn.dll
C:\WINDOWS\system32\uuciicsl.dll
C:\WINDOWS\system32\uvjesoly.dll
C:\WINDOWS\system32\uvqtiosd.dll
C:\WINDOWS\system32\uwkpxldo.dll
C:\WINDOWS\system32\whextphx.dll
C:\WINDOWS\system32\wlcllxcc.dll
C:\WINDOWS\system32\wphmwdum.dll
C:\WINDOWS\system32\wswenlea.dll
C:\WINDOWS\system32\xefybmjp.dll
C:\WINDOWS\system32\xutqvahx.ini
C:\WINDOWS\system32\xxjxtiqv.dll
C:\WINDOWS\system32\ydnrilqt.dll
C:\WINDOWS\system32\yhbftaui.dll
C:\WINDOWS\system32\ypiuvfuv.dll
C:\WINDOWS\system32\yqoynlef.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE


((((((((((((((((((((((((( Files Created from 2008-01-16 to 2008-02-16 )))))))))))))))))))))))))))))))
.

2008-02-16 10:27 . 2004-08-10 05:00 388,608 –a—— C:\kmd.exe
2008-02-16 09:44 . 2008-02-16 09:44 5,187 –a—— C:\WINDOWS\system32\uymufxxj.dll
2008-02-16 09:44 . 2008-02-16 09:44 5,180 –a—— C:\WINDOWS\system32\etvokxvb.dll
2008-02-14 12:59 . 2008-02-14 12:59 5,187 –a—— C:\WINDOWS\system32\dqumhnng.dll
2008-02-14 12:57 . 2008-02-14 12:57 5,191 –a—— C:\WINDOWS\system32\klaqepek.dll
2008-02-13 09:23 . 2008-02-13 09:23 5,191 –a—— C:\WINDOWS\system32\sloltldh.dll
2008-02-13 09:23 . 2008-02-13 09:23 5,187 –a—— C:\WINDOWS\system32\pamgwicb.dll
2008-02-12 17:12 . 2008-02-12 17:12 5,198 –a—— C:\WINDOWS\system32\dbtmetgi.dll
2008-02-12 17:11 . 2008-02-12 17:11 5,202 –a—— C:\WINDOWS\system32\gcogoxxv.dll
2008-02-11 11:08 . 2008-02-11 11:08 5,198 –a—— C:\WINDOWS\system32\yguylrsa.dll
2008-02-11 11:01 . 2008-02-11 11:01 5,202 –a—— C:\WINDOWS\system32\igbaevdj.dll
2008-02-10 10:34 . 2008-02-10 10:34 5,198 –a—— C:\WINDOWS\system32\ntvanncp.dll
2008-02-10 10:31 . 2008-02-10 10:31 5,202 –a—— C:\WINDOWS\system32\oelqqasr.dll
2008-02-09 08:04 . 2008-02-09 08:04 d——– C:\Documents and Settings\Rick\Application Data\MSNInstaller
2008-02-09 08:04 . 2008-02-09 08:04 d——– C:\DOCUME~1\Rick\APPLIC~1\MSNInstaller
2008-02-09 08:04 . 2008-02-09 08:04 d——– C:\DOCUME~1\Rick\APPLIC~1\MSNInstaller
2008-02-09 07:59 . 2008-02-09 07:59 5,198 –a—— C:\WINDOWS\system32\gnhglaef.dll
2008-02-09 07:58 . 2008-02-09 07:58 5,202 –a—— C:\WINDOWS\system32\qtpfpptk.dll
2008-02-08 06:58 . 2008-02-08 06:58 5,202 –a—— C:\WINDOWS\system32\kuaamrtg.dll
2008-02-07 07:50 . 2008-02-07 07:50 5,202 –a—— C:\WINDOWS\system32\pmfanxfk.dll
2008-02-07 07:50 . 2008-02-07 07:50 5,198 –a—— C:\WINDOWS\system32\gidmhvje.dll
2008-02-04 08:11 . 2008-02-04 08:11 5,198 –a—— C:\WINDOWS\system32\ntlnmxnn.dll
2008-02-04 08:07 . 2008-02-04 08:07 5,202 –a—— C:\WINDOWS\system32\rskhixrc.dll
2008-02-02 11:39 . 2008-02-02 11:39 d—-c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\SupportSoft
2008-02-02 11:38 . 2008-02-02 11:38 d——– C:\Program Files\Dell Support Center
2008-02-02 11:38 . 2008-02-02 11:38 d——– C:\Program Files\Common Files\supportsoft
2008-02-02 11:28 . 2008-02-02 11:28 5,198 –a—— C:\WINDOWS\system32\lyhpgbgk.dll
2008-02-02 11:23 . 2008-02-02 11:23 5,202 –a—— C:\WINDOWS\system32\usbbpvce.dll
2008-01-31 18:59 . 2008-01-31 18:59 5,198 –a—— C:\WINDOWS\system32\jwjfwmax.dll
2008-01-31 18:57 . 2008-01-31 18:57 5,202 –a—— C:\WINDOWS\system32\uvkepaum.dll
2008-01-30 14:49 . 2008-01-30 14:49 5,198 –a—— C:\WINDOWS\system32\cjixnior.dll
2008-01-29 14:11 . 2008-01-29 14:11 5,184 –a—— C:\WINDOWS\system32\hkpemiks.dll
2008-01-28 08:37 . 2008-02-02 11:36 d—-c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\Dell
2008-01-28 08:08 . 2008-01-28 08:12 d——– C:\Documents and Settings\Rick\Application Data\Intuit
2008-01-28 08:08 . 2008-01-28 08:12 d——– C:\DOCUME~1\Rick\APPLIC~1\Intuit
2008-01-28 08:08 . 2008-01-28 08:12 d——– C:\DOCUME~1\Rick\APPLIC~1\Intuit
2008-01-28 07:55 . 2008-01-28 07:55 5,184 –a—— C:\WINDOWS\system32\fwqydcop.dll
2008-01-27 11:20 . 2008-01-27 11:20 5,184 –a—— C:\WINDOWS\system32\ldpwtivx.dll
2008-01-26 09:50 . 2008-01-26 09:50 5,184 –a—— C:\WINDOWS\system32\tgsyawxd.dll
2008-01-25 08:04 . 2008-01-25 08:04 5,184 –a—— C:\WINDOWS\system32\ikwaqfmh.dll
2008-01-24 07:06 . 2008-01-24 07:06 5,184 –a—— C:\WINDOWS\system32\vdicrexc.dll
2008-01-23 07:07 . 2008-01-23 07:07 5,184 –a—— C:\WINDOWS\system32\fdfygmru.dll
2008-01-21 07:48 . 2008-01-21 07:48 5,184 –a—— C:\WINDOWS\system32\vrfuxfca.dll
2008-01-19 13:02 . 2008-01-19 13:02 d——– C:\Program Files\iPod
2008-01-19 12:42 . 2008-02-16 09:42 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-19 12:42 . 2008-01-19 12:42 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-19 11:53 . 2008-01-19 12:01 d——– C:\WINDOWS\system32\ActiveScan
2008-01-19 11:53 . 2008-01-19 11:53 30,590 –a—— C:\WINDOWS\system32\pavas.ico
2008-01-19 11:53 . 2008-01-19 11:53 2,550 –a—— C:\WINDOWS\system32\Uninstall.ico
2008-01-19 11:53 . 2008-01-19 11:53 1,406 –a—— C:\WINDOWS\system32\Help.ico
2008-01-19 09:04 . 2008-01-19 09:04 5,184 –a—— C:\WINDOWS\system32\abwpccdn.dll
2008-01-19 09:01 . 2008-02-16 09:43 6,112 –a—— C:\WINDOWS\BMc7c3f0aa.xml
2008-01-19 09:01 . 2008-02-16 09:42 22 –a—— C:\WINDOWS\pskt.ini
2008-01-18 07:45 . 2008-01-18 07:45 5,184 –a—— C:\WINDOWS\system32\vkbqakbg.dll
2008-01-18 07:42 . 2008-01-18 07:42 5,165 –a—— C:\WINDOWS\system32\welmnvou.dll
2008-01-16 19:31 . 2008-01-16 19:31 5,184 –a—— C:\WINDOWS\system32\iohqhhsa.dll
2008-01-16 19:28 . 2008-01-16 19:28 5,165 –a—— C:\WINDOWS\system32\hbunfthh.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-16 14:49 ——— d—–w C:\Documents and Settings\Rick\Application Data\Skype
2008-02-16 14:49 ——— d—–w C:\DOCUME~1\Rick\APPLIC~1\Skype
2008-02-16 14:49 ——— d—–w C:\DOCUME~1\Rick\APPLIC~1\Skype
2008-02-15 16:36 ——— d—–w C:\Program Files\SpongeBob SquarePants Diner Dash
2008-02-15 16:28 ——— d—–w C:\Program Files\Fairly Odd Parents Information Stupor Highway
2008-02-15 14:01 ——— d—–w C:\Program Files\Trend Micro
2008-02-14 22:30 ——— d—–w C:\Program Files\Diegos Rescue Adventure
2008-02-11 16:13 ——— d—–w C:\Documents and Settings\Andrew\Application Data\Intuit
2008-01-28 13:06 ——— d—–w C:\Program Files\Common Files\AnswerWorks 4.0
2008-01-28 13:05 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-28 12:49 ——— d—–w C:\Program Files\TurboTax
2008-01-19 18:03 ——— d—–w C:\Program Files\iTunes
2008-01-19 18:00 ——— d—–w C:\Program Files\QuickTime
2008-01-17 22:33 ——— dc–a-w C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-12-28 20:29 ——— d—–w C:\Documents and Settings\Ann Marie\Application Data\Skype
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-18 00:56 ——— d—–w C:\Program Files\MalwareAlarm
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{100EB1FD-D03E-47FD-81F3-EE91287F9465}]
C:\Program Files\ShoppingReport\Bin\2.0.21\ShoppingReport.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetDefaultMIDI"="MIDIDef.exe" [2004-12-22 17:40 24576 C:\WINDOWS\MIDIDEF.EXE]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23 102400]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-23 11:55 68856]
"Simple Star PhotoShow Media Manager"="C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe" [2006-01-13 16:22 233472]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-01-22 15:23 25368104]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09 460784]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 05:00 15360]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 09:23 202544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 14:01 67584]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 20:49 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 20:46 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 20:50 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 17:48 32881]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 03:12 94208]
"CTSysVol"="C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-09-15 09:47 57344]
"MBMon"="CTMBHA.DLL" [2005-05-19 08:54 1345520 C:\WINDOWS\system32\CTMBHA.DLL]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00 90112]
"VoiceCenter"="C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" [2005-09-19 07:42 1159168]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 07:58 213936]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-05-16 07:58 86960]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 05:20 122940]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-13 16:33 1838592]
"Lexmark X5100 Series"="C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe" [2003-03-04 07:49 86100]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 07:58 213936]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe" [2006-12-15 17:51 1807960]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384]

C:\Documents and Settings\Andrew\Start Menu\Programs\Startup\
Trend Micro Anti-Spyware.lnk - C:\Program Files\Trend Micro\Tmasy\Tmasy.exe [2007-07-24 20:45:39 1406480]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-03-06 10:44:57 24576]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxurss]
cbxurss.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Andrew^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
path=C:\Documents and Settings\Andrew\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c4f0c336]
–a—— 2007-12-12 19:21 85568 C:\WINDOWS\system32\divegbvt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dcsm]
C:\Program Files\Common Files\DriveCleaner Free\dcsm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
–a—— 2007-03-15 10:09 460784 C:\Program Files\DellSupport\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
–a—— 2005-09-08 19:20 8192 C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2006-03-06 10:50 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOL ACS"=2 (0x2)
"DSBrokerService"=3 (0x3)
"iPod Service"=3 (0x3)
"GameConsoleService"=3 (0x3)

R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
S4 GameConsoleService;GameConsoleService;"C:\Program Files\WildTangent\Apps\Dell Game Console\GameConsoleService.exe" [2007-08-28 18:06]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-16 10:50:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\Rundll32.exe
C:\DOCUME~1\Rick\LOCALS~1\Temp\clclean.0001
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-02-16 10:58:46 - machine was rebooted [Rick]
ComboFix-quarantined-files.txt 2008-02-16 15:58:43
.
2008-02-13 14:36:24 — E O F —

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:24:54 PM, on 2/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\DOCUME~1\Rick\LOCALS~1\Temp\clclean.0001
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/sp?r=al&cf=sp&…amp;O=I&UT=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 64.136.29.30;64.136.21.30;64.136.29.34;searchap.untd.com;127.0.0.1;localhost;*mi
crosoft.com;*windowsupdate.com;*wustat.windows.com;*.pogo.com;*.worldwinner.com;*
test-speed.com;liveupdate.symantecliveupdate.com;*symantec.com;*.nai.com;*.networkass
ociates.com;*photosite.com;*.dir.untd.com;*.prod.untd.com;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.0.21\ShoppingReport.dll (file missing)
O2 - BHO: NickToolbarInstall Class - {11AF48E4-CA6C-45ee-A181-282CD7A5BFCD} - C:\Documents and Settings\Andrew\Application Data\LaunchPad Toolbar\launchpadtoolbar.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\x1IEBHO.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: Nick - {A30B8EF5-82CA-4789-B77F-9C1C20DF53CB} - C:\Documents and Settings\Andrew\Application Data\LaunchPad Toolbar\launchpadtoolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Simple Star PhotoShow Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://wildcat.speedlinetech.com/iNotes6W.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolor.com/ClarkActivia.cab
O16 - DPF: {47CEF84E-92D8-4C4A-86D7-CB982889DCC0} (Oberon Media Network Optimizer) - http://mp1.mplay.oberon-media.com/client/flashnet.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.24.18/ttinst.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem…GameManager.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: cbxurss - cbxurss.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

–
End of file - 13890 bytes


# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=2880 (20080215)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.064 (20070717)
# EOSSerial=dbb5ed9dd3cc2c43a20f83a32e2d5595
# end=finished
# remove_checked=false
# unwanted_checked=false
# utc_time=2008-02-16 11:18:48
# local_time=2008-02-16 06:18:48 (-0500, Eastern Standard Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 2
# scanned=546098
# found=18
# scan_time=10274
C:\Program Files\MalwareAlarm\Uninstall.exe Win32/Adware.SpySheriff application 66DDBEB1A4263BE71AF2CE24412158EA
C:\QooBox\Quarantine\C\WINDOWS\system32\ahckbnbj.dll.vir Win32/BHO.G trojan F6B7E56559E398E6B175CA93456BA205
C:\QooBox\Quarantine\C\WINDOWS\system32\aorsyrfo.dll.vir Win32/BHO.G trojan 021337C4DB95B1F25580372BCB406A2C
C:\QooBox\Quarantine\C\WINDOWS\system32\bnhglbbk.dll.vir Win32/BHO.G trojan D8DA5E5DFBB7A5CE982D7D188AE37DDA
C:\QooBox\Quarantine\C\WINDOWS\system32\dthdeohg.dll.vir Win32/Adware.AdMedia application A8724D2CA3CD70B6613E60F18A3657E8
C:\QooBox\Quarantine\C\WINDOWS\system32\fjufxttd.dll.vir Win32/BHO.G trojan 9CBAF960BF2C449780D886181ECF03C7
C:\QooBox\Quarantine\C\WINDOWS\system32\fkgcktgk.dll.vir Win32/BHO.G trojan 999DE2AF47647A2B1D91C46E2746B00E
C:\QooBox\Quarantine\C\WINDOWS\system32\fmrpjjex.dll.vir Win32/BHO.G trojan 5A5F8831523010487F19DF40E5BEE903
C:\QooBox\Quarantine\C\WINDOWS\system32\msuldfnk.dll.vir Win32/BHO.G trojan A1C3F5E6FD859EFE975499B142CD2429
C:\QooBox\Quarantine\C\WINDOWS\system32\pfouryss.dll.vir Win32/BHO.G trojan CA81429A455508A0467DA68C0D017AB6
C:\QooBox\Quarantine\C\WINDOWS\system32\uuciicsl.dll.vir Win32/BHO.G trojan F41DFA14C13286606BCE8918826288BF
C:\QooBox\Quarantine\C\WINDOWS\system32\whextphx.dll.vir Win32/BHO.G trojan 37B18E894E64E5C1D297CA509D6178BA
C:\QooBox\Quarantine\C\WINDOWS\system32\wswenlea.dll.vir Win32/BHO.G trojan 148CE41D98C0E15834D2018D2A13EEF1
C:\QooBox\Quarantine\C\WINDOWS\system32\xxjxtiqv.dll.vir Win32/Adware.AdMedia application 7901DDD5B5D9DAAAB8681666F60D9DCA
C:\QooBox\Quarantine\C\WINDOWS\system32\ypiuvfuv.dll.vir Win32/Adware.AdMedia application C17DF010151D23121E6B78758A99A452
C:\WINDOWS\system32\baveewjo.dll Win32/Adware.Virtumonde application A0EE6A036014FEAA6F05EC3664E313E2
C:\WINDOWS\system32\divegbvt.dll Win32/Adware.Virtumonde application A0EE6A036014FEAA6F05EC3664E313E2
C:\WINDOWS\system32\gtoqcuss.dll Win32/Adware.Virtumonde application A0EE6A036014FEAA6F05EC3664E313E2
The script did not run or you posted the wrong ComboFix.txt. It shows in the header. The text file that you posted is from the first run of ComboFix. Remember to name the text file exactly as directed, then click and drag the text file onto the ComboFix icon. 1. Look in the C:\ComboFix folder for ComboFix.txt or in the C:\ root. If you find it it should say that it was run with a CFSCript switch. If found, please post it. 2. If not present, rerun the script from my last post and stay by your machine to copy the results or note any error messages that may pop up. Please post the results.
Let's try it again.

Here is the correct Combofix log:
ComboFix 08-02-16.2 - Rick 2008-02-17 10:41:29.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1517 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Rick\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\BMc7c3f0aa.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup
C:\WINDOWS\system32\abwpccdn.dll
C:\WINDOWS\system32\cjixnior.dll
C:\WINDOWS\system32\dbtmetgi.dll
C:\WINDOWS\system32\divegbvt.dll
C:\WINDOWS\system32\dqumhnng.dll
C:\WINDOWS\system32\etvokxvb.dll
C:\WINDOWS\system32\fdfygmru.dll
C:\WINDOWS\system32\fwqydcop.dll
C:\WINDOWS\system32\gcogoxxv.dll
C:\WINDOWS\system32\gidmhvje.dll
C:\WINDOWS\system32\gnhglaef.dll
C:\WINDOWS\system32\hbunfthh.dll
C:\WINDOWS\system32\Help.ico
C:\WINDOWS\system32\hkpemiks.dll
C:\WINDOWS\system32\igbaevdj.dll
C:\WINDOWS\system32\ikwaqfmh.dll
C:\WINDOWS\system32\iohqhhsa.dll
C:\WINDOWS\system32\jwjfwmax.dll
C:\WINDOWS\system32\klaqepek.dll
C:\WINDOWS\system32\kuaamrtg.dll
C:\WINDOWS\system32\ldpwtivx.dll
C:\WINDOWS\system32\lyhpgbgk.dll
C:\WINDOWS\system32\ntlnmxnn.dll
C:\WINDOWS\system32\ntvanncp.dll
C:\WINDOWS\system32\oelqqasr.dll
C:\WINDOWS\system32\pamgwicb.dll
C:\WINDOWS\system32\pavas.ico
C:\WINDOWS\system32\pmfanxfk.dll
C:\WINDOWS\system32\qtpfpptk.dll
C:\WINDOWS\system32\rskhixrc.dll
C:\WINDOWS\system32\sloltldh.dll
C:\WINDOWS\system32\tgsyawxd.dll
C:\WINDOWS\system32\Uninstall.ico
C:\WINDOWS\system32\usbbpvce.dll
C:\WINDOWS\system32\uvkepaum.dll
C:\WINDOWS\system32\uymufxxj.dll
C:\WINDOWS\system32\vdicrexc.dll
C:\WINDOWS\system32\vkbqakbg.dll
C:\WINDOWS\system32\vrfuxfca.dll
C:\WINDOWS\system32\welmnvou.dll
C:\WINDOWS\system32\yguylrsa.dll
E:\setup.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\BMc7c3f0aa.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup
C:\WINDOWS\system32\abwpccdn.dll
C:\WINDOWS\system32\baveewjo.dll
C:\WINDOWS\system32\cjixnior.dll
C:\WINDOWS\system32\dbtmetgi.dll
C:\WINDOWS\system32\divegbvt.dll
C:\WINDOWS\system32\dqumhnng.dll
C:\WINDOWS\system32\etvokxvb.dll
C:\WINDOWS\system32\fdfygmru.dll
C:\WINDOWS\system32\fwqydcop.dll
C:\WINDOWS\system32\gcogoxxv.dll
C:\WINDOWS\system32\gidmhvje.dll
C:\WINDOWS\system32\gnhglaef.dll
C:\WINDOWS\system32\gtoqcuss.dll
C:\WINDOWS\system32\hbunfthh.dll
C:\WINDOWS\system32\Help.ico
C:\WINDOWS\system32\hkpemiks.dll
C:\WINDOWS\system32\igbaevdj.dll
C:\WINDOWS\system32\ikwaqfmh.dll
C:\WINDOWS\system32\iohqhhsa.dll
C:\WINDOWS\system32\jwjfwmax.dll
C:\WINDOWS\system32\klaqepek.dll
C:\WINDOWS\system32\kuaamrtg.dll
C:\WINDOWS\system32\ldpwtivx.dll
C:\WINDOWS\system32\lyhpgbgk.dll
C:\WINDOWS\system32\ntlnmxnn.dll
C:\WINDOWS\system32\ntvanncp.dll
C:\WINDOWS\system32\oelqqasr.dll
C:\WINDOWS\system32\pamgwicb.dll
C:\WINDOWS\system32\pavas.ico
C:\WINDOWS\system32\pmfanxfk.dll
C:\WINDOWS\system32\qtpfpptk.dll
C:\WINDOWS\system32\rskhixrc.dll
C:\WINDOWS\system32\sloltldh.dll
C:\WINDOWS\system32\tgsyawxd.dll
C:\WINDOWS\system32\Uninstall.ico
C:\WINDOWS\system32\usbbpvce.dll
C:\WINDOWS\system32\uvkepaum.dll
C:\WINDOWS\system32\uymufxxj.dll
C:\WINDOWS\system32\vdicrexc.dll
C:\WINDOWS\system32\vkbqakbg.dll
C:\WINDOWS\system32\vrfuxfca.dll
C:\WINDOWS\system32\welmnvou.dll
C:\WINDOWS\system32\yguylrsa.dll

.
((((((((((((((((((((((((( Files Created from 2008-01-17 to 2008-02-17 )))))))))))))))))))))))))))))))
.

2008-02-16 15:26 . 2008-02-16 18:18 d——– C:\Program Files\EsetOnlineScanner
2008-02-16 13:19 . 2007-12-14 01:59 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-02-16 13:18 . 2008-02-16 13:18 d——– C:\Program Files\Common Files\Java
2008-02-16 10:27 . 2004-08-10 05:00 388,608 –a—— C:\kmd.exe
2008-02-11 09:40 . 2008-02-11 09:40 2,715,648 –a—— C:\WINDOWS\system32\OnlineScanner.ocx
2008-02-11 09:39 . 2008-02-11 09:39 253,952 –a—— C:\WINDOWS\system32\OnlineScannerDLLA.dll
2008-02-11 09:39 . 2008-02-11 09:39 237,568 –a—— C:\WINDOWS\system32\OnlineScannerDLLW.dll
2008-02-09 08:04 . 2008-02-09 08:04 d——– C:\Documents and Settings\Rick\Application Data\MSNInstaller
2008-02-09 08:04 . 2008-02-09 08:04 d——– C:\DOCUME~1\Rick\APPLIC~1\MSNInstaller
2008-02-08 13:53 . 2008-02-08 13:53 110,592 –a—— C:\WINDOWS\system32\OnlineScannerLang.dll
2008-02-05 08:48 . 2008-02-05 08:48 77,824 –a—— C:\WINDOWS\system32\OnlineScannerUninstaller.exe
2008-02-02 11:39 . 2008-02-02 11:39 d—-c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\SupportSoft
2008-02-02 11:38 . 2008-02-02 11:38 d——– C:\Program Files\Dell Support Center
2008-02-02 11:38 . 2008-02-02 11:38 d——– C:\Program Files\Common Files\supportsoft
2008-01-28 08:37 . 2008-02-02 11:36 d—-c— C:\DOCUME~1\ALLUSE~1\APPLIC~1\Dell
2008-01-28 08:08 . 2008-01-28 08:12 d——– C:\Documents and Settings\Rick\Application Data\Intuit
2008-01-28 08:08 . 2008-01-28 08:12 d——– C:\DOCUME~1\Rick\APPLIC~1\Intuit
2008-01-19 13:02 . 2008-01-19 13:02 d——– C:\Program Files\iPod
2008-01-19 12:42 . 2008-02-17 10:32 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-19 12:42 . 2008-01-19 12:42 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-19 11:53 . 2008-01-19 12:01 d——– C:\WINDOWS\system32\ActiveScan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-17 15:37 ——— d—–w C:\Program Files\Nick Arcade
2008-02-17 15:34 ——— d—–w C:\Documents and Settings\Rick\Application Data\Skype
2008-02-17 15:34 ——— d—–w C:\DOCUME~1\Rick\APPLIC~1\Skype
2008-02-16 18:19 ——— d—–w C:\Program Files\Java
2008-02-15 16:36 ——— d—–w C:\Program Files\SpongeBob SquarePants Diner Dash
2008-02-15 16:28 ——— d—–w C:\Program Files\Fairly Odd Parents Information Stupor Highway
2008-02-15 14:01 ——— d—–w C:\Program Files\Trend Micro
2008-02-14 22:30 ——— d—–w C:\Program Files\Diegos Rescue Adventure
2008-02-11 16:13 ——— d—–w C:\Documents and Settings\Andrew\Application Data\Intuit
2008-01-28 13:06 ——— d—–w C:\Program Files\Common Files\AnswerWorks 4.0
2008-01-28 13:05 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-28 12:49 ——— d—–w C:\Program Files\TurboTax
2008-01-19 18:03 ——— d—–w C:\Program Files\iTunes
2008-01-19 18:00 ——— d—–w C:\Program Files\QuickTime
2008-01-17 22:33 ——— dc–a-w C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-12-28 20:29 ——— d—–w C:\Documents and Settings\Ann Marie\Application Data\Skype
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-18 00:56 ——— d—–w C:\Program Files\MalwareAlarm
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetDefaultMIDI"="MIDIDef.exe" [2004-12-22 17:40 24576 C:\WINDOWS\MIDIDEF.EXE]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23 102400]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-23 11:55 68856]
"Simple Star PhotoShow Media Manager"="C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe" [2006-01-13 16:22 233472]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-01-22 15:23 25368104]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09 460784]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 05:00 15360]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 09:23 202544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 14:01 67584]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 20:49 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 20:46 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 20:50 114688]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 03:12 94208]
"CTSysVol"="C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-09-15 09:47 57344]
"MBMon"="CTMBHA.DLL" [2005-05-19 08:54 1345520 C:\WINDOWS\system32\CTMBHA.DLL]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00 90112]
"VoiceCenter"="C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" [2005-09-19 07:42 1159168]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 07:58 213936]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-05-16 07:58 86960]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 05:20 122940]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-13 16:33 1838592]
"Lexmark X5100 Series"="C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe" [2003-03-04 07:49 86100]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 07:58 213936]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe" [2006-12-15 17:51 1807960]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]

C:\Documents and Settings\Andrew\Start Menu\Programs\Startup\
Trend Micro Anti-Spyware.lnk - C:\Program Files\Trend Micro\Tmasy\Tmasy.exe [2007-07-24 20:45:39 1406480]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-03-06 10:44:57 24576]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
–a—— 2007-03-15 10:09 460784 C:\Program Files\DellSupport\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
–a—— 2005-09-08 19:20 8192 C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2006-03-06 10:50 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOL ACS"=2 (0x2)
"DSBrokerService"=3 (0x3)
"iPod Service"=3 (0x3)
"GameConsoleService"=3 (0x3)

R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
S4 GameConsoleService;GameConsoleService;"C:\Program Files\WildTangent\Apps\Dell Game Console\GameConsoleService.exe" [2007-08-28 18:06]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-17 10:48:06
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\system32\Rundll32.exe
C:\DOCUME~1\Rick\LOCALS~1\Temp\clclean.0001
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
.
**************************************************************************
.
Completion time: 2008-02-17 10:57:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-17 15:57:33
ComboFix2.txt 2008-02-16 20:18:22
ComboFix3.txt 2008-02-16 15:58:47
.
2008-02-13 14:36:24 — E O F —
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform full scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
Here is the MBAM log. So far computer is running much better. Malwarebytes' Anti-Malware 1.03 Database version: 371 Scan type: Full Scan (C:\|) Objects scanned: 213039 Time elapsed: 1 hour(s), 29 minute(s), 40 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 7 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 7 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\MalwareAlarm (Rogue.Malware.Alarm) -> Quarantined and deleted successfully. Files Infected: C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP204\A0096136.dll (Rogue.Multiple) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP204\A0096137.dll (Rogue.Multiple) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP204\A0096138.dll (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\MalwareAlarm\MalwareAlarm.lic (Rogue.Malware.Alarm) -> Quarantined and deleted successfully. C:\Program Files\MalwareAlarm\Uninstall.exe (Rogue.Malware.Alarm) -> Quarantined and deleted successfully. C:\Documents and Settings\Ann Marie\Desktop\Find And Fix Errors.lnk (Rogue.Link) -> Quarantined and deleted successfully. C:\Documents and Settings\Ann Marie\Desktop\Repair Your Registry.lnk (Rogue.Link) -> Quarantined and deleted successfully.
Your log looks clean. If you have no more malware-related problems that you are aware of, just give me the OK and we can start the final but essential cleanup procedures and recommendations.

Trevuren
I would recommend that you keep MBAM and update and run it regularly.

Congratulations, your logs look CLEAN

There are a few things you must do once you system is completely clean:

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK


  • [external image: Posted Image]



The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.


Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Use and Update an Anti-Virus Software - I can not overemphasize the need for you to use and update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. FIREWALL
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found here

Do not install more than one firewall program because they will conflict with each other


4. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

5. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

6. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

7. Install Spybot - Search and Destroy - Download and install Spybot - Search and Destroy with its TeaTimer option. This will provide real time spyware and hijacker protection on your computer alongside your virus protection. You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A tutorial on installing and using this product can be found here:
Instructions for - Spybot S & D and Ad-aware

8. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI