This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Baseline

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi There,

Pop-up's are driving me crazy! I've tried every auto removal tool for smitfraud and vundo that I can find.

I have regular pop up's from celldorado, zedo, anti-spyware programs and many others.

Any help very much appreciated.

Paul




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:32:45, on 17/02/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\ATK Hotkey\ASLDRSrv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Windows\System32\ACEngSvr.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\Program Files\Enigma Software Group\SpyHunter\SHService.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\StkCSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\PROGRA~1\Maxtor\MANAGE~1\msssort.exe
C:\PROGRA~1\Maxtor\ONETOU~1\MaxMenuMgr.exe
C:\PROGRA~1\Maxtor\MSSBAC~1\MaxBackService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\SkypeMate\SkypeMate.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\kmd.exe
C:\327882R2FWJFW\swxcacls.cfexe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Telstra BigPond Home Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SHStartup.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Startup: SkypeMate.lnk = C:\Program Files\SkypeMate\SkypeMate.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O13 - Gopher Prefix:
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ss/sa…abs/tgctlsr.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: SpyHunter3 Service - Enigma Software Group, Inc. - C:\Program Files\Enigma Software Group\SpyHunter\SHService.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
Run - ATF Cleaner instructions here.

—————-


Then download Malwarebytes' Anti-Malware to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform FULL SCAN, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Thanks so much Little Eagle!!! That app is fantastic, I had tried so many other Smitfraud removal tools. I take it that I had a smitfraud infection? I was about to format and re-install.. I can't thank you enough!
I spoke a bit soon.. Pop-ups are back :( This file "C:\Windows\System32\drivers\core.cache.dsk " Which I believe is related to Smitfraud keeps coming back, if it's actually being deleted. Any Suggestions? Log file as requested Malwarebytes' Anti-Malware 1.05 Database version: 396 Scan type: Full Scan (C:\|D:\|) Objects scanned: 139616 Time elapsed: 56 minute(s), 0 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Windows\System32\x64 (Trojan.Downloader) -> No action taken. Files Infected: C:\Program Files\WinRAR\UnRAR.exe (Trojan.Downloader) -> No action taken. C:\Windows\System32\drivers\core.cache.dsk (Malware.Trace) -> No action taken.
Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.



1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net


2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review


Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
Hi There Little Eagle,

Thanks again for your help..

Log file for your enjoyment!

ComboFix 08-02-25.3 - Paul 2008-02-26 20:13:43.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1205 [GMT 0:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Windows\system32\drivers\core.cache.dsk
C:\Windows\system32\drivers\dxapii.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DXAPII
——-\dxapii


((((((((((((((((((((((((( Files Created from 2008-01-26 to 2008-02-26 )))))))))))))))))))))))))))))))
.

2008-02-26 19:30 . 2008-02-26 19:30 d——– C:\Program Files\O2blueroom
2008-02-23 12:55 . 2008-02-23 12:55 d——– C:\Users\Paul\AppData\Roaming\Malwarebytes
2008-02-23 12:54 . 2008-02-23 12:54 d——– C:\ProgramData\Malwarebytes
2008-02-23 12:54 . 2008-02-23 12:54 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-19 21:20 . 2008-02-19 21:20 d——– C:\Users\Paul\AppData\Roaming\Ceedo
2008-02-16 19:17 . 2008-02-16 19:17 d——– C:\VundoFix Backups
2008-02-16 19:10 . 2008-02-16 19:12 175,465,324 –a—— C:\SYM_REGISTRY_BACKUP.reg
2008-02-16 10:02 . 2008-01-10 05:50 1,244,672 –a—— C:\Windows\System32\mcmde.dll
2008-02-14 03:14 . 2008-02-14 03:14 194,560 –a—— C:\Windows\System32\WebClnt.dll
2008-02-14 03:14 . 2008-02-14 03:14 110,080 –a—— C:\Windows\System32\drivers\mrxdav.sys
2008-02-14 03:09 . 2008-02-14 03:09 3,504,696 –a—— C:\Windows\System32\ntkrnlpa.exe
2008-02-14 03:09 . 2008-02-14 03:09 3,470,392 –a—— C:\Windows\System32\ntoskrnl.exe
2008-02-14 03:09 . 2008-02-14 03:09 154,624 –a—— C:\Windows\System32\drivers\nwifi.sys
2008-02-14 03:09 . 2008-02-14 03:09 109,624 –a—— C:\Windows\System32\drivers\ataport.sys
2008-02-14 03:09 . 2008-02-14 03:09 45,112 –a—— C:\Windows\System32\drivers\pciidex.sys
2008-02-14 03:09 . 2008-02-14 03:09 21,560 –a—— C:\Windows\System32\drivers\atapi.sys
2008-02-14 03:09 . 2008-02-14 03:09 17,464 –a—— C:\Windows\System32\drivers\intelide.sys
2008-02-14 03:08 . 2008-02-14 03:08 4,247,552 –a—— C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-14 03:08 . 2008-02-14 03:08 1,686,528 –a—— C:\Windows\System32\gameux.dll
2008-02-14 03:08 . 2008-02-14 03:08 803,328 –a—— C:\Windows\System32\drivers\tcpip.sys
2008-02-14 03:08 . 2008-02-14 03:08 216,632 –a—— C:\Windows\System32\drivers\netio.sys
2008-02-14 03:08 . 2008-02-14 03:08 167,424 –a—— C:\Windows\System32\tcpipcfg.dll
2008-02-14 03:08 . 2008-02-14 03:08 24,064 –a—— C:\Windows\System32\netcfg.exe
2008-02-14 03:08 . 2008-02-14 03:08 22,016 –a—— C:\Windows\System32\netiougc.exe
2008-02-10 19:33 . 2008-02-10 19:33 d——– C:\Users\Paul\AppData\Roaming\Grisoft
2008-02-10 19:33 . 2007-05-30 12:10 10,872 –a—— C:\Windows\System32\drivers\AvgAsCln.sys
2008-02-02 16:15 . 2008-02-02 16:15 d——– C:\Users\Paul\AppData\Roaming\PC Tools
2008-02-02 16:15 . 2008-02-26 20:12 d-a—— C:\ProgramData\TEMP
2008-02-02 16:15 . 2008-02-26 13:02 d——– C:\Program Files\Spyware Doctor
2008-02-02 16:15 . 2007-12-10 14:53 81,288 –a—— C:\Windows\System32\drivers\iksyssec.sys
2008-02-02 16:15 . 2007-12-10 14:53 66,952 –a—— C:\Windows\System32\drivers\iksysflt.sys
2008-02-02 16:15 . 2007-12-10 14:53 41,864 –a—— C:\Windows\System32\drivers\ikfilesec.sys
2008-02-02 16:15 . 2007-12-10 14:53 29,576 –a—— C:\Windows\System32\drivers\kcom.sys
2008-02-02 15:46 . 2008-02-10 23:42 3,396 –a—— C:\Windows\System32\tmp.reg
2008-02-01 20:27 . 2008-02-01 20:27 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-02-01 20:26 . 2008-02-02 15:23 d——– C:\Users\Paul\AppData\Roaming\SUPERAntiSpyware.com
2008-02-01 20:26 . 2008-02-02 15:23 d——– C:\Program Files\SUPERAntiSpyware
2008-02-01 20:04 . 2008-02-01 20:04 d——– C:\Program Files\Enigma Software Group
2008-01-27 18:41 . 2008-01-27 18:41 d——– C:\Program Files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-24 23:51 ——— d—–w C:\Program Files\LimeWire
2008-02-24 10:44 ——— d—–w C:\Users\Paul\AppData\Roaming\Skype
2008-02-24 09:47 ——— d—–w C:\Users\Paul\AppData\Roaming\skypePM
2008-02-23 16:13 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-17 21:03 ——— d—–w C:\ProgramData\Spybot - Search & Destroy
2008-02-14 03:12 54,784 —-a-w C:\Windows\system32\drivers\i8042prt.sys
2008-02-14 03:12 495,160 —-a-w C:\Windows\system32\drivers\Wdf01000.sys
2008-02-14 03:12 35,384 —-a-w C:\Windows\system32\drivers\WdfLdr.sys
2008-02-14 03:12 35,384 —-a-w C:\Windows\system32\drivers\kbdclass.sys
2008-02-14 03:12 34,360 —-a-w C:\Windows\system32\drivers\mouclass.sys
2008-02-14 03:12 19,968 —-a-w C:\Windows\system32\drivers\sermouse.sys
2008-02-14 03:12 15,872 —-a-w C:\Windows\system32\drivers\mouhid.sys
2008-02-14 03:08 537,600 —-a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-14 03:08 449,536 —-a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-14 03:08 2,144,256 —-a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-14 03:08 173,056 —-a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 08:00 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-10 19:32 ——— d—–w C:\ProgramData\Grisoft
2008-02-02 15:23 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-26 20:05 ——— d—–w C:\Users\Paul\AppData\Roaming\NewsRover
2008-01-21 05:59 ——— d—–w C:\ProgramData\Lavasoft
2008-01-21 05:56 9,344 —-a-w C:\Windows\system32\drivers\NSDriver.sys
2008-01-21 05:56 8,320 —-a-w C:\Windows\system32\drivers\AWRTRD.sys
2008-01-21 05:42 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-01-21 05:18 ——— d—–w C:\Program Files\TuneUp Utilities 2008
2008-01-21 05:13 ——— d—–w C:\ProgramData\TuneUp Software
2008-01-21 04:53 ——— d—–w C:\Users\Paul\AppData\Roaming\LimeWire
2008-01-20 16:41 ——— d—–w C:\Program Files\iTunes
2008-01-20 16:41 ——— d—–w C:\Program Files\iPod
2008-01-20 16:40 ——— d—–w C:\ProgramData\Apple Computer
2008-01-20 16:38 ——— d—–w C:\Program Files\QuickTime
2008-01-20 08:00 ——— d—–w C:\Program Files\Canon
2008-01-12 03:21 ——— d—–w C:\Users\Paul\AppData\Roaming\Canon
2008-01-12 03:12 ——— d—–w C:\Program Files\CD-LabelPrint
2008-01-12 02:50 ——— d–h–w C:\ProgramData\CanonBJ
2008-01-12 02:48 ——— d–h–w C:\Program Files\CanonBJ
2008-01-09 22:41 ——— d—–w C:\Program Files\ASUS
2008-01-09 22:39 ——— d—–w C:\Program Files\Windows Sidebar
2008-01-09 22:39 ——— d—–w C:\Program Files\Windows Mail
2008-01-09 21:45 211,000 —-a-w C:\Windows\system32\drivers\volsnap.sys
2008-01-09 21:45 1,060,920 —-a-w C:\Windows\system32\drivers\ntfs.sys
2007-12-26 07:22 ——— d—–w C:\Users\Paul\AppData\Roaming\TuneUp Software
2007-12-09 15:56 32 —-a-w C:\ProgramData\ezsid.dat
2007-08-30 02:11 174 –sha-w C:\Program Files\desktop.ini
2007-09-16 13:07 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012007091620070917\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MSSOverlay]
@={b75ab0c8-03d5-4592-9821-a48d54d66b14}

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 21:45 1232896]
"LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-05-15 16:12 484904]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 12:35 125440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-06-16 17:04 1006264]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 11:43 729088]
"ATKMEDIA"="C:\Program Files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 15:27 61440]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-22 05:27 815104]
"PowerForPhone"="C:\Program Files\PowerForPhone\PowerForPhone.exe" [2007-01-15 22:17 778240]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 13:00 79224]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-10-17 22:19 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-10-17 22:18 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-10-17 22:18 133656]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"O2Blueroom"="C:\Program Files\O2blueroom\BlueroomAlerts.exe" [2007-04-11 13:25 1248889]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 14:58 1744896]

C:\Users\Paul\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
SkypeMate.lnk - C:\Program Files\SkypeMate\SkypeMate.exe [2007-03-07 03:56:14 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CollaborationHost"=C:\Windows\system32\p2phost.exe -s

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BigPondWirelessBroadbandCM"="C:\Program Files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe" -tsr
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{58E7A08B-688A-4756-8236-C08005E2B278}C:\program files\skype\phone\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath |Desc=Skype. Take a deep breath
"UDP Query User{45A3FF2E-C530-49EF-9F3F-30F52B4B978B}C:\program files\skype\phone\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath |Desc=Skype. Take a deep breath
"{77A3890E-02CA-499E-BBAD-6401CDFBB84A}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{DCEE901C-97A0-4E9F-993F-A5F44AAF9738}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{487FBAEA-B5A3-4BD2-B52C-4F5999401779}C:\program files\limewire\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire|Desc=LimeWire
"UDP Query User{882DEEF8-2472-4A70-AB18-A1016E2B0B17}C:\program files\limewire\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire|Desc=LimeWire
"{5BE6CC20-7183-42ED-B081-382B3980589B}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"TCP Query User{4DA24F9A-41D5-4C99-95D1-1A544A6666A3}C:\program files\skype\phone\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath |Desc=Skype. Take a deep breath
"UDP Query User{DE9AC63F-D7A5-4490-AED0-ACB7C719C9F0}C:\program files\skype\phone\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath |Desc=Skype. Take a deep breath
"TCP Query User{52B909FA-F46B-45EC-84A6-F14A0A8228A1}C:\program files\internet explorer\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer|Desc=Internet Explorer
"UDP Query User{AC0EE0AC-20F5-46F6-89F7-A563599CEB6C}C:\program files\internet explorer\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer|Desc=Internet Explorer
"TCP Query User{B8AB2071-AE44-4116-A664-C83503E1B3B0}C:\program files\nokia\nokia software updater\nsu_ui_client.exe"= UDP:C:\program files\nokia\nokia software updater\nsu_ui_client.exe:OTI@Home User Interface|Desc=OTI@Home User Interface
"UDP Query User{105AB93C-F306-445F-B3CF-ED253C6DFF54}C:\program files\nokia\nokia software updater\nsu_ui_client.exe"= TCP:C:\program files\nokia\nokia software updater\nsu_ui_client.exe:OTI@Home User Interface|Desc=OTI@Home User Interface
"TCP Query User{9A8916B8-866A-4690-A29A-1DF087645A88}C:\program files\common files\nokia\service layer\nsl_host_process.exe"= UDP:C:\program files\common files\nokia\service layer\nsl_host_process.exe:Nokia Service Layer Host Process |Desc=Nokia Service Layer Host Process
"UDP Query User{6AEF068C-A3BF-4D4C-BD4A-14F21F80DEC3}C:\program files\common files\nokia\service layer\nsl_host_process.exe"= TCP:C:\program files\common files\nokia\service layer\nsl_host_process.exe:Nokia Service Layer Host Process |Desc=Nokia Service Layer Host Process
"TCP Query User{57F6D96A-17BB-4719-8200-FC3595217AFF}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe"= UDP:C:\program files\common files\nokia\service layer\a\nsl_host_process.exe:Nokia Service Layer Host Process |Desc=Nokia Service Layer Host Process
"UDP Query User{6FB15EE8-5DC3-4B0A-96F9-87A4672832A8}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe"= TCP:C:\program files\common files\nokia\service layer\a\nsl_host_process.exe:Nokia Service Layer Host Process |Desc=Nokia Service Layer Host Process
"TCP Query User{1204D6A3-6541-46A9-9B9E-AA2F48FD70AC}C:\program files\maxtor\managerapp\maxutilities.exe"= UDP:C:\program files\maxtor\managerapp\maxutilities.exe:Maxtor EasyManage™|Desc=Maxtor EasyManage™
"UDP Query User{8EDA6626-AC65-42B2-9A02-909A452C0161}C:\program files\maxtor\managerapp\maxutilities.exe"= TCP:C:\program files\maxtor\managerapp\maxutilities.exe:Maxtor EasyManage™|Desc=Maxtor EasyManage™
"{88843DE9-37D4-45B8-8ADD-CD3A36E241A3}"= UDP:C:\UT2004Demo\System\UT2004.exe:UT2004
"{0D99F3D3-2DF5-4595-8F6B-171F6FDB0E86}"= TCP:C:\UT2004Demo\System\UT2004.exe:UT2004
"{F85C4B6B-A449-42D5-95A7-A9B50D6A4289}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{9334C69D-13BF-4358-BE43-1F170B7F807C}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{07A88891-20D4-4502-83F8-617932644453}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{99F66C1E-BC75-47F8-9908-CA7E4736B5C6}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{D502385B-37DF-4770-B0FF-4387F9B3BE4F}C:\program files\yahoo!\messenger\yahoomessenger.exe"= UDP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger|Desc=Yahoo! Messenger
"UDP Query User{71C5D21F-86EE-43B0-8B43-F4DF2134421A}C:\program files\yahoo!\messenger\yahoomessenger.exe"= TCP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger|Desc=Yahoo! Messenger
"{282C548A-D657-4A86-BBC5-4828FDF5AFD6}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{8B2316E4-1343-43EF-A871-F08424E1F915}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{5AC78936-D031-4E90-9846-97C21AA1DA84}C:\program files\maxtor\managerapp\maxutilities.exe"= UDP:C:\program files\maxtor\managerapp\maxutilities.exe:Maxtor EasyManage™|Desc=Maxtor EasyManage™
"UDP Query User{DBD3DA11-0295-4059-A917-AC463107DD75}C:\program files\maxtor\managerapp\maxutilities.exe"= TCP:C:\program files\maxtor\managerapp\maxutilities.exe:Maxtor EasyManage™|Desc=Maxtor EasyManage™
"TCP Query User{ADB64D17-1A6F-4BDD-8C9B-CCDC68406A0A}C:\program files\internet explorer\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer|Desc=Internet Explorer
"UDP Query User{4EDF13DE-5C0F-4208-8ADD-3E06F26FF44B}C:\program files\internet explorer\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer|Desc=Internet Explorer

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-12-04 14:52]
R2 ghaio;ghaio;C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2006-12-28 08:17]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-10-17 22:05]
R3 NETw3v32;Intel® PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-12-19 01:12]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;C:\Windows\system32\Drivers\StkCMini.sys [2006-12-21 18:36]
R3 WCPU;WCPU;C:\Program Files\P4G\WCPU.sys [2007-01-02 22:37]
S3 cmusbnet;WAN Driver @ 3GPP (6280);C:\Windows\system32\DRIVERS\cmusbnet.sys [2007-06-22 10:54]
S3 cmusbser;%CMUSBSER%;C:\Windows\system32\DRIVERS\cmusbser.sys [2006-12-13 19:31]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50.sys [2007-07-13 17:25]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{65764227-1cd5-11dc-a47e-001a92ee2f64}]
\shell\AutoRun\command - .\MigWiz\migsetup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{66e92132-df2e-11dc-a90e-001a92ee2f64}]
\shell\AutoRun\command - F:\Autorun.exe /run
\shell\Shell00\Command - F:\Autorun.exe /run
\shell\Shell01\Command - F:\Autorun.exe /action
\shell\Shell02\Command - F:\Autorun.exe /uninstall


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-01-21 19:26:03 C:\Windows\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
"2008-02-25 20:17:27 C:\Windows\Tasks\User_Feed_Synchronization-{68D8AC64-086B-45E3-9DD9-073ABB34BA5A}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 20:19:20
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\ATK Hotkey\ASLDRSrv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\ACEngSvr.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\Windows\System32\StkCSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\PROGRA~1\Maxtor\MANAGE~1\msssort.exe
C:\PROGRA~1\Maxtor\ONETOU~1\MaxMenuMgr.exe
C:\PROGRA~1\Maxtor\MSSBAC~1\MaxBackService.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-02-26 20:23:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-26 20:23:06
.
2008-02-21 23:29:25 — E O F —
Open notepad and copy/paste the text in the codebox below into it:

Driver::
dxapii

Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.
Thanks again!

It looks like the pop-up's have finally diassapeared!

Latest Log file….

DO I get the all-clear doc??

ComboFix 08-02-25.3 - Paul 2008-03-01 13:22:30.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1138 [GMT 0:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Users\Paul\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-02-01 to 2008-03-01 )))))))))))))))))))))))))))))))
.

2008-02-26 19:30 . 2008-02-26 19:30 d——– C:\Program Files\O2blueroom
2008-02-23 12:55 . 2008-02-23 12:55 d——– C:\Users\Paul\AppData\Roaming\Malwarebytes
2008-02-23 12:54 . 2008-02-23 12:54 d——– C:\ProgramData\Malwarebytes
2008-02-23 12:54 . 2008-02-23 12:54 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-19 21:20 . 2008-02-19 21:20 d——– C:\Users\Paul\AppData\Roaming\Ceedo
2008-02-16 19:17 . 2008-02-16 19:17 d——– C:\VundoFix Backups
2008-02-16 19:10 . 2008-02-16 19:12 175,465,324 –a—— C:\SYM_REGISTRY_BACKUP.reg
2008-02-16 10:02 . 2008-01-10 05:50 1,244,672 –a—— C:\Windows\System32\mcmde.dll
2008-02-14 03:14 . 2008-02-14 03:14 194,560 –a—— C:\Windows\System32\WebClnt.dll
2008-02-14 03:14 . 2008-02-14 03:14 110,080 –a—— C:\Windows\System32\drivers\mrxdav.sys
2008-02-14 03:09 . 2008-02-14 03:09 3,504,696 –a—— C:\Windows\System32\ntkrnlpa.exe
2008-02-14 03:09 . 2008-02-14 03:09 3,470,392 –a—— C:\Windows\System32\ntoskrnl.exe
2008-02-14 03:09 . 2008-02-14 03:09 154,624 –a—— C:\Windows\System32\drivers\nwifi.sys
2008-02-14 03:09 . 2008-02-14 03:09 109,624 –a—— C:\Windows\System32\drivers\ataport.sys
2008-02-14 03:09 . 2008-02-14 03:09 45,112 –a—— C:\Windows\System32\drivers\pciidex.sys
2008-02-14 03:09 . 2008-02-14 03:09 21,560 –a—— C:\Windows\System32\drivers\atapi.sys
2008-02-14 03:09 . 2008-02-14 03:09 17,464 –a—— C:\Windows\System32\drivers\intelide.sys
2008-02-14 03:08 . 2008-02-14 03:08 4,247,552 –a—— C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-14 03:08 . 2008-02-14 03:08 1,686,528 –a—— C:\Windows\System32\gameux.dll
2008-02-14 03:08 . 2008-02-14 03:08 803,328 –a—— C:\Windows\System32\drivers\tcpip.sys
2008-02-14 03:08 . 2008-02-14 03:08 216,632 –a—— C:\Windows\System32\drivers\netio.sys
2008-02-14 03:08 . 2008-02-14 03:08 167,424 –a—— C:\Windows\System32\tcpipcfg.dll
2008-02-14 03:08 . 2008-02-14 03:08 24,064 –a—— C:\Windows\System32\netcfg.exe
2008-02-14 03:08 . 2008-02-14 03:08 22,016 –a—— C:\Windows\System32\netiougc.exe
2008-02-10 19:33 . 2008-02-10 19:33 d——– C:\Users\Paul\AppData\Roaming\Grisoft
2008-02-10 19:33 . 2007-05-30 12:10 10,872 –a—— C:\Windows\System32\drivers\AvgAsCln.sys
2008-02-02 16:15 . 2008-02-02 16:15 d——– C:\Users\Paul\AppData\Roaming\PC Tools
2008-02-02 16:15 . 2008-02-26 20:12 d-a—— C:\ProgramData\TEMP
2008-02-02 16:15 . 2008-02-26 13:02 d——– C:\Program Files\Spyware Doctor
2008-02-02 16:15 . 2007-12-10 14:53 81,288 –a—— C:\Windows\System32\drivers\iksyssec.sys
2008-02-02 16:15 . 2007-12-10 14:53 66,952 –a—— C:\Windows\System32\drivers\iksysflt.sys
2008-02-02 16:15 . 2007-12-10 14:53 41,864 –a—— C:\Windows\System32\drivers\ikfilesec.sys
2008-02-02 16:15 . 2007-12-10 14:53 29,576 –a—— C:\Windows\System32\drivers\kcom.sys
2008-02-02 15:46 . 2008-02-10 23:42 3,396 –a—— C:\Windows\System32\tmp.reg
2008-02-01 20:27 . 2008-02-01 20:27 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-02-01 20:26 . 2008-02-02 15:23 d——– C:\Users\Paul\AppData\Roaming\SUPERAntiSpyware.com
2008-02-01 20:26 . 2008-02-02 15:23 d——– C:\Program Files\SUPERAntiSpyware
2008-02-01 20:04 . 2008-02-01 20:04 d——– C:\Program Files\Enigma Software Group

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-01 12:33 ——— d—–w C:\Users\Paul\AppData\Roaming\Skype
2008-03-01 10:36 ——— d—–w C:\Users\Paul\AppData\Roaming\skypePM
2008-03-01 10:32 45,056 —-a-w C:\Windows\System32\acovcnt.exe
2008-02-24 23:51 ——— d—–w C:\Program Files\LimeWire
2008-02-23 16:13 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-17 21:03 ——— d—–w C:\ProgramData\Spybot - Search & Destroy
2008-02-14 03:08 537,600 —-a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-14 03:08 449,536 —-a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-14 03:08 2,144,256 —-a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-14 03:08 173,056 —-a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 08:00 824,832 —-a-w C:\Windows\System32\wininet.dll
2008-02-13 08:00 56,320 —-a-w C:\Windows\System32\iesetup.dll
2008-02-13 08:00 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-13 08:00 26,624 —-a-w C:\Windows\System32\ieUnatt.exe
2008-02-10 19:32 ——— d—–w C:\ProgramData\Grisoft
2008-02-02 15:23 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-02 00:55 83,456 —-a-w C:\Windows\System32\VACFix.exe
2008-01-27 18:41 ——— d—–w C:\Program Files\Trend Micro
2008-01-27 14:37 81,920 —-a-w C:\Windows\System32\IEDFix.exe
2008-01-26 20:05 ——— d—–w C:\Users\Paul\AppData\Roaming\NewsRover
2008-01-21 05:59 ——— d—–w C:\ProgramData\Lavasoft
2008-01-21 05:56 9,344 —-a-w C:\Windows\system32\drivers\NSDriver.sys
2008-01-21 05:56 8,320 —-a-w C:\Windows\system32\drivers\AWRTRD.sys
2008-01-21 05:56 12,632 —-a-w C:\Windows\System32\lsdelete.exe
2008-01-21 05:42 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-01-21 05:18 ——— d—–w C:\Program Files\TuneUp Utilities 2008
2008-01-21 05:13 306,432 —-a-w C:\Windows\System32\TuneUpDefragService.exe
2008-01-21 05:13 ——— d—–w C:\ProgramData\TuneUp Software
2008-01-21 04:53 ——— d—–w C:\Users\Paul\AppData\Roaming\LimeWire
2008-01-20 16:41 ——— d—–w C:\Program Files\iTunes
2008-01-20 16:41 ——— d—–w C:\Program Files\iPod
2008-01-20 16:40 ——— d—–w C:\ProgramData\Apple Computer
2008-01-20 16:38 ——— d—–w C:\Program Files\QuickTime
2008-01-20 08:00 ——— d—–w C:\Program Files\Canon
2008-01-12 03:21 ——— d—–w C:\Users\Paul\AppData\Roaming\Canon
2008-01-12 03:12 ——— d—–w C:\Program Files\CD-LabelPrint
2008-01-12 02:50 ——— d–h–w C:\ProgramData\CanonBJ
2008-01-12 02:48 ——— d–h–w C:\Program Files\CanonBJ
2008-01-09 22:41 ——— d—–w C:\Program Files\ASUS
2008-01-09 22:39 ——— d—–w C:\Program Files\Windows Sidebar
2008-01-09 22:39 ——— d—–w C:\Program Files\Windows Mail
2008-01-09 21:45 211,000 —-a-w C:\Windows\system32\drivers\volsnap.sys
2008-01-09 21:45 11,776 —-a-w C:\Windows\System32\sbunattend.exe
2008-01-09 21:45 1,060,920 —-a-w C:\Windows\system32\drivers\ntfs.sys
2007-12-20 10:44 16,640 —-a-w C:\Windows\System32\authuitu.dll
2007-12-20 10:41 29,440 —-a-w C:\Windows\System32\uxtuneup.dll
2007-12-12 09:11 9,728 —-a-w C:\Windows\System32\LAPRXY.DLL
2007-12-12 09:11 223,232 —-a-w C:\Windows\System32\WMASF.DLL
2007-12-12 09:11 1,327,104 —-a-w C:\Windows\System32\quartz.dll
2007-12-11 19:46 524,288 —-a-w C:\Windows\System32\DivXsm.exe
2007-12-11 19:46 3,596,288 —-a-w C:\Windows\System32\qt-dx331.dll
2007-12-11 19:45 200,704 —-a-w C:\Windows\System32\ssldivx.dll
2007-12-11 19:45 1,044,480 —-a-w C:\Windows\System32\libdivx.dll
2007-12-11 19:43 12,288 —-a-w C:\Windows\System32\DivXWMPExtType.dll
2007-12-09 15:56 32 —-a-w C:\ProgramData\ezsid.dat
2007-12-04 13:04 837,496 —-a-w C:\Windows\System32\aswBoot.exe
2007-12-04 12:54 95,608 —-a-w C:\Windows\System32\AvastSS.scr
2007-08-30 02:11 174 –sha-w C:\Program Files\desktop.ini
2007-09-16 13:07 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012007091620070917\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MSSOverlay]
@={b75ab0c8-03d5-4592-9821-a48d54d66b14}

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 21:45 1232896]
"LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-05-15 16:12 484904]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 12:35 125440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-06-16 17:04 1006264]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 11:43 729088]
"ATKMEDIA"="C:\Program Files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 15:27 61440]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-22 05:27 815104]
"PowerForPhone"="C:\Program Files\PowerForPhone\PowerForPhone.exe" [2007-01-15 22:17 778240]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 13:00 79224]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-10-17 22:19 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-10-17 22:18 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-10-17 22:18 133656]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"O2Blueroom"="C:\Program Files\O2blueroom\BlueroomAlerts.exe" [2007-04-11 13:25 1248889]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 14:58 1744896]

C:\Users\Paul\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
SkypeMate.lnk - C:\Program Files\SkypeMate\SkypeMate.exe [2007-03-07 03:56:14 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CollaborationHost"=C:\Windows\system32\p2phost.exe -s

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BigPondWirelessBroadbandCM"="C:\Program Files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe" -tsr
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{58E7A08B-688A-4756-8236-C08005E2B278}C:\program files\skype\phone\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath |Desc=Skype. Take a deep breath
"UDP Query User{45A3FF2E-C530-49EF-9F3F-30F52B4B978B}C:\program files\skype\phone\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath |Desc=Skype. Take a deep breath
"{77A3890E-02CA-499E-BBAD-6401CDFBB84A}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{DCEE901C-97A0-4E9F-993F-A5F44AAF9738}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{487FBAEA-B5A3-4BD2-B52C-4F5999401779}C:\program files\limewire\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire|Desc=LimeWire
"UDP Query User{882DEEF8-2472-4A70-AB18-A1016E2B0B17}C:\program files\limewire\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire|Desc=LimeWire
"{5BE6CC20-7183-42ED-B081-382B3980589B}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"TCP Query User{4DA24F9A-41D5-4C99-95D1-1A544A6666A3}C:\program files\skype\phone\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath |Desc=Skype. Take a deep breath
"UDP Query User{DE9AC63F-D7A5-4490-AED0-ACB7C719C9F0}C:\program files\skype\phone\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath |Desc=Skype. Take a deep breath
"TCP Query User{52B909FA-F46B-45EC-84A6-F14A0A8228A1}C:\program files\internet explorer\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer|Desc=Internet Explorer
"UDP Query User{AC0EE0AC-20F5-46F6-89F7-A563599CEB6C}C:\program files\internet explorer\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer|Desc=Internet Explorer
"TCP Query User{B8AB2071-AE44-4116-A664-C83503E1B3B0}C:\program files\nokia\nokia software updater\nsu_ui_client.exe"= UDP:C:\program files\nokia\nokia software updater\nsu_ui_client.exe:OTI@Home User Interface|Desc=OTI@Home User Interface
"UDP Query User{105AB93C-F306-445F-B3CF-ED253C6DFF54}C:\program files\nokia\nokia software updater\nsu_ui_client.exe"= TCP:C:\program files\nokia\nokia software updater\nsu_ui_client.exe:OTI@Home User Interface|Desc=OTI@Home User Interface
"TCP Query User{9A8916B8-866A-4690-A29A-1DF087645A88}C:\program files\common files\nokia\service layer\nsl_host_process.exe"= UDP:C:\program files\common files\nokia\service layer\nsl_host_process.exe:Nokia Service Layer Host Process |Desc=Nokia Service Layer Host Process
"UDP Query User{6AEF068C-A3BF-4D4C-BD4A-14F21F80DEC3}C:\program files\common files\nokia\service layer\nsl_host_process.exe"= TCP:C:\program files\common files\nokia\service layer\nsl_host_process.exe:Nokia Service Layer Host Process |Desc=Nokia Service Layer Host Process
"TCP Query User{57F6D96A-17BB-4719-8200-FC3595217AFF}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe"= UDP:C:\program files\common files\nokia\service layer\a\nsl_host_process.exe:Nokia Service Layer Host Process |Desc=Nokia Service Layer Host Process
"UDP Query User{6FB15EE8-5DC3-4B0A-96F9-87A4672832A8}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe"= TCP:C:\program files\common files\nokia\service layer\a\nsl_host_process.exe:Nokia Service Layer Host Process |Desc=Nokia Service Layer Host Process
"TCP Query User{1204D6A3-6541-46A9-9B9E-AA2F48FD70AC}C:\program files\maxtor\managerapp\maxutilities.exe"= UDP:C:\program files\maxtor\managerapp\maxutilities.exe:Maxtor EasyManage™|Desc=Maxtor EasyManage™
"UDP Query User{8EDA6626-AC65-42B2-9A02-909A452C0161}C:\program files\maxtor\managerapp\maxutilities.exe"= TCP:C:\program files\maxtor\managerapp\maxutilities.exe:Maxtor EasyManage™|Desc=Maxtor EasyManage™
"{88843DE9-37D4-45B8-8ADD-CD3A36E241A3}"= UDP:C:\UT2004Demo\System\UT2004.exe:UT2004
"{0D99F3D3-2DF5-4595-8F6B-171F6FDB0E86}"= TCP:C:\UT2004Demo\System\UT2004.exe:UT2004
"{F85C4B6B-A449-42D5-95A7-A9B50D6A4289}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{9334C69D-13BF-4358-BE43-1F170B7F807C}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{07A88891-20D4-4502-83F8-617932644453}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{99F66C1E-BC75-47F8-9908-CA7E4736B5C6}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{D502385B-37DF-4770-B0FF-4387F9B3BE4F}C:\program files\yahoo!\messenger\yahoomessenger.exe"= UDP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger|Desc=Yahoo! Messenger
"UDP Query User{71C5D21F-86EE-43B0-8B43-F4DF2134421A}C:\program files\yahoo!\messenger\yahoomessenger.exe"= TCP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger|Desc=Yahoo! Messenger
"{282C548A-D657-4A86-BBC5-4828FDF5AFD6}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{8B2316E4-1343-43EF-A871-F08424E1F915}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{5AC78936-D031-4E90-9846-97C21AA1DA84}C:\program files\maxtor\managerapp\maxutilities.exe"= UDP:C:\program files\maxtor\managerapp\maxutilities.exe:Maxtor EasyManage™|Desc=Maxtor EasyManage™
"UDP Query User{DBD3DA11-0295-4059-A917-AC463107DD75}C:\program files\maxtor\managerapp\maxutilities.exe"= TCP:C:\program files\maxtor\managerapp\maxutilities.exe:Maxtor EasyManage™|Desc=Maxtor EasyManage™
"TCP Query User{ADB64D17-1A6F-4BDD-8C9B-CCDC68406A0A}C:\program files\internet explorer\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer|Desc=Internet Explorer
"UDP Query User{4EDF13DE-5C0F-4208-8ADD-3E06F26FF44B}C:\program files\internet explorer\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer|Desc=Internet Explorer

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R2 ASLDRService;ASLDR Service;C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2006-12-20 21:59]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-12-04 14:52]
R2 ghaio;ghaio;C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2006-12-28 08:17]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;C:\Windows\System32\StkCSrv.exe [2006-12-10 16:31]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2006-10-31 21:40]
R2 UxTuneUp;TuneUp Theme Extension;C:\Windows\System32\svchost.exe [2006-11-02 09:45]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-10-17 22:05]
R3 NETw3v32;Intel® PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-12-19 01:12]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;C:\Windows\system32\Drivers\StkCMini.sys [2006-12-21 18:36]
R3 WCPU;WCPU;C:\Program Files\P4G\WCPU.sys [2007-01-02 22:37]
S3 cmusbnet;WAN Driver @ 3GPP (6280);C:\Windows\system32\DRIVERS\cmusbnet.sys [2007-06-22 10:54]
S3 cmusbser;%CMUSBSER%;C:\Windows\system32\DRIVERS\cmusbser.sys [2006-12-13 19:31]
S3 DMService;Whale Component Manager;C:\Windows\DOWNLO~1\CONFLICT.1\DMService.exe [2007-11-18 16:02]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50.sys [2007-07-13 17:25]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\Windows\System32\TuneUpDefragService.exe [2008-01-21 05:13]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{65764227-1cd5-11dc-a47e-001a92ee2f64}]
\shell\AutoRun\command - .\MigWiz\migsetup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{66e92132-df2e-11dc-a90e-001a92ee2f64}]
\shell\AutoRun\command - F:\Autorun.exe /run
\shell\Shell00\Command - F:\Autorun.exe /run
\shell\Shell01\Command - F:\Autorun.exe /action
\shell\Shell02\Command - F:\Autorun.exe /uninstall


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-01-21 19:26:03 C:\Windows\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
"2008-03-01 10:49:16 C:\Windows\Tasks\User_Feed_Synchronization-{68D8AC64-086B-45E3-9DD9-073ABB34BA5A}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-01 13:24:28
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-01 13:25:52
ComboFix-quarantined-files.txt 2008-03-01 13:25:46
ComboFix2.txt 2008-02-26 20:23:20
.
2008-02-28 21:57:48 — E O F —
Click HERE to run Panda's ActiveScan

* You need to use IE to run this scan
* Once you are on the Panda site click the Scan your PC button
* A new window will open…click the Check Now button
* Enter your Country
* Enter your State/Province
* Enter your e-mail address and click send
* Select either Home User or Company
* Click the big Scan Now button
* If it wants to install an ActiveX component allow it
* It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
* When download is complete, click on My Computer to start the scan
* When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI