This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Polipos/Trojan problem

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Download ComboFix from Here or Here to your Desktop.



Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review


Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
ComboFix 08-02-25 - Main 2008-02-24 16:52:38.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.755 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\smdat32a.sys
C:\WINDOWS\smdat32m.sys

.
((((((((((((((((((((((((( Files Created from 2008-01-25 to 2008-02-25 )))))))))))))))))))))))))))))))
.

2008-02-24 16:48 . 2008-02-24 16:48 d——– C:\WINDOWS\LastGood
2008-02-23 19:44 . 2008-02-23 19:44 d——– C:\WINDOWS\ERUNT
2008-02-23 19:33 . 2008-02-23 20:11 d——– C:\SDFix
2008-02-23 05:55 . 2008-02-24 09:26 d——– C:\WINDOWS\system32\ActiveScan
2008-02-23 05:55 . 2008-02-24 06:34 30,590 –a—— C:\WINDOWS\system32\pavas.ico
2008-02-22 14:28 . 2008-02-22 16:02 d——– C:\Program Files\EsetOnlineScanner
2008-02-22 07:52 . 2008-02-22 07:52 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-22 07:52 . 2008-02-22 07:52 d——– C:\Documents and Settings\Main\Application Data\Malwarebytes
2008-02-22 07:52 . 2008-02-22 07:52 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-22 04:25 . 2008-02-22 04:25 0 –a—— C:\WINDOWS\system32\REN13E.tmp
2008-02-22 04:25 . 2008-02-22 04:25 0 –a—— C:\WINDOWS\system32\REN13D.tmp
2008-02-20 19:51 . 2004-08-04 07:00 113,222 –a–c— C:\WINDOWS\system32\dllcache\zoneclim.dll
2008-02-20 19:51 . 2004-08-04 07:00 41,029 –a–c— C:\WINDOWS\system32\dllcache\zcorem.dll
2008-02-20 19:51 . 2004-08-04 07:00 36,937 –a–c— C:\WINDOWS\system32\dllcache\zclientm.exe
2008-02-20 19:51 . 2004-08-04 07:00 29,760 –a–c— C:\WINDOWS\system32\dllcache\znetm.dll
2008-02-20 19:51 . 2004-08-04 07:00 13,894 –a–c— C:\WINDOWS\system32\dllcache\zonelibm.dll
2008-02-20 19:51 . 2004-08-04 07:00 4,677 –a–c— C:\WINDOWS\system32\dllcache\zeeverm.dll
2008-02-20 19:49 . 2004-08-04 07:00 13,463,552 –a–c— C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-02-20 19:48 . 2004-08-04 07:00 1,817,687 –a–c— C:\WINDOWS\system32\dllcache\bckgres.dll
2008-02-20 19:47 . 2008-02-20 19:47 488 -rah—– C:\WINDOWS\system32\logonui.exe.manifest
2008-02-20 19:46 . 2008-02-20 19:46 749 -rah—– C:\WINDOWS\WindowsShell.Manifest
2008-02-20 19:46 . 2008-02-20 19:46 749 -rah—– C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-02-20 19:46 . 2008-02-20 19:46 749 -rah—– C:\WINDOWS\system32\sapi.cpl.manifest
2008-02-20 19:46 . 2008-02-20 19:46 749 -rah—– C:\WINDOWS\system32\ncpa.cpl.manifest
2008-02-20 12:33 . 2008-02-20 12:33 22 –a—— C:\WINDOWS\system32\ati64hlp.stb
2008-02-20 11:53 . 2008-02-24 06:34 2,550 –a—— C:\WINDOWS\system32\Uninstall.ico
2008-02-20 11:53 . 2008-02-24 06:34 1,406 –a—— C:\WINDOWS\system32\Help.ico
2008-02-20 11:31 . 2008-02-20 11:31 22 –a—— C:\WINDOWS\system32\ati64hl2.stb
2008-02-20 11:27 . 2008-02-20 11:27 497 –a—— C:\WINDOWS\Ascd_tmp.ini
2008-02-20 11:16 . 2008-02-22 04:21 d——– C:\Program Files\ATI Technologies
2008-02-20 11:16 . 2004-07-17 21:10 516,096 –a—— C:\WINDOWS\system32\ati2sgag.exe
2008-02-20 11:16 . 2004-07-17 23:17 294,912 -ra—— C:\WINDOWS\system32\atiiiexx.dll
2008-02-20 11:16 . 2004-07-17 22:55 135,168 -ra—— C:\WINDOWS\system32\ATIDEMGR.dll
2008-02-18 16:01 . 2008-02-18 16:05 d——– C:\WINDOWS\SxsCaPendDel
2008-02-18 15:58 . 2004-08-04 00:56 870,784 –a—— C:\WINDOWS\system32\ati3d1ag.dll
2008-02-18 15:58 . 2004-08-04 00:56 32,768 –a—— C:\WINDOWS\system32\ativtmxx.dll
2008-02-18 15:58 . 2004-08-04 00:56 23,040 –a—— C:\WINDOWS\system32\ativmvxx.ax
2008-02-18 15:55 . 2008-02-22 04:21 10 –a—— C:\WINDOWS\WININIT.INI
2008-02-18 15:25 . 2004-08-04 07:00 380,416 –a–c— C:\WINDOWS\system32\dllcache\rstrui.exe
2008-02-18 15:25 . 2004-08-04 07:00 93,184 –a-sc— C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-18 15:25 . 2004-08-04 07:00 60,416 –a-sc— C:\WINDOWS\system32\dllcache\msimn.exe
2008-02-18 15:23 . 2004-08-04 07:00 218,112 –a–c— C:\WINDOWS\system32\dllcache\wmiprvse.exe
2008-02-18 15:15 . 2004-08-04 07:00 1,086,058 -ra—— C:\WINDOWS\SET46.tmp
2008-02-18 15:15 . 2004-08-04 07:00 1,042,903 -ra—— C:\WINDOWS\SET43.tmp
2008-02-18 15:15 . 2004-08-04 07:00 13,753 -ra—— C:\WINDOWS\SET54.tmp
2008-02-14 18:00 . 2008-02-14 18:04 d——– C:\Documents and Settings\Main\DoctorWeb
2008-02-11 19:57 . 2008-02-11 19:57 205 –a—— C:\~TaxUnin.bat
2008-02-11 13:21 . 2008-02-11 13:21 d——– C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-02-11 09:40 . 2008-02-11 09:40 2,715,648 –a—— C:\WINDOWS\system32\OnlineScanner.ocx
2008-02-11 09:39 . 2008-02-11 09:39 253,952 –a—— C:\WINDOWS\system32\OnlineScannerDLLA.dll
2008-02-11 09:39 . 2008-02-11 09:39 237,568 –a—— C:\WINDOWS\system32\OnlineScannerDLLW.dll
2008-02-09 22:41 . 2004-08-04 07:00 1,086,058 -ra—— C:\WINDOWS\SET42.tmp
2008-02-09 22:41 . 2004-08-04 07:00 1,042,903 -ra—— C:\WINDOWS\SET3F.tmp
2008-02-09 22:41 . 2004-08-04 07:00 13,753 -ra—— C:\WINDOWS\SET4F.tmp
2008-02-09 22:28 . 2008-02-09 22:28 d——– C:\WINDOWS\system32\FxsTmp
2008-02-09 22:26 . 2004-08-04 07:00 562,176 –a—— C:\WINDOWS\system32\fxsst.dll
2008-02-09 09:21 . 2008-02-09 09:21 d——– C:\Documents and Settings\Main\Application Data\Simple Star
2008-02-09 09:21 . 2004-07-13 15:47 421,888 –a—— C:\WINDOWS\Nero PhotoShow.scr
2008-02-09 09:08 . 2008-02-20 11:11 d——– C:\Documents and Settings\Main\Application Data\Ahead
2008-02-09 09:07 . 2008-02-09 09:07 d——– C:\WINDOWS\InCD
2008-02-09 09:07 . 2004-11-26 08:44 2,461,696 –a—— C:\WINDOWS\UNMRW.exe
2008-02-09 09:07 . 2004-11-26 13:36 98,176 –a—— C:\WINDOWS\system32\drivers\InCDfs.sys
2008-02-09 09:07 . 2005-01-05 05:12 55,606 –a—— C:\WINDOWS\UNMRW.cfg
2008-02-09 09:07 . 2004-11-26 13:36 28,928 –a—— C:\WINDOWS\system32\drivers\InCDpass.sys
2008-02-09 09:07 . 2004-11-26 07:36 27,648 ——— C:\WINDOWS\system32\drivers\InCDrm.sys
2008-02-09 09:07 . 2004-11-26 13:36 7,808 –a—— C:\WINDOWS\system32\drivers\InCDrec.sys
2008-02-09 09:04 . 2008-02-22 04:31 d——– C:\Program Files\Common Files\Ahead
2008-02-09 09:04 . 2008-02-22 04:31 d——– C:\Program Files\Ahead
2008-02-09 09:04 . 2008-02-09 09:04 d——– C:\Documents and Settings\All Users\Application Data\Ahead
2008-02-09 09:04 . 2001-03-08 18:30 24,064 ——— C:\WINDOWS\system32\msxml3a.dll
2008-02-08 19:07 . 2008-02-08 19:07 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-08 19:07 . 2008-02-08 19:07 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-08 13:53 . 2008-02-08 13:53 110,592 –a—— C:\WINDOWS\system32\OnlineScannerLang.dll
2008-02-05 09:29 . 2004-08-04 07:00 1,086,058 -ra—— C:\WINDOWS\SET41.tmp
2008-02-05 09:29 . 2004-08-04 07:00 1,042,903 -ra—— C:\WINDOWS\SET3E.tmp
2008-02-05 09:29 . 2004-08-04 07:00 13,753 -ra—— C:\WINDOWS\SET4E.tmp
2008-02-05 08:48 . 2008-02-05 08:48 77,824 –a—— C:\WINDOWS\system32\OnlineScannerUninstaller.exe
2008-02-04 08:53 . 2008-02-04 08:53 d——– C:\Documents and Settings\Main\Application Data\ATI
2008-02-04 08:52 . 2008-02-04 08:52 0 –a—— C:\WINDOWS\ativpsrm.bin
2008-02-02 22:15 . 2008-02-02 22:15 d——– C:\ATI
2008-02-02 11:52 . 2008-02-02 11:52 393,216 –a—— C:\WINDOWS\system32\LOGONUI.000
2008-01-29 07:59 . 2004-08-04 07:00 1,086,058 -ra—— C:\WINDOWS\SET50.tmp
2008-01-29 07:59 . 2004-08-04 07:00 1,042,903 -ra—— C:\WINDOWS\SET4D.tmp
2008-01-29 07:59 . 2004-08-04 07:00 13,753 -ra—— C:\WINDOWS\SET5C.tmp
2008-01-26 19:51 . 2008-02-11 13:16 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-26 19:46 . 2008-01-26 19:46 d——– C:\Program Files\Common Files\PC Tools

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-24 14:20 ——— d—–w C:\Program Files\Common Files\aolshare
2008-02-22 10:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-22 09:24 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-22 09:23 ——— d—–w C:\Program Files\msaccrt
2008-02-22 09:23 ——— d—–w C:\Program Files\ATI Multimedia
2008-02-22 09:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\ATI MMC
2008-02-12 00:57 205 —-a-w C:\~TaxUnin.bat
2008-02-12 00:57 ——— d—–w C:\Program Files\Common Files\Intuit
2008-02-10 13:32 ——— d—–w C:\Program Files\Google
2008-02-10 13:31 ——— d—–w C:\Program Files\Puppy Luv
2008-02-10 13:30 ——— d—–w C:\Program Files\Picasa2
2008-02-10 13:29 ——— d—–w C:\Program Files\IrfanView
2008-02-10 13:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\PureEdge
2008-02-10 13:26 ——— d—–w C:\Program Files\ASUS
2008-02-10 12:54 ——— d—–w C:\Program Files\INSTAFINK
2008-02-10 12:49 42,496 —-a-w C:\WINDOWS\UniFish3.exe
2008-02-10 12:48 138,752 —-a-w C:\WINDOWS\system32\sndvol32.exe.tmp
2008-02-10 12:46 114,688 —-a-w C:\WINDOWS\system32\calc.exe.tmp
2008-02-10 12:42 60,416 —-a-w C:\WINDOWS\ALCFDRTM.EXE
2008-02-10 04:40 176,128 —-a-r C:\WINDOWS\system32\nvusmb.exe
2008-02-09 00:12 ——— d—–w C:\Program Files\QuickTime
2008-02-09 00:12 ——— d—–w C:\Program Files\Common Files\Real
2008-02-06 16:57 ——— d—–w C:\Documents and Settings\Main\Application Data\Intuit
2008-02-02 18:15 ——— d—–w C:\Program Files\TurboTax
2008-01-30 21:58 ——— d—–w C:\Program Files\Fx Splitter
2008-01-27 20:05 94,208 —-a-w C:\WINDOWS\DIIUnin.exe
2008-01-24 23:17 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-12-21 14:39 10,752 —-a-w C:\WINDOWS\system32\WhoisCL.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe" [ ]
"AOL Fast Start"="C:\America Online 9.0\AOL.exe" [2005-07-12 05:17 50776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="C:\Program Files\Common Files\AOL\1156876735\ee\AOLSoftware.exe" [2006-09-25 19:52 50736]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 07:50 71216]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" [2008-01-27 15:05 532480]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-17 21:10 339968]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"C:\\Program Files\\Common Files\\AOL\\1156876735\\EE\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\Common Files\\AOL\\1156876735\\EE\\aolsoftware.exe"=
"C:\\WINDOWS\\explorer.exe"=


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7f1a4172-349c-11db-97c6-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe

*Newly Created Service* - ATWPKT2
.
Contents of the 'Scheduled Tasks' folder
"2008-01-24 23:25:24 C:\WINDOWS\Tasks\RegClean Scheduled Scan.job"
- C:\Program Files\RegClean\RegClean.ex
- C:\Program Files\RegClean
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-25 16:53:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-25 16:54:10
ComboFix-quarantined-files.txt 2008-02-25 21:54:01
.
2008-02-24 16:58:03 — E O F —

_______________________________________________________________________________

Logfile of HijackThis v1.99.1
Scan saved at 5:07:51 PM, on 2/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\AOL\1156876735\ee\AOLSoftware.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\America Online 9.0\waol.exe
C:\America Online 9.0\shellmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1156876735\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\America Online 9.0\AOL.EXE" -b
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1201971963921
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D78EC274-DE04-4BD8-BF64-571900AE1895}: NameServer = 205.188.146.145
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
Open notepad and copy/paste the text in the codebox below into it:

File::
C:\WINDOWS\system32\REN13E.tmp
C:\WINDOWS\system32\REN13D.tmp
C:\WINDOWS\SET46.tmp
C:\WINDOWS\SET43.tmp
C:\WINDOWS\SET54.tmp

Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.
ComboFix 08-02-25 - Main 2008-02-26 18:34:34.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.741 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Main\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-26 to 2008-02-26 )))))))))))))))))))))))))))))))
.

2008-02-23 19:44 . 2008-02-23 19:44 d——– C:\WINDOWS\ERUNT
2008-02-23 19:33 . 2008-02-23 20:11 d——– C:\SDFix
2008-02-23 05:55 . 2008-02-24 09:26 d——– C:\WINDOWS\system32\ActiveScan
2008-02-23 05:55 . 2008-02-24 06:34 30,590 –a—— C:\WINDOWS\system32\pavas.ico
2008-02-22 14:28 . 2008-02-22 16:02 d——– C:\Program Files\EsetOnlineScanner
2008-02-22 07:52 . 2008-02-22 07:52 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-22 07:52 . 2008-02-22 07:52 d——– C:\Documents and Settings\Main\Application Data\Malwarebytes
2008-02-22 07:52 . 2008-02-22 07:52 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-22 04:25 . 2008-02-22 04:25 0 –a—— C:\WINDOWS\system32\REN13E.tmp
2008-02-22 04:25 . 2008-02-22 04:25 0 –a—— C:\WINDOWS\system32\REN13D.tmp
2008-02-20 19:51 . 2004-08-04 07:00 113,222 –a–c— C:\WINDOWS\system32\dllcache\zoneclim.dll
2008-02-20 19:51 . 2004-08-04 07:00 41,029 –a–c— C:\WINDOWS\system32\dllcache\zcorem.dll
2008-02-20 19:51 . 2004-08-04 07:00 36,937 –a–c— C:\WINDOWS\system32\dllcache\zclientm.exe
2008-02-20 19:51 . 2004-08-04 07:00 29,760 –a–c— C:\WINDOWS\system32\dllcache\znetm.dll
2008-02-20 19:51 . 2004-08-04 07:00 13,894 –a–c— C:\WINDOWS\system32\dllcache\zonelibm.dll
2008-02-20 19:51 . 2004-08-04 07:00 4,677 –a–c— C:\WINDOWS\system32\dllcache\zeeverm.dll
2008-02-20 19:49 . 2004-08-04 07:00 13,463,552 –a–c— C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-02-20 19:48 . 2004-08-04 07:00 1,817,687 –a–c— C:\WINDOWS\system32\dllcache\bckgres.dll
2008-02-20 19:47 . 2008-02-20 19:47 488 -rah—– C:\WINDOWS\system32\logonui.exe.manifest
2008-02-20 19:46 . 2008-02-20 19:46 749 -rah—– C:\WINDOWS\WindowsShell.Manifest
2008-02-20 19:46 . 2008-02-20 19:46 749 -rah—– C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-02-20 19:46 . 2008-02-20 19:46 749 -rah—– C:\WINDOWS\system32\sapi.cpl.manifest
2008-02-20 19:46 . 2008-02-20 19:46 749 -rah—– C:\WINDOWS\system32\ncpa.cpl.manifest
2008-02-20 12:33 . 2008-02-20 12:33 22 –a—— C:\WINDOWS\system32\ati64hlp.stb
2008-02-20 11:53 . 2008-02-24 06:34 2,550 –a—— C:\WINDOWS\system32\Uninstall.ico
2008-02-20 11:53 . 2008-02-24 06:34 1,406 –a—— C:\WINDOWS\system32\Help.ico
2008-02-20 11:31 . 2008-02-20 11:31 22 –a—— C:\WINDOWS\system32\ati64hl2.stb
2008-02-20 11:27 . 2008-02-20 11:27 497 –a—— C:\WINDOWS\Ascd_tmp.ini
2008-02-20 11:16 . 2008-02-22 04:21 d——– C:\Program Files\ATI Technologies
2008-02-20 11:16 . 2004-07-17 21:10 516,096 –a—— C:\WINDOWS\system32\ati2sgag.exe
2008-02-20 11:16 . 2004-07-17 23:17 294,912 -ra—— C:\WINDOWS\system32\atiiiexx.dll
2008-02-20 11:16 . 2004-07-17 22:55 135,168 -ra—— C:\WINDOWS\system32\ATIDEMGR.dll
2008-02-18 16:01 . 2008-02-18 16:05 d——– C:\WINDOWS\SxsCaPendDel
2008-02-18 15:58 . 2004-08-04 00:56 870,784 –a—— C:\WINDOWS\system32\ati3d1ag.dll
2008-02-18 15:58 . 2004-08-04 00:56 32,768 –a—— C:\WINDOWS\system32\ativtmxx.dll
2008-02-18 15:58 . 2004-08-04 00:56 23,040 –a—— C:\WINDOWS\system32\ativmvxx.ax
2008-02-18 15:55 . 2008-02-22 04:21 10 –a—— C:\WINDOWS\WININIT.INI
2008-02-18 15:25 . 2004-08-04 07:00 380,416 –a–c— C:\WINDOWS\system32\dllcache\rstrui.exe
2008-02-18 15:25 . 2004-08-04 07:00 93,184 –a-sc— C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-18 15:25 . 2004-08-04 07:00 60,416 –a-sc— C:\WINDOWS\system32\dllcache\msimn.exe
2008-02-18 15:23 . 2004-08-04 07:00 218,112 –a–c— C:\WINDOWS\system32\dllcache\wmiprvse.exe
2008-02-18 15:15 . 2004-08-04 07:00 1,086,058 -ra—— C:\WINDOWS\SET46.tmp
2008-02-18 15:15 . 2004-08-04 07:00 1,042,903 -ra—— C:\WINDOWS\SET43.tmp
2008-02-18 15:15 . 2004-08-04 07:00 13,753 -ra—— C:\WINDOWS\SET54.tmp
2008-02-14 18:00 . 2008-02-14 18:04 d——– C:\Documents and Settings\Main\DoctorWeb
2008-02-11 19:57 . 2008-02-11 19:57 205 –a—— C:\~TaxUnin.bat
2008-02-11 13:21 . 2008-02-11 13:21 d——– C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-02-11 09:40 . 2008-02-11 09:40 2,715,648 –a—— C:\WINDOWS\system32\OnlineScanner.ocx
2008-02-11 09:39 . 2008-02-11 09:39 253,952 –a—— C:\WINDOWS\system32\OnlineScannerDLLA.dll
2008-02-11 09:39 . 2008-02-11 09:39 237,568 –a—— C:\WINDOWS\system32\OnlineScannerDLLW.dll
2008-02-09 22:41 . 2004-08-04 07:00 1,086,058 -ra—— C:\WINDOWS\SET42.tmp
2008-02-09 22:41 . 2004-08-04 07:00 1,042,903 -ra—— C:\WINDOWS\SET3F.tmp
2008-02-09 22:41 . 2004-08-04 07:00 13,753 -ra—— C:\WINDOWS\SET4F.tmp
2008-02-09 22:28 . 2008-02-09 22:28 d——– C:\WINDOWS\system32\FxsTmp
2008-02-09 22:26 . 2004-08-04 07:00 562,176 –a—— C:\WINDOWS\system32\fxsst.dll
2008-02-09 09:21 . 2008-02-09 09:21 d——– C:\Documents and Settings\Main\Application Data\Simple Star
2008-02-09 09:21 . 2004-07-13 15:47 421,888 –a—— C:\WINDOWS\Nero PhotoShow.scr
2008-02-09 09:08 . 2008-02-20 11:11 d——– C:\Documents and Settings\Main\Application Data\Ahead
2008-02-09 09:07 . 2008-02-09 09:07 d——– C:\WINDOWS\InCD
2008-02-09 09:07 . 2004-11-26 08:44 2,461,696 –a—— C:\WINDOWS\UNMRW.exe
2008-02-09 09:07 . 2004-11-26 13:36 98,176 –a—— C:\WINDOWS\system32\drivers\InCDfs.sys
2008-02-09 09:07 . 2005-01-05 05:12 55,606 –a—— C:\WINDOWS\UNMRW.cfg
2008-02-09 09:07 . 2004-11-26 13:36 28,928 –a—— C:\WINDOWS\system32\drivers\InCDpass.sys
2008-02-09 09:07 . 2004-11-26 07:36 27,648 ——— C:\WINDOWS\system32\drivers\InCDrm.sys
2008-02-09 09:07 . 2004-11-26 13:36 7,808 –a—— C:\WINDOWS\system32\drivers\InCDrec.sys
2008-02-09 09:04 . 2008-02-22 04:31 d——– C:\Program Files\Common Files\Ahead
2008-02-09 09:04 . 2008-02-22 04:31 d——– C:\Program Files\Ahead
2008-02-09 09:04 . 2008-02-09 09:04 d——– C:\Documents and Settings\All Users\Application Data\Ahead
2008-02-09 09:04 . 2001-03-08 18:30 24,064 ——— C:\WINDOWS\system32\msxml3a.dll
2008-02-08 19:07 . 2008-02-08 19:07 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-08 19:07 . 2008-02-08 19:07 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-08 13:53 . 2008-02-08 13:53 110,592 –a—— C:\WINDOWS\system32\OnlineScannerLang.dll
2008-02-05 09:29 . 2004-08-04 07:00 1,086,058 -ra—— C:\WINDOWS\SET41.tmp
2008-02-05 09:29 . 2004-08-04 07:00 1,042,903 -ra—— C:\WINDOWS\SET3E.tmp
2008-02-05 09:29 . 2004-08-04 07:00 13,753 -ra—— C:\WINDOWS\SET4E.tmp
2008-02-05 08:48 . 2008-02-05 08:48 77,824 –a—— C:\WINDOWS\system32\OnlineScannerUninstaller.exe
2008-02-04 08:53 . 2008-02-04 08:53 d——– C:\Documents and Settings\Main\Application Data\ATI
2008-02-04 08:52 . 2008-02-04 08:52 0 –a—— C:\WINDOWS\ativpsrm.bin
2008-02-02 22:15 . 2008-02-02 22:15 d——– C:\ATI
2008-02-02 11:52 . 2008-02-02 11:52 393,216 –a—— C:\WINDOWS\system32\LOGONUI.000
2008-01-29 07:59 . 2004-08-04 07:00 1,086,058 -ra—— C:\WINDOWS\SET50.tmp
2008-01-29 07:59 . 2004-08-04 07:00 1,042,903 -ra—— C:\WINDOWS\SET4D.tmp
2008-01-29 07:59 . 2004-08-04 07:00 13,753 -ra—— C:\WINDOWS\SET5C.tmp
2008-01-26 19:51 . 2008-02-11 13:16 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-26 19:46 . 2008-01-26 19:46 d——– C:\Program Files\Common Files\PC Tools

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-24 14:20 ——— d—–w C:\Program Files\Common Files\aolshare
2008-02-22 10:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-22 09:24 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-22 09:23 ——— d—–w C:\Program Files\msaccrt
2008-02-22 09:23 ——— d—–w C:\Program Files\ATI Multimedia
2008-02-22 09:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\ATI MMC
2008-02-12 00:57 205 —-a-w C:\~TaxUnin.bat
2008-02-12 00:57 ——— d—–w C:\Program Files\Common Files\Intuit
2008-02-10 13:32 ——— d—–w C:\Program Files\Google
2008-02-10 13:31 ——— d—–w C:\Program Files\Puppy Luv
2008-02-10 13:30 ——— d—–w C:\Program Files\Picasa2
2008-02-10 13:29 ——— d—–w C:\Program Files\IrfanView
2008-02-10 13:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\PureEdge
2008-02-10 13:26 ——— d—–w C:\Program Files\ASUS
2008-02-10 12:54 ——— d—–w C:\Program Files\INSTAFINK
2008-02-10 12:49 42,496 —-a-w C:\WINDOWS\UniFish3.exe
2008-02-10 12:48 138,752 —-a-w C:\WINDOWS\system32\sndvol32.exe.tmp
2008-02-10 12:46 114,688 —-a-w C:\WINDOWS\system32\calc.exe.tmp
2008-02-10 12:42 60,416 —-a-w C:\WINDOWS\ALCFDRTM.EXE
2008-02-10 04:40 176,128 —-a-r C:\WINDOWS\system32\nvusmb.exe
2008-02-09 00:12 ——— d—–w C:\Program Files\QuickTime
2008-02-09 00:12 ——— d—–w C:\Program Files\Common Files\Real
2008-02-06 16:57 ——— d—–w C:\Documents and Settings\Main\Application Data\Intuit
2008-02-02 18:15 ——— d—–w C:\Program Files\TurboTax
2008-01-30 21:58 ——— d—–w C:\Program Files\Fx Splitter
2008-01-27 20:05 94,208 —-a-w C:\WINDOWS\DIIUnin.exe
2008-01-24 23:17 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-12-21 14:39 10,752 —-a-w C:\WINDOWS\system32\WhoisCL.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe" [ ]
"AOL Fast Start"="C:\America Online 9.0\AOL.exe" [2005-07-12 05:17 50776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="C:\Program Files\Common Files\AOL\1156876735\ee\AOLSoftware.exe" [2006-09-25 19:52 50736]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 07:50 71216]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" [2008-01-27 15:05 532480]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-17 21:10 339968]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"C:\\Program Files\\Common Files\\AOL\\1156876735\\EE\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\Common Files\\AOL\\1156876735\\EE\\aolsoftware.exe"=
"C:\\WINDOWS\\explorer.exe"=


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7f1a4172-349c-11db-97c6-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-01-24 23:25:24 C:\WINDOWS\Tasks\RegClean Scheduled Scan.job"
- C:\Program Files\RegClean\RegClean.ex
- C:\Program Files\RegClean
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 18:35:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-26 18:36:01
ComboFix-quarantined-files.txt 2008-02-26 23:35:53
ComboFix2.txt 2008-02-25 21:54:11
.
2008-02-26 23:24:04 — E O F —

______________________________________________________________________________

Logfile of HijackThis v1.99.1
Scan saved at 6:45:36 PM, on 2/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\AOL\1156876735\ee\AOLSoftware.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\America Online 9.0\waol.exe
C:\WINDOWS\system32\wscntfy.exe
C:\America Online 9.0\shellmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1156876735\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\America Online 9.0\AOL.EXE" -b
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1201971963921
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D78EC274-DE04-4BD8-BF64-571900AE1895}: NameServer = 205.188.146.145
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
Doesn't look like it was done right can you try it again

Open notepad and copy/paste the text in the codebox below into it:

File::
C:\WINDOWS\system32\REN13E.tmp
C:\WINDOWS\system32\REN13D.tmp
C:\WINDOWS\SET46.tmp
C:\WINDOWS\SET43.tmp
C:\WINDOWS\SET54.tmp

Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.

ComboFix 08-02-25 - Main 2008-02-27 5:51:48.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.766 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Main\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-27 to 2008-02-27 )))))))))))))))))))))))))))))))
.

2008-02-27 05:47 . 2008-02-27 05:47 d——– C:\WINDOWS\LastGood
2008-02-23 19:44 . 2008-02-23 19:44 d——– C:\WINDOWS\ERUNT
2008-02-23 19:33 . 2008-02-23 20:11 d——– C:\SDFix
2008-02-23 05:55 . 2008-02-24 09:26 d——– C:\WINDOWS\system32\ActiveScan
2008-02-23 05:55 . 2008-02-24 06:34 30,590 –a—— C:\WINDOWS\system32\pavas.ico
2008-02-22 14:28 . 2008-02-22 16:02 d——– C:\Program Files\EsetOnlineScanner
2008-02-22 07:52 . 2008-02-22 07:52 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-22 07:52 . 2008-02-22 07:52 d——– C:\Documents and Settings\Main\Application Data\Malwarebytes
2008-02-22 07:52 . 2008-02-22 07:52 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-22 04:25 . 2008-02-22 04:25 0 –a—— C:\WINDOWS\system32\REN13E.tmp
2008-02-22 04:25 . 2008-02-22 04:25 0 –a—— C:\WINDOWS\system32\REN13D.tmp
2008-02-20 19:51 . 2004-08-04 07:00 113,222 –a–c— C:\WINDOWS\system32\dllcache\zoneclim.dll
2008-02-20 19:51 . 2004-08-04 07:00 41,029 –a–c— C:\WINDOWS\system32\dllcache\zcorem.dll
2008-02-20 19:51 . 2004-08-04 07:00 36,937 –a–c— C:\WINDOWS\system32\dllcache\zclientm.exe
2008-02-20 19:51 . 2004-08-04 07:00 29,760 –a–c— C:\WINDOWS\system32\dllcache\znetm.dll
2008-02-20 19:51 . 2004-08-04 07:00 13,894 –a–c— C:\WINDOWS\system32\dllcache\zonelibm.dll
2008-02-20 19:51 . 2004-08-04 07:00 4,677 –a–c— C:\WINDOWS\system32\dllcache\zeeverm.dll
2008-02-20 19:49 . 2004-08-04 07:00 13,463,552 –a–c— C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-02-20 19:48 . 2004-08-04 07:00 1,817,687 –a–c— C:\WINDOWS\system32\dllcache\bckgres.dll
2008-02-20 19:47 . 2008-02-20 19:47 488 -rah—– C:\WINDOWS\system32\logonui.exe.manifest
2008-02-20 19:46 . 2008-02-20 19:46 749 -rah—– C:\WINDOWS\WindowsShell.Manifest
2008-02-20 19:46 . 2008-02-20 19:46 749 -rah—– C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-02-20 19:46 . 2008-02-20 19:46 749 -rah—– C:\WINDOWS\system32\sapi.cpl.manifest
2008-02-20 19:46 . 2008-02-20 19:46 749 -rah—– C:\WINDOWS\system32\ncpa.cpl.manifest
2008-02-20 12:33 . 2008-02-20 12:33 22 –a—— C:\WINDOWS\system32\ati64hlp.stb
2008-02-20 11:53 . 2008-02-24 06:34 2,550 –a—— C:\WINDOWS\system32\Uninstall.ico
2008-02-20 11:53 . 2008-02-24 06:34 1,406 –a—— C:\WINDOWS\system32\Help.ico
2008-02-20 11:31 . 2008-02-20 11:31 22 –a—— C:\WINDOWS\system32\ati64hl2.stb
2008-02-20 11:27 . 2008-02-20 11:27 497 –a—— C:\WINDOWS\Ascd_tmp.ini
2008-02-20 11:16 . 2008-02-22 04:21 d——– C:\Program Files\ATI Technologies
2008-02-20 11:16 . 2004-07-17 21:10 516,096 –a—— C:\WINDOWS\system32\ati2sgag.exe
2008-02-20 11:16 . 2004-07-17 23:17 294,912 -ra—— C:\WINDOWS\system32\atiiiexx.dll
2008-02-20 11:16 . 2004-07-17 22:55 135,168 -ra—— C:\WINDOWS\system32\ATIDEMGR.dll
2008-02-18 16:01 . 2008-02-18 16:05 d——– C:\WINDOWS\SxsCaPendDel
2008-02-18 15:58 . 2004-08-04 00:56 870,784 –a—— C:\WINDOWS\system32\ati3d1ag.dll
2008-02-18 15:58 . 2004-08-04 00:56 32,768 –a—— C:\WINDOWS\system32\ativtmxx.dll
2008-02-18 15:58 . 2004-08-04 00:56 23,040 –a—— C:\WINDOWS\system32\ativmvxx.ax
2008-02-18 15:55 . 2008-02-22 04:21 10 –a—— C:\WINDOWS\WININIT.INI
2008-02-18 15:25 . 2004-08-04 07:00 380,416 –a–c— C:\WINDOWS\system32\dllcache\rstrui.exe
2008-02-18 15:25 . 2004-08-04 07:00 93,184 –a-sc— C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-18 15:25 . 2004-08-04 07:00 60,416 –a-sc— C:\WINDOWS\system32\dllcache\msimn.exe
2008-02-18 15:23 . 2004-08-04 07:00 218,112 –a–c— C:\WINDOWS\system32\dllcache\wmiprvse.exe
2008-02-18 15:15 . 2004-08-04 07:00 1,086,058 -ra—— C:\WINDOWS\SET46.tmp
2008-02-18 15:15 . 2004-08-04 07:00 1,042,903 -ra—— C:\WINDOWS\SET43.tmp
2008-02-18 15:15 . 2004-08-04 07:00 13,753 -ra—— C:\WINDOWS\SET54.tmp
2008-02-14 18:00 . 2008-02-14 18:04 d——– C:\Documents and Settings\Main\DoctorWeb
2008-02-11 19:57 . 2008-02-11 19:57 205 –a—— C:\~TaxUnin.bat
2008-02-11 13:21 . 2008-02-11 13:21 d——– C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-02-11 09:40 . 2008-02-11 09:40 2,715,648 –a—— C:\WINDOWS\system32\OnlineScanner.ocx
2008-02-11 09:39 . 2008-02-11 09:39 253,952 –a—— C:\WINDOWS\system32\OnlineScannerDLLA.dll
2008-02-11 09:39 . 2008-02-11 09:39 237,568 –a—— C:\WINDOWS\system32\OnlineScannerDLLW.dll
2008-02-09 22:41 . 2004-08-04 07:00 1,086,058 -ra—— C:\WINDOWS\SET42.tmp
2008-02-09 22:41 . 2004-08-04 07:00 1,042,903 -ra—— C:\WINDOWS\SET3F.tmp
2008-02-09 22:41 . 2004-08-04 07:00 13,753 -ra—— C:\WINDOWS\SET4F.tmp
2008-02-09 22:28 . 2008-02-09 22:28 d——– C:\WINDOWS\system32\FxsTmp
2008-02-09 22:26 . 2004-08-04 07:00 562,176 –a—— C:\WINDOWS\system32\fxsst.dll
2008-02-09 09:21 . 2008-02-09 09:21 d——– C:\Documents and Settings\Main\Application Data\Simple Star
2008-02-09 09:21 . 2004-07-13 15:47 421,888 –a—— C:\WINDOWS\Nero PhotoShow.scr
2008-02-09 09:08 . 2008-02-20 11:11 d——– C:\Documents and Settings\Main\Application Data\Ahead
2008-02-09 09:07 . 2008-02-09 09:07 d——– C:\WINDOWS\InCD
2008-02-09 09:07 . 2004-11-26 08:44 2,461,696 –a—— C:\WINDOWS\UNMRW.exe
2008-02-09 09:07 . 2004-11-26 13:36 98,176 –a—— C:\WINDOWS\system32\drivers\InCDfs.sys
2008-02-09 09:07 . 2005-01-05 05:12 55,606 –a—— C:\WINDOWS\UNMRW.cfg
2008-02-09 09:07 . 2004-11-26 13:36 28,928 –a—— C:\WINDOWS\system32\drivers\InCDpass.sys
2008-02-09 09:07 . 2004-11-26 07:36 27,648 ——— C:\WINDOWS\system32\drivers\InCDrm.sys
2008-02-09 09:07 . 2004-11-26 13:36 7,808 –a—— C:\WINDOWS\system32\drivers\InCDrec.sys
2008-02-09 09:04 . 2008-02-22 04:31 d——– C:\Program Files\Common Files\Ahead
2008-02-09 09:04 . 2008-02-22 04:31 d——– C:\Program Files\Ahead
2008-02-09 09:04 . 2008-02-09 09:04 d——– C:\Documents and Settings\All Users\Application Data\Ahead
2008-02-09 09:04 . 2001-03-08 18:30 24,064 ——— C:\WINDOWS\system32\msxml3a.dll
2008-02-08 19:07 . 2008-02-08 19:07 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-08 19:07 . 2008-02-08 19:07 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-08 13:53 . 2008-02-08 13:53 110,592 –a—— C:\WINDOWS\system32\OnlineScannerLang.dll
2008-02-05 09:29 . 2004-08-04 07:00 1,086,058 -ra—— C:\WINDOWS\SET41.tmp
2008-02-05 09:29 . 2004-08-04 07:00 1,042,903 -ra—— C:\WINDOWS\SET3E.tmp
2008-02-05 09:29 . 2004-08-04 07:00 13,753 -ra—— C:\WINDOWS\SET4E.tmp
2008-02-05 08:48 . 2008-02-05 08:48 77,824 –a—— C:\WINDOWS\system32\OnlineScannerUninstaller.exe
2008-02-04 08:53 . 2008-02-04 08:53 d——– C:\Documents and Settings\Main\Application Data\ATI
2008-02-04 08:52 . 2008-02-04 08:52 0 –a—— C:\WINDOWS\ativpsrm.bin
2008-02-02 22:15 . 2008-02-02 22:15 d——– C:\ATI
2008-02-02 11:52 . 2008-02-02 11:52 393,216 –a—— C:\WINDOWS\system32\LOGONUI.000
2008-01-29 07:59 . 2004-08-04 07:00 1,086,058 -ra—— C:\WINDOWS\SET50.tmp
2008-01-29 07:59 . 2004-08-04 07:00 1,042,903 -ra—— C:\WINDOWS\SET4D.tmp
2008-01-29 07:59 . 2004-08-04 07:00 13,753 -ra—— C:\WINDOWS\SET5C.tmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-24 14:20 ——— d—–w C:\Program Files\Common Files\aolshare
2008-02-22 10:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-22 09:24 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-22 09:23 ——— d—–w C:\Program Files\msaccrt
2008-02-22 09:23 ——— d—–w C:\Program Files\ATI Multimedia
2008-02-22 09:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\ATI MMC
2008-02-12 00:57 205 —-a-w C:\~TaxUnin.bat
2008-02-12 00:57 ——— d—–w C:\Program Files\Common Files\Intuit
2008-02-11 18:16 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-10 13:32 ——— d—–w C:\Program Files\Google
2008-02-10 13:31 ——— d—–w C:\Program Files\Puppy Luv
2008-02-10 13:30 ——— d—–w C:\Program Files\Picasa2
2008-02-10 13:29 ——— d—–w C:\Program Files\IrfanView
2008-02-10 13:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\PureEdge
2008-02-10 13:26 ——— d—–w C:\Program Files\ASUS
2008-02-10 12:54 ——— d—–w C:\Program Files\INSTAFINK
2008-02-10 12:49 42,496 —-a-w C:\WINDOWS\UniFish3.exe
2008-02-10 12:48 138,752 —-a-w C:\WINDOWS\system32\sndvol32.exe.tmp
2008-02-10 12:46 114,688 —-a-w C:\WINDOWS\system32\calc.exe.tmp
2008-02-10 12:42 60,416 —-a-w C:\WINDOWS\ALCFDRTM.EXE
2008-02-10 04:40 176,128 —-a-r C:\WINDOWS\system32\nvusmb.exe
2008-02-09 00:12 ——— d—–w C:\Program Files\QuickTime
2008-02-09 00:12 ——— d—–w C:\Program Files\Common Files\Real
2008-02-06 16:57 ——— d—–w C:\Documents and Settings\Main\Application Data\Intuit
2008-02-02 18:15 ——— d—–w C:\Program Files\TurboTax
2008-01-30 21:58 ——— d—–w C:\Program Files\Fx Splitter
2008-01-27 20:05 94,208 —-a-w C:\WINDOWS\DIIUnin.exe
2008-01-27 00:46 ——— d—–w C:\Program Files\Common Files\PC Tools
2008-01-24 23:17 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-12-21 14:39 10,752 —-a-w C:\WINDOWS\system32\WhoisCL.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe" [ ]
"AOL Fast Start"="C:\America Online 9.0\AOL.exe" [2005-07-12 05:17 50776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="C:\Program Files\Common Files\AOL\1156876735\ee\AOLSoftware.exe" [2006-09-25 19:52 50736]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 07:50 71216]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" [2008-01-27 15:05 532480]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-17 21:10 339968]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"C:\\Program Files\\Common Files\\AOL\\1156876735\\EE\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\Common Files\\AOL\\1156876735\\EE\\aolsoftware.exe"=
"C:\\WINDOWS\\explorer.exe"=


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7f1a4172-349c-11db-97c6-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-01-24 23:25:24 C:\WINDOWS\Tasks\RegClean Scheduled Scan.job"
- C:\Program Files\RegClean\RegClean.ex
- C:\Program Files\RegClean
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-27 05:52:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-27 5:53:15
ComboFix-quarantined-files.txt 2008-02-27 10:53:07
ComboFix2.txt 2008-02-26 23:36:01
ComboFix3.txt 2008-02-25 21:54:11
.
2008-02-27 10:48:16 — E O F —


Logfile of HijackThis v1.99.1
Scan saved at 6:04:03 AM, on 2/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\AOL\1156876735\ee\AOLSoftware.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\America Online 9.0\waol.exe
C:\America Online 9.0\shellmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1156876735\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\America Online 9.0\AOL.EXE" -b
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1201971963921
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D78EC274-DE04-4BD8-BF64-571900AE1895}: NameServer = 205.188.146.145
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
Run this online scan from ESET

You will need to use Internet explorer for this scan!
  • First, accept the Terms of Use
  • Click: Start
  • When asked, allow the ActiveX control to install
  • Click: Start
  • Make sure the options:
    Remove found threats, and Scan unwanted applications
    are both checked!
  • Click: Scan

When the scan finishes, use Notepad to open the ESET report.
It will be located here C:\Program Files\EsetOnlineScanner\log.txt
# version=4 # OnlineScanner.ocx=1.0.0.635 # OnlineScannerDLLA.dll=1, 0, 0, 79 # OnlineScannerDLLW.dll=1, 0, 0, 78 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=2903 (20080226) # vers_arch_module=1.064 (20080214) # vers_adv_heur_module=1.064 (20070717) # EOSSerial=04cd7b2662ddcf488ac3735d19844a77 # end=finished # remove_checked=true # unwanted_checked=true # utc_time=2008-02-27 10:28:32 # local_time=2008-02-27 05:28:32 (-0500, Eastern Standard Time) # country="United States" # osver=5.1.2600 NT Service Pack 2 # scanned=125329 # found=0 # scan_time=951
It is working a lot faster, but there are still some problems. We have no sound, an error message says: "Windows can't find c:\windows\system32\sndvol.32.exe". We re-installed this from the Windows XP disc, and the error message now says can not find sound mixer. All of the buttons in the control panel/sound device area are working. Any suggestions?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI