This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] bitsprx.dll

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have the file bitsprx.dll trojan. AVG won't remove it, combofix didn't find it, and hijackthis won't remove it. I have quarantined it several times, it keeps coming back. Also, my cd drives have lost their drivers about the time this started popping up. My physical drive, my nero virtual drive, and the alcohol drives all say their drivers are corrupted or lost, and they won't recognize new ones. I don't know if it is related, but whatever.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:53:27 PM, on 2/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Parental Control\ParentalControl.Exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSI\Common\RaUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\RegistrySmart\RegistrySmart.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = wlan.pcci.edu
O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:\Program Files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {12C373C0-985A-4B8E-A5A6-9413CD44C1E8} - C:\WINDOWS\system32\yayyy.dll (file missing)
O2 - BHO: (no name) - {16C4CC4D-559A-40CA-927A-F59BD019E904} - C:\WINDOWS\system32\epfrqijs.dll
O2 - BHO: (no name) - {30BAA4DF-E0AB-4AFD-B6D8-FFAA032D0468} - C:\WINDOWS\system32\iiffcby.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {8396A2B4-C0F4-4BDF-B6DF-DFC6030CC2BD} - C:\WINDOWS\system32\bitsprx.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mm_server] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [1020c7ea] rundll32.exe "C:\WINDOWS\system32\jtlvmaow.dll",b
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ParentalControl] C:\Program Files\Parental Control\ParentalControl.Exe /SERVICE
O4 - HKLM\..\Run: [RegistrySmart] C:\Program Files\RegistrySmart\RegistrySmart.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [WinAble] C:\Program Files\WinAble\winable.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: TimeLeft.lnk = C:\Program Files\TimeLeft3\TimeLeft.exe
O4 - Global Startup: MSI Wireless Utility.lnk = C:\Program Files\MSI\Common\RaUI.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162325755270
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162325746407
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O20 - Winlogon Notify: iiffcby - iiffcby.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Sophos AutoUpdate Service - Sony Corporation - (no file)

–
End of file - 6666 bytes
Hello Zeraphim21 and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.


Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • ComboFix will automatically start. Any monitoring programs will be shut down like your antivirus, antispyware programs for example.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:05:22 AM, on 2/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Parental Control\ParentalControl.Exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\RegistrySmart\RegistrySmart.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\MSI\Common\RaUI.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = wlan.pcci.edu
O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:\Program Files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {12C373C0-985A-4B8E-A5A6-9413CD44C1E8} - C:\WINDOWS\system32\yayyy.dll (file missing)
O2 - BHO: (no name) - {16C4CC4D-559A-40CA-927A-F59BD019E904} - C:\WINDOWS\system32\epfrqijs.dll
O2 - BHO: (no name) - {30BAA4DF-E0AB-4AFD-B6D8-FFAA032D0468} - C:\WINDOWS\system32\iiffcby.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {8396A2B4-C0F4-4BDF-B6DF-DFC6030CC2BD} - C:\WINDOWS\system32\bitsprx.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mm_server] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [1020c7ea] rundll32.exe "C:\WINDOWS\system32\jtlvmaow.dll",b
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ParentalControl] C:\Program Files\Parental Control\ParentalControl.Exe /SERVICE
O4 - HKLM\..\Run: [RegistrySmart] C:\Program Files\RegistrySmart\RegistrySmart.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [WinAble] C:\Program Files\WinAble\winable.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: TimeLeft.lnk = C:\Program Files\TimeLeft3\TimeLeft.exe
O4 - Global Startup: MSI Wireless Utility.lnk = C:\Program Files\MSI\Common\RaUI.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162325755270
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162325746407
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O20 - Winlogon Notify: iiffcby - iiffcby.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Sophos AutoUpdate Service - Sony Corporation - (no file)

–
End of file - 6548 bytes


Start Time= Wed 02/20/2008 9:01:24.84

QuickScan did not find any signs of infected files

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2008-02-19 23:38:42 ( .D… ) "C:\Program Files\Trend Micro"
2008-02-19 22:56:22 ( .D… ) "C:\Documents and Settings\Lumpy\Application Data\RegistrySmart"
2008-02-19 22:56:12 ( .D… ) "C:\Program Files\RegistrySmart"
2008-02-18 21:09:26 3226 ( A…. ) "C:\WINDOWS\system32\tmp.reg"
2008-02-18 09:42:52 ( .D… ) "C:\Documents and Settings\Lumpy\Application Data\ParentalControl"
2008-02-18 09:42:44 ( .D… ) "C:\Program Files\Parental Control"
2008-02-16 19:46:46 85504 ( A…. ) "C:\WINDOWS\system32\VACFix.exe"
2008-02-08 10:37:48 82432 ( A…. ) "C:\WINDOWS\system32\IEDFix.exe"
2008-02-04 17:09:46 18214008 ( A…. ) "C:\WINDOWS\system32\MRT.exe"
2008-02-02 12:21:44 ( .D… ) "C:\Program Files\KONAMI"
2008-01-28 16:00:04 26688 ( A…. ) "C:\WINDOWS\system32\epfrqijs.dll"
2008-01-23 22:48:44 ( .D… ) "C:\Program Files\Common Files\Motive"
2008-01-11 19:14:18 ( .D… ) "C:\Program Files\MSXML 6.0"
2008-01-11 18:47:06 ( .D… ) "C:\Program Files\MSXML 4.0"
2008-01-10 23:53:32 44544 ( A…. ) "C:\WINDOWS\system32\pngfilt.dll"
2008-01-07 15:37:46 ( .D… ) "C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools"
2008-01-07 15:37:34 ( .D… ) "C:\Program Files\DAEMON Tools Lite"
2007-12-26 00:04:04 ( .D… ) "C:\Documents and Settings\Lumpy\Application Data\Grisoft"
2007-12-25 23:23:42 ( .D… ) "C:\Documents and Settings\Lumpy\Application Data\AVG7"
2007-12-25 23:22:10 ( .D… ) "C:\Program Files\Grisoft"
2007-12-24 23:18:14 ( .D… ) "C:\Program Files\Silent Hill"
2007-12-24 23:18:02 720896 ( A…. ) "C:\WINDOWS\iun6002ev.exe"
2007-12-24 15:49:34 ( .D… ) "C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools Pro"
2007-12-24 15:47:38 ( .D… ) "C:\Program Files\Temporary"
2007-12-23 20:51:16 ( .D… ) "C:\Program Files\LimeWire"
2007-12-19 17:01:06 347136 ( A…. ) "C:\WINDOWS\system32\dxtmsft.dll"
2007-12-07 23:21:48 3592192 ( A…. ) "C:\WINDOWS\system32\mshtml.dll"
2007-12-06 20:21:48 1159680 ( A…. ) "C:\WINDOWS\system32\urlmon.dll"
2007-12-06 20:21:48 824832 ( A…. ) "C:\WINDOWS\system32\wininet.dll"
2007-12-06 20:21:48 671232 ( A…. ) "C:\WINDOWS\system32\mstime.dll"
2007-12-06 20:21:48 478208 ( A…. ) "C:\WINDOWS\system32\mshtmled.dll"
2007-12-06 20:21:48 459264 ( A…. ) "C:\WINDOWS\system32\msfeeds.dll"
2007-12-06 20:21:48 233472 ( A…. ) "C:\WINDOWS\system32\webcheck.dll"
2007-12-06 20:21:48 193024 ( A…. ) "C:\WINDOWS\system32\msrating.dll"
2007-12-06 20:21:48 105984 ( A…. ) "C:\WINDOWS\system32\url.dll"
2007-12-06 20:21:48 102912 ( A…. ) "C:\WINDOWS\system32\occache.dll"
2007-12-06 20:21:48 52224 ( A…. ) "C:\WINDOWS\system32\msfeedsbs.dll"
2007-12-06 20:21:48 27648 ( A…. ) "C:\WINDOWS\system32\jsproxy.dll"
2007-12-06 20:21:46 6066176 ( A…. ) "C:\WINDOWS\system32\ieframe.dll"
2007-12-06 20:21:46 384512 ( A…. ) "C:\WINDOWS\system32\iedkcs32.dll"
2007-12-06 20:21:46 383488 ( A…. ) "C:\WINDOWS\system32\ieapfltr.dll"
2007-12-06 20:21:46 267776 ( A…. ) "C:\WINDOWS\system32\iertutil.dll"
2007-12-06 20:21:46 230400 ( A…. ) "C:\WINDOWS\system32\ieaksie.dll"
2007-12-06 20:21:46 214528 ( A…. ) "C:\WINDOWS\system32\dxtrans.dll"
2007-12-06 20:21:46 153088 ( A…. ) "C:\WINDOWS\system32\ieakeng.dll"
2007-12-06 20:21:46 133120 ( A…. ) "C:\WINDOWS\system32\extmgr.dll"
2007-12-06 20:21:46 124928 ( A…. ) "C:\WINDOWS\system32\advpack.dll"
2007-12-06 20:21:46 63488 ( A…. ) "C:\WINDOWS\system32\icardie.dll"
2007-12-06 20:21:46 44544 ( A…. ) "C:\WINDOWS\system32\iernonce.dll"
2007-12-06 05:00:58 70656 ( A…. ) "C:\WINDOWS\system32\ie4uinit.exe"
2007-12-06 05:00:58 13824 ( A…. ) "C:\WINDOWS\system32\ieudinit.exe"
2007-12-05 22:59:52 161792 ( A…. ) "C:\WINDOWS\system32\ieakui.dll"
2007-12-04 12:38:14 550912 ( A…. ) "C:\WINDOWS\system32\oleaut32.dll"
2007-11-28 23:08:50 1755857 ( A…. ) "C:\WINDOWS\system32\NEED4SHEED Team Screensaver.scr"
2007-11-28 23:07:58 1456688 ( A…. ) "C:\WINDOWS\system32\Need4Sheed.com.scr"
2007-11-28 23:03:54 1842674 ( A…. ) "C:\WINDOWS\system32\Fab Five.scr"


((((((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"ATIModeChange"="Ati2mdxx.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"mm_server"="\"C:\\Program Files\\Musicmatch\\Musicmatch Jukebox\\mm_server.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"1020c7ea"="rundll32.exe \"C:\\WINDOWS\\system32\\jtlvmaow.dll\",b"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_03\\bin\\jusched.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"ParentalControl"="C:\\Program Files\\Parental Control\\ParentalControl.Exe /SERVICE"
"RegistrySmart"="C:\\Program Files\\RegistrySmart\\RegistrySmart.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
@=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"WinAble"="C:\\Program Files\\WinAble\\winable.exe"
"DAEMON Tools Lite"="\"C:\\Program Files\\DAEMON Tools Lite\\daemon.exe\""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000
"DisableClock"=dword:00000000
"NoDispCPL"=dword:00000000
"DisableTaskMgr"=dword:00000000

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{30BAA4DF-E0AB-4AFD-B6D8-FFAA032D0468}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoUpdate Monitor.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\AutoUpdate Monitor.lnk"
"backup"="C:\\WINDOWS\\pss\\AutoUpdate Monitor.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\Program Files\\Sophos\\AutoUpdate\\ALMon.exe "
"item"="AutoUpdate Monitor"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Billminder.lnk"
"backup"="C:\\WINDOWS\\pss\\Billminder.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\QUICKENW\\BILLMIND.EXE -startup"
"item"="Billminder"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk"
"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l"
"item"="Microsoft Office"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Quicken Startup.lnk"
"backup"="C:\\WINDOWS\\pss\\Quicken Startup.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\QUICKENW\\QWDLLS.EXE "
"item"="Quicken Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Wireless-B Notebook Adapter Utility.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Wireless-B Notebook Adapter Utility.lnk"
"backup"="C:\\WINDOWS\\pss\\Wireless-B Notebook Adapter Utility.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\Program Files\\Linksys\\Wireless-B Notebook Adapter\\WPC11Cfg.exe "
"item"="Wireless-B Notebook Adapter Utility"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\ymetray.lnk"
"backup"="C:\\WINDOWS\\pss\\ymetray.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Yahoo!\\YAHOO!~1\\ymetray.exe yahoomusicengine -preload"
"item"="ymetray"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Lumpy^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
"path"="C:\\Documents and Settings\\Lumpy\\Start Menu\\Programs\\Startup\\PowerReg Scheduler.exe"
"backup"="C:\\WINDOWS\\pss\\PowerReg Scheduler.exeStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Lumpy\\Start Menu\\Programs\\Startup\\PowerReg Scheduler.exe"
"item"="PowerReg Scheduler"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="aim6"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\AIM6\\aim6.exe\" /d locale=en-US ee://aol/imApp"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NMBgMonitor"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitDownload]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BitDownload"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\BitDownload\\BitDownload.exe\" /minimized"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DVDLauncher"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="E_FATIACA"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATIACA.EXE /P26 \"EPSON Stylus CX3800 Series\" /O6 \"USB001\" /M \"Stylus CX3800\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mimboot"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\MUSICM~1\\MUSICM~1\\mimboot.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RavAV]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AdobeR"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\AdobeR.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Store Enc]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="up rule option"
"hkey"="HKCU"
"command"="C:\\DOCUME~1\\Lumpy\\APPLIC~1\\DOGMET~1\\up rule option.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=dword:00000002
"WMPNetworkSvc"=dword:00000003
"WebClient"=dword:00000002
"TapiSrv"=dword:00000003
"SharedAccess"=dword:00000002
"SCardSvr"=dword:00000003
"SamSs"=dword:00000002
"RemoteAccess"=dword:00000002
"RDSessMgr"=dword:00000003
"RasMan"=dword:00000003
"RasAuto"=dword:00000003
"mnmsrvc"=dword:00000003
"Irmon"=dword:00000002
"iPod Service"=dword:00000003
"ImapiService"=dword:00000003
"ERSvc"=dword:00000002


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AF11FA32918A6C12.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Low Battery Alarm Program.job
C:\WINDOWS\tasks\RegistrySmart Scheduled Scan.job

Completion time: Wed 02/20/2008 9:02:54.04
ComboFix ver 06.06.17 - This logfile is located at C:\ComboFix.txt
You are apparently unwilling to follow my directions and prefer to do things your way. If this is the case, I will no longer provide you with any assistance in fixing your computer and you can continue to do it your self.


I directed you:

If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.


You decided to run a version of the program that was created on the following date: ComboFix ver 06.06.17

So you have wasted my time and yours. I could have helped at least 3 other people during the time I spent trying to figure out what was wrong with the data posted in your ComboFix.txt log. I do not intend to waste any more. I will give you one last chance.

1. DELETE ComboFix.exe from your desktop as well as the following folder: C:\ComboFix

2. Install and run the most current version of this tool as directed in my first post.

Failure to comply with the above could result in your case being referred to our Admin staff for proper disposition.

Trevuren
ComboFix 08-02-22 - Lumpy 2008-02-21 19:09:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.236 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Lumpy\ravmonlog
C:\Program Files\MyWay
C:\Program Files\MyWay\myBar\History\search
C:\Program Files\MyWay\myBar\Settings\prevcfg.htm
C:\Program Files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL
C:\Program Files\MyWay\SrchAstt\1.bin\PARTNER.DAT
C:\Program Files\MyWay\SrchAstt\1.bin\PARTNER2.DAT
C:\Program Files\MyWay\SrchAstt\Cache\008E01B8
C:\Program Files\MyWay\SrchAstt\Cache\files.ini
C:\Program Files\Temporary
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\woamvltj.ini
C:\WINDOWS\system32\yyyay.ini
C:\WINDOWS\system32\yyyay.ini2

—– BITS: Possible infected sites —–

hxxp://au.download.windowsupdaõj
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\nm


((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 )))))))))))))))))))))))))))))))
.

2008-02-19 23:38 . 2008-02-19 23:38 d——– C:\Program Files\Trend Micro
2008-02-19 22:56 . 2008-02-19 22:56 d——– C:\Program Files\RegistrySmart
2008-02-19 22:56 . 2008-02-19 23:03 d——– C:\Documents and Settings\Lumpy\Application Data\RegistrySmart
2008-02-18 21:09 . 2008-02-18 21:09 3,226 –a—— C:\WINDOWS\system32\tmp.reg
2008-02-18 21:04 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-02-18 21:04 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-02-18 21:04 . 2008-02-16 19:46 85,504 –a—— C:\WINDOWS\system32\VACFix.exe
2008-02-18 21:04 . 2008-02-08 10:37 82,432 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-02-18 21:04 . 2003-06-05 20:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-02-18 21:04 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-02-18 21:04 . 2007-10-03 23:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-02-18 09:42 . 2008-02-18 09:45 d——– C:\Program Files\Parental Control
2008-02-18 09:42 . 2008-02-18 09:42 d——– C:\Documents and Settings\Lumpy\Application Data\ParentalControl
2008-02-18 09:42 . 2008-02-21 19:12 d——– C:\Documents and Settings\All Users\Application Data\ParentalControl
2008-02-02 12:21 . 2008-02-02 12:21 d——– C:\Program Files\KONAMI
2008-01-28 16:00 . 2008-01-28 16:00 26,688 –a—— C:\WINDOWS\system32\epfrqijs.dll
2008-01-23 22:49 . 2008-01-23 22:49 d——– C:\Documents and Settings\All Users\Application Data\Motive
2008-01-23 22:49 . 2005-07-12 00:28 69,632 –a—— C:\WINDOWS\system32\MCCDevice.dll
2008-01-23 22:49 . 2005-07-12 00:28 6,048 –a—— C:\WINDOWS\system32\MCC16.dll
2008-01-23 22:48 . 2008-01-29 09:48 d——– C:\Program Files\Common Files\Motive
2008-01-23 22:48 . 2008-01-23 22:49 29,540,732 –a—— C:\BellSouthIW.re~
2008-01-23 22:48 . 2002-02-13 19:53 6,345 -ra—— C:\WINDOWS\system32\DevMngr.vxd
2008-01-22 17:12 . 2003-02-28 18:26 139,536 –a—— C:\WINDOWS\system32\javaee.dll
2008-01-22 17:12 . 2003-02-28 18:26 46,352 –a—— C:\WINDOWS\setdebug.exe
2008-01-22 17:12 . 2003-02-28 16:54 7,315 –a—— C:\WINDOWS\system32\javasup.vxd
2008-01-22 17:12 . 2003-02-28 16:35 6,550 –a—— C:\WINDOWS\jautoexp.dat
2008-01-22 17:12 . 2003-02-28 16:38 113 –a—— C:\WINDOWS\system32\zonedon.reg
2008-01-22 17:12 . 2003-02-28 16:38 113 –a—— C:\WINDOWS\system32\zonedoff.reg

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-21 17:46 ——— d—–w C:\Program Files\e-Sword
2008-02-20 13:42 ——— d—–w C:\Program Files\Incomplete
2008-02-20 13:35 ——— d—–w C:\Program Files\LimeWire
2008-02-20 02:16 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\AVG7
2008-02-08 12:12 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-08 05:21 ——— d—–w C:\Program Files\DivX
2008-01-12 01:14 ——— d—–w C:\Program Files\MSXML 6.0
2008-01-12 00:47 ——— d—–w C:\Program Files\MSXML 4.0
2008-01-07 21:39 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools
2008-01-07 21:37 ——— d—–w C:\Program Files\DAEMON Tools Lite
2008-01-06 04:39 715,248 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-12-26 08:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\safe cash bash extra
2007-12-26 06:22 ——— d—–w C:\Program Files\Java
2007-12-26 06:04 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\Grisoft
2007-12-26 05:40 ——— d—–w C:\Program Files\Serif
2007-12-26 05:32 ——— d—–w C:\Program Files\EA GAMES
2007-12-26 05:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2007-12-26 05:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-26 05:22 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-26 05:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-26 05:19 ——— d—–w C:\Program Files\Microsoft Games
2007-12-25 05:20 ——— d—–w C:\Program Files\Silent Hill
2007-12-25 05:18 720,896 —-a-w C:\WINDOWS\iun6002ev.exe
2007-12-24 21:50 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools Pro
2007-12-24 19:29 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\IGN_DLM
2007-10-10 18:15 34,768 —-a-w C:\Documents and Settings\Lumpy\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{12C373C0-985A-4B8E-A5A6-9413CD44C1E8}]
C:\WINDOWS\system32\yayyy.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{16C4CC4D-559A-40CA-927A-F59BD019E904}]
2008-01-28 16:00 26688 –a—— C:\WINDOWS\system32\epfrqijs.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8396A2B4-C0F4-4BDF-B6DF-DFC6030CC2BD}]
2004-08-04 00:56 84992 –a—— C:\WINDOWS\system32\bitsprx.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-03 07:54 486856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-08-12 21:10 335872]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 16:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-12 19:51 185896]
"mm_server"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe" [2005-03-09 19:10 102400]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-24 03:24 282624]
"1020c7ea"="C:\WINDOWS\system32\jtlvmaow.dll" [ ]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-08 11:02 579072]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25 6731312]
"ParentalControl"="C:\Program Files\Parental Control\ParentalControl.exe" [2007-06-26 01:30 6088192]
"RegistrySmart"="C:\Program Files\RegistrySmart\RegistrySmart.exe" [2008-02-13 09:08 4351216]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-25 23:22 219136]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 00:56 53760 C:\WINDOWS\system32\narrator.exe]

C:\Documents and Settings\Lumpy\Start Menu\Programs\Startup\
TimeLeft.lnk - C:\Program Files\TimeLeft3\TimeLeft.exe [2007-01-11 03:56:51 1046016]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
MSI Wireless Utility.lnk - C:\Program Files\MSI\Common\RaUI.exe [2007-07-10 12:32:15 425984]
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-02-05 14:29:20 54512]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableClock"= 0 (0x0)
"DisableRegistryTools"= 0 (0x0)
"NoDispCPL"= 0 (0x0)
"DisableTaskMgr"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoMultiIE"= 0 (0x0)
"LWA"= 0 (0x0)
"LWB"= 0 (0x0)
"LWC"= 0 (0x0)
"LWD"= 0 (0x0)
"LWE"= 0 (0x0)
"LWF"= 0 (0x0)
"LWG"= 0 (0x0)
"LWH"= 0 (0x0)
"LWI"= 0 (0x0)
"LWJ"= 0 (0x0)
"LWK"= 0 (0x0)
"LWL"= 0 (0x0)
"LWM"= 0 (0x0)
"LWN"= 0 (0x0)
"LWO"= 0 (0x0)
"LWP"= 0 (0x0)
"LWQ"= 0 (0x0)
"LWR"= 0 (0x0)
"LWS"= 0 (0x0)
"LWT"= 0 (0x0)
"LWU"= 0 (0x0)
"LWV"= 0 (0x0)
"LWW"= 0 (0x0)
"LWX"= 0 (0x0)
"LWY"= 0 (0x0)
"LWZ"= 0 (0x0)
"NoRun"= 0 (0x0)
"NoFind"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iiffcby]
iiffcby.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoUpdate Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk
backup=C:\WINDOWS\pss\AutoUpdate Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
backup=C:\WINDOWS\pss\Billminder.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
backup=C:\WINDOWS\pss\Quicken Startup.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Wireless-B Notebook Adapter Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless-B Notebook Adapter Utility.lnk
backup=C:\WINDOWS\pss\Wireless-B Notebook Adapter Utility.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Lumpy^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
path=C:\Documents and Settings\Lumpy\Start Menu\Programs\Startup\PowerReg Scheduler.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
C:\Program Files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2007-03-12 12:49 153136 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitDownload]
C:\Program Files\BitDownload\BitDownload.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
–a—— 2005-02-08 04:00 98304 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2006-09-25 14:54 229952 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
–a—— 2005-03-09 19:10 11776 C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2007-03-09 17:53 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-09-24 03:24 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RavAV]
C:\WINDOWS\AdobeR.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Store Enc]
C:\DOCUME~1\Lumpy\APPLIC~1\DOGMET~1\up rule option.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-03-14 02:43 83608 C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2007-05-12 19:51 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"WebClient"=2 (0x2)
"TapiSrv"=3 (0x3)
"SharedAccess"=2 (0x2)
"SCardSvr"=3 (0x3)
"SamSs"=2 (0x2)
"RemoteAccess"=2 (0x2)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)
"mnmsrvc"=3 (0x3)
"Irmon"=2 (0x2)
"iPod Service"=3 (0x3)
"ImapiService"=3 (0x3)
"ERSvc"=2 (0x2)

R0 esfjtggi;esfjtggi;C:\WINDOWS\system32\drivers\thfhjgha.dat []
R1 cp_drv;Crawler Parental Control Driver;C:\Documents and Settings\All Users\Application Data\ParentalControl\cp_drv.sys [2008-02-18 09:43]
R1 cp_tdifw_drv;cp_tdifw_drv;C:\Documents and Settings\All Users\Application Data\ParentalControl\cp_tdifw_drv.sys [2008-02-18 09:43]
R3 axsaki;axsaki;C:\WINDOWS\system32\DRIVERS\axsaki.sys [2003-03-30 21:38]
R3 axskbus;axskbus;C:\WINDOWS\system32\DRIVERS\axskbus.sys [2003-03-28 11:58]
S3 atimtai;atimtai;C:\WINDOWS\system32\DRIVERS\atimtai.sys [2001-08-17 12:48]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1d8e2213-80f8-11db-949c-000f663bf8c6}]
\Shell\AutoRun\command - E:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2750b1c1-69f7-11db-acb2-806d6172696f}]
\Shell\AutoRun\command - D:\BellSouth.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{529bcb50-b591-11db-9520-000f663bf8c6}]
\Shell\AutoRun\command - E:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{80514710-a727-11dc-9749-0019db91814c}]
\Shell\AutoRun\command - Desktop.ini
\Shell\explore\Command - Desktop.ini
\Shell\open\Command - Desktop.ini

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a09be9c0-689e-11db-9428-000f663bf8c6}]
\Shell\AutoRun\command - F:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a09be9c1-689e-11db-9428-000f663bf8c6}]
\Shell\AutoRun\command - Copy of Desktop.ini
\Shell\explore\Command - Copy of Desktop.ini
\Shell\open\Command - Copy of Desktop.ini

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a78c7c83-a82a-11dc-974c-0019db91814c}]
\Shell\AutoRun\command - Copy of Desktop.ini
\Shell\explore\Command - Copy of Desktop.ini
\Shell\open\Command - Copy of Desktop.ini

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b802da00-f2a5-11db-95ec-0008749c80da}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cae6c3f0-bd68-11dc-9760-0019db91814c}]
\Shell\AutoRun\command - G:\setup.exe
\Shell\directx\command - G:\DirectX\dxsetup.exe
\Shell\setup\command - G:\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-22 01:00:00 C:\WINDOWS\Tasks\AF11FA32918A6C12.job"
- c:\docume~1\lumpy\applic~1\dogmet~1\Admintrans32.exe
"2008-02-18 22:26:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-10-17 22:32:12 C:\WINDOWS\Tasks\Low Battery Alarm Program.job"
"2008-02-22 01:16:52 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
- C:\Program Files\RegistrySmart\RegistrySmart.ex
- C:\Program Files\RegistrySmart
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-21 19:15:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
.
**************************************************************************
.
Completion time: 2008-02-21 19:21:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-22 01:21:48
ComboFix2.txt 2008-02-20 15:02:54
.
2008-02-13 13:21:10 — E O F —




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:28, on 2008-02-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Parental Control\ParentalControl.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\WINDOWS\explorer.exe
C:\Program Files\MSI\Common\RaUI.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = wlan.pcci.edu
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {12C373C0-985A-4B8E-A5A6-9413CD44C1E8} - C:\WINDOWS\system32\yayyy.dll (file missing)
O2 - BHO: (no name) - {16C4CC4D-559A-40CA-927A-F59BD019E904} - C:\WINDOWS\system32\epfrqijs.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {8396A2B4-C0F4-4BDF-B6DF-DFC6030CC2BD} - C:\WINDOWS\system32\bitsprx.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mm_server] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [1020c7ea] rundll32.exe "C:\WINDOWS\system32\jtlvmaow.dll",b
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ParentalControl] C:\Program Files\Parental Control\ParentalControl.Exe /SERVICE
O4 - HKLM\..\Run: [RegistrySmart] C:\Program Files\RegistrySmart\RegistrySmart.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: TimeLeft.lnk = C:\Program Files\TimeLeft3\TimeLeft.exe
O4 - Global Startup: MSI Wireless Utility.lnk = C:\Program Files\MSI\Common\RaUI.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162325755270
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162325746407
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O20 - Winlogon Notify: iiffcby - iiffcby.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Sophos AutoUpdate Service - Sony Corporation - (no file)

–
End of file - 6180 bytes



My original combofix was downloaded on the 19th. I assumed I had the latest version. I didn't "try to do it my way" so there is no need to refer me for "disposition." My bad. Here is the info you asked for.
A. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\system32\epfrqijs.dll
C:\WINDOWS\system32\Process.exe
C:\WINDOWS\system32\WS2Fix.exe
C:\WINDOWS\jautoexp.dat
C:\WINDOWS\system32\bitsprx.dll
C:\WINDOWS\pss\PowerReg Scheduler.exeStartup
E:\autorun.exe
G:\setup.exe
G:\DirectX
C:\WINDOWS\Tasks\AF11FA32918A6C12.job

Folder::
C:\Documents and Settings\All Users\Application Data\safe cash bash extra
C:\DOCUMENTS AND SETTINGS\Lumpy\APPLICATION DATA\DOGMET~1\up rule option.exe

Driver::
esfjtggi


Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{12C373C0-985A-4B8E-A5A6-9413CD44C1E8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{16C4CC4D-559A-40CA-927A-F59BD019E904}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{12C373C0-985A-4B8E-A5A6-9413CD44C1E8}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"1020c7ea"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iiffcby]
[-HKLM\~\startupfolder\C:^Documents and Settings^Lumpy^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Store Enc]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1d8e2213-80f8-11db-949c-000f663bf8c6}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cae6c3f0-bd68-11dc-9760-0019db91814c}]
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


B. Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:16, on 2008-02-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)


Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Parental Control\ParentalControl.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\MSI\Common\RaUI.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = wlan.pcci.edu
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {8396A2B4-C0F4-4BDF-B6DF-DFC6030CC2BD} - C:\WINDOWS\system32\bitsprx.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mm_server] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ParentalControl] C:\Program Files\Parental Control\ParentalControl.Exe /SERVICE
O4 - HKLM\..\Run: [RegistrySmart] C:\Program Files\RegistrySmart\RegistrySmart.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: TimeLeft.lnk = C:\Program Files\TimeLeft3\TimeLeft.exe
O4 - Global Startup: MSI Wireless Utility.lnk = C:\Program Files\MSI\Common\RaUI.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162325755270
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162325746407
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Sophos AutoUpdate Service - Sony Corporation - (no file)

–
End of file - 6026 bytes





ComboFix 08-02-22 - Lumpy 2008-02-21 20:53:39.2 - NTFSx86

Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Lumpy\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\jautoexp.dat
C:\WINDOWS\pss\PowerReg Scheduler.exeStartup
C:\WINDOWS\system32\bitsprx.dll
C:\WINDOWS\system32\epfrqijs.dll
C:\WINDOWS\system32\Process.exe
C:\WINDOWS\system32\WS2Fix.exe
C:\WINDOWS\Tasks\AF11FA32918A6C12.job
E:\autorun.exe
G:\DirectX
G:\setup.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\safe cash bash extra
C:\Documents and Settings\All Users\Application Data\safe cash bash extra\build amen nurb
C:\WINDOWS\jautoexp.dat
C:\WINDOWS\pss\PowerReg Scheduler.exeStartup
C:\WINDOWS\system32\epfrqijs.dll
C:\WINDOWS\system32\Process.exe
C:\WINDOWS\system32\WS2Fix.exe
C:\WINDOWS\Tasks\AF11FA32918A6C12.job
C:\WINDOWS\system32\bitsprx.dll . . . . failed to delete

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_ESFJTGGI
——-\esfjtggi


((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 )))))))))))))))))))))))))))))))
.

2008-02-19 23:38 . 2008-02-19 23:38 d——– C:\Program Files\Trend Micro
2008-02-19 22:56 . 2008-02-19 22:56 d——– C:\Program Files\RegistrySmart
2008-02-19 22:56 . 2008-02-19 23:03 d——– C:\Documents and Settings\Lumpy\Application Data\RegistrySmart
2008-02-18 21:09 . 2008-02-18 21:09 3,226 –a—— C:\WINDOWS\system32\tmp.reg
2008-02-18 21:04 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-02-18 21:04 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-02-18 21:04 . 2008-02-16 19:46 85,504 –a—— C:\WINDOWS\system32\VACFix.exe
2008-02-18 21:04 . 2008-02-08 10:37 82,432 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-02-18 21:04 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-02-18 09:42 . 2008-02-18 09:45 d——– C:\Program Files\Parental Control
2008-02-18 09:42 . 2008-02-18 09:42 d——– C:\Documents and Settings\Lumpy\Application Data\ParentalControl
2008-02-18 09:42 . 2008-02-21 21:03 d——– C:\Documents and Settings\All Users\Application Data\ParentalControl
2008-02-02 12:21 . 2008-02-02 12:21 d——– C:\Program Files\KONAMI
2008-01-23 22:49 . 2008-01-23 22:49 d——– C:\Documents and Settings\All Users\Application Data\Motive
2008-01-23 22:49 . 2005-07-12 00:28 69,632 –a—— C:\WINDOWS\system32\MCCDevice.dll
2008-01-23 22:49 . 2005-07-12 00:28 6,048 –a—— C:\WINDOWS\system32\MCC16.dll
2008-01-23 22:48 . 2008-01-29 09:48 d——– C:\Program Files\Common Files\Motive
2008-01-23 22:48 . 2008-01-23 22:49 29,540,732 –a—— C:\BellSouthIW.re~
2008-01-23 22:48 . 2002-02-13 19:53 6,345 -ra—— C:\WINDOWS\system32\DevMngr.vxd
2008-01-22 17:12 . 2003-02-28 18:26 139,536 –a—— C:\WINDOWS\system32\javaee.dll
2008-01-22 17:12 . 2003-02-28 18:26 46,352 –a—— C:\WINDOWS\setdebug.exe
2008-01-22 17:12 . 2003-02-28 16:54 7,315 –a—— C:\WINDOWS\system32\javasup.vxd
2008-01-22 17:12 . 2003-02-28 16:38 113 –a—— C:\WINDOWS\system32\zonedon.reg
2008-01-22 17:12 . 2003-02-28 16:38 113 –a—— C:\WINDOWS\system32\zonedoff.reg

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 01:17 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\AVG7
2008-02-21 17:46 ——— d—–w C:\Program Files\e-Sword
2008-02-20 13:42 ——— d—–w C:\Program Files\Incomplete
2008-02-20 13:35 ——— d—–w C:\Program Files\LimeWire
2008-02-08 12:12 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-08 05:21 ——— d—–w C:\Program Files\DivX
2008-01-12 01:14 ——— d—–w C:\Program Files\MSXML 6.0
2008-01-12 00:47 ——— d—–w C:\Program Files\MSXML 4.0
2008-01-07 21:39 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools
2008-01-07 21:37 ——— d—–w C:\Program Files\DAEMON Tools Lite
2008-01-06 04:39 715,248 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-12-26 06:22 ——— d—–w C:\Program Files\Java
2007-12-26 06:04 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\Grisoft
2007-12-26 05:40 ——— d—–w C:\Program Files\Serif
2007-12-26 05:32 ——— d—–w C:\Program Files\EA GAMES
2007-12-26 05:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2007-12-26 05:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-26 05:22 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-26 05:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-26 05:19 ——— d—–w C:\Program Files\Microsoft Games
2007-12-25 05:20 ——— d—–w C:\Program Files\Silent Hill
2007-12-25 05:18 720,896 —-a-w C:\WINDOWS\iun6002ev.exe
2007-12-24 21:50 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools Pro
2007-12-24 19:29 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\IGN_DLM
2007-10-10 18:15 34,768 —-a-w C:\Documents and Settings\Lumpy\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8396A2B4-C0F4-4BDF-B6DF-DFC6030CC2BD}]
2004-08-04 00:56 84992 –a—— C:\WINDOWS\system32\bitsprx.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-03 07:54 486856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-08-12 21:10 335872]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 16:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-12 19:51 185896]
"mm_server"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe" [2005-03-09 19:10 102400]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-24 03:24 282624]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-08 11:02 579072]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25 6731312]
"ParentalControl"="C:\Program Files\Parental Control\ParentalControl.exe" [2007-06-26 01:30 6088192]
"RegistrySmart"="C:\Program Files\RegistrySmart\RegistrySmart.exe" [2008-02-13 09:08 4351216]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-25 23:22 219136]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 00:56 53760 C:\WINDOWS\system32\narrator.exe]

C:\Documents and Settings\Lumpy\Start Menu\Programs\Startup\
TimeLeft.lnk - C:\Program Files\TimeLeft3\TimeLeft.exe [2007-01-11 03:56:51 1046016]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
MSI Wireless Utility.lnk - C:\Program Files\MSI\Common\RaUI.exe [2007-07-10 12:32:15 425984]
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-02-05 14:29:20 54512]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableClock"= 0 (0x0)
"NoDispCPL"= 0 (0x0)
"DisableRegistryTools"= 0 (0x0)
"DisableTaskMgr"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoMultiIE"= 0 (0x0)
"LWA"= 0 (0x0)
"LWB"= 0 (0x0)
"LWC"= 0 (0x0)
"LWD"= 0 (0x0)
"LWE"= 0 (0x0)
"LWF"= 0 (0x0)
"LWG"= 0 (0x0)
"LWH"= 0 (0x0)
"LWI"= 0 (0x0)
"LWJ"= 0 (0x0)
"LWK"= 0 (0x0)
"LWL"= 0 (0x0)
"LWM"= 0 (0x0)
"LWN"= 0 (0x0)
"LWO"= 0 (0x0)
"LWP"= 0 (0x0)
"LWQ"= 0 (0x0)
"LWR"= 0 (0x0)
"LWS"= 0 (0x0)
"LWT"= 0 (0x0)
"LWU"= 0 (0x0)
"LWV"= 0 (0x0)
"LWW"= 0 (0x0)
"LWX"= 0 (0x0)
"LWY"= 0 (0x0)
"LWZ"= 0 (0x0)
"NoRun"= 0 (0x0)
"NoFind"= 0 (0x0)

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoUpdate Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk
backup=C:\WINDOWS\pss\AutoUpdate Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
backup=C:\WINDOWS\pss\Billminder.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
backup=C:\WINDOWS\pss\Quicken Startup.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Wireless-B Notebook Adapter Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless-B Notebook Adapter Utility.lnk
backup=C:\WINDOWS\pss\Wireless-B Notebook Adapter Utility.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2007-03-12 12:49 153136 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitDownload]
C:\Program Files\BitDownload\BitDownload.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
–a—— 2005-02-08 04:00 98304 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2006-09-25 14:54 229952 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
–a—— 2005-03-09 19:10 11776 C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2007-03-09 17:53 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-09-24 03:24 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RavAV]
C:\WINDOWS\AdobeR.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-03-14 02:43 83608 C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2007-05-12 19:51 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"WebClient"=2 (0x2)
"TapiSrv"=3 (0x3)
"SharedAccess"=2 (0x2)
"SCardSvr"=3 (0x3)
"SamSs"=2 (0x2)
"RemoteAccess"=2 (0x2)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)
"mnmsrvc"=3 (0x3)
"Irmon"=2 (0x2)
"iPod Service"=3 (0x3)
"ImapiService"=3 (0x3)
"ERSvc"=2 (0x2)

R0 esfjtggi;esfjtggi;C:\WINDOWS\system32\drivers\thfhjgha.dat []
R1 cp_drv;Crawler Parental Control Driver;C:\Documents and Settings\All Users\Application Data\ParentalControl\cp_drv.sys [2008-02-18 09:43]
R1 cp_tdifw_drv;cp_tdifw_drv;C:\Documents and Settings\All Users\Application Data\ParentalControl\cp_tdifw_drv.sys [2008-02-18 09:43]
R3 axsaki;axsaki;C:\WINDOWS\system32\DRIVERS\axsaki.sys [2003-03-30 21:38]
R3 axskbus;axskbus;C:\WINDOWS\system32\DRIVERS\axskbus.sys [2003-03-28 11:58]
S3 atimtai;atimtai;C:\WINDOWS\system32\DRIVERS\atimtai.sys [2001-08-17 12:48]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2750b1c1-69f7-11db-acb2-806d6172696f}]
\Shell\AutoRun\command - D:\BellSouth.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{529bcb50-b591-11db-9520-000f663bf8c6}]
\Shell\AutoRun\command - E:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{80514710-a727-11dc-9749-0019db91814c}]
\Shell\AutoRun\command - Desktop.ini
\Shell\explore\Command - Desktop.ini
\Shell\open\Command - Desktop.ini

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a09be9c0-689e-11db-9428-000f663bf8c6}]
\Shell\AutoRun\command - F:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a09be9c1-689e-11db-9428-000f663bf8c6}]
\Shell\AutoRun\command - Copy of Desktop.ini
\Shell\explore\Command - Copy of Desktop.ini
\Shell\open\Command - Copy of Desktop.ini

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a78c7c83-a82a-11dc-974c-0019db91814c}]
\Shell\AutoRun\command - Copy of Desktop.ini
\Shell\explore\Command - Copy of Desktop.ini
\Shell\open\Command - Copy of Desktop.ini

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b802da00-f2a5-11db-95ec-0008749c80da}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

*Newly Created Service* - ESFJTGGI
.
Contents of the 'Scheduled Tasks' folder
"2008-02-18 22:26:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-10-17 22:32:12 C:\WINDOWS\Tasks\Low Battery Alarm Program.job"
"2008-02-22 03:03:34 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
- C:\Program Files\RegistrySmart\RegistrySmart.ex
- C:\Program Files\RegistrySmart
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-21 21:02:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
.
**************************************************************************
.
Completion time: 2008-02-21 21:05:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-22 03:05:52
ComboFix2.txt 2008-02-22 01:22:00
ComboFix3.txt 2008-02-20 15:02:54
.
2008-02-13 13:21:10 — E O F —







——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
2008-02-21 23:04
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 22/02/2008
Kaspersky Anti-Virus database records: 575350
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\

Scan Statistics:
Total number of scanned objects: 66723
Number of viruses found: 14
Number of infected objects: 35
Number of suspicious objects: 0
Duration of the scan process: 01:37:23

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Lumpy\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\cert8.db Object is locked skipped
C:\Documents and Settings\Lumpy\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Lumpy\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\history.dat Object is locked skipped
C:\Documents and Settings\Lumpy\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\key3.db Object is locked skipped
C:\Documents and Settings\Lumpy\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\parent.lock Object is locked skipped
C:\Documents and Settings\Lumpy\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Lumpy\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Lumpy\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\XUL.mfl Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\History\History.IE5\MSHist012008022120080222\index.dat Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lumpy\My Documents\filelib\Gangsters2Setup-dm(2).exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Documents and Settings\Lumpy\My Documents\filelib\Gangsters2Setup-dm.exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Documents and Settings\Lumpy\My Documents\filelib\GettysburgSetup-dm.exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Documents and Settings\Lumpy\My Documents\filelib\ResidentEvil3-dm.exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Documents and Settings\Lumpy\My Documents\Greek\Parsing Sheets\Rom. 6.12-18.xls Object is locked skipped
C:\Documents and Settings\Lumpy\My Documents\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Lumpy\My Documents\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Lumpy\My Documents\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Lumpy\My Documents\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Lumpy\ntuser.dat Object is locked skipped
C:\Documents and Settings\Lumpy\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\e-Sword\2000+ Bible Illustrations.top Object is locked skipped
C:\Program Files\e-Sword\markup.ovl Object is locked skipped
C:\Program Files\e-Sword\study.not Object is locked skipped
C:\Program Files\LimeWire\DAEMONTools-Pro-Cracked-V-4.10.218[clean]\DTPro4100218Basic.exe/data0000.cab/wr-1-922.exe Infected: Trojan-Downloader.Win32.Small.gll skipped
C:\Program Files\LimeWire\DAEMONTools-Pro-Cracked-V-4.10.218[clean]\DTPro4100218Basic.exe/data0000.cab/DTPRO4~1.EXE/data0000.cab/is151099.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\LimeWire\DAEMONTools-Pro-Cracked-V-4.10.218[clean]\DTPro4100218Basic.exe/data0000.cab/DTPRO4~1.EXE/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\LimeWire\DAEMONTools-Pro-Cracked-V-4.10.218[clean]\DTPro4100218Basic.exe/data0000.cab/DTPRO4~1.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\LimeWire\DAEMONTools-Pro-Cracked-V-4.10.218[clean]\DTPro4100218Basic.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\LimeWire\DAEMONTools-Pro-Cracked-V-4.10.218[clean]\DTPro4100218Basic.exe Rsrc-Package: infected - 5 skipped
C:\Program Files\Mozilla Firefox\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\QooBox\Quarantine\C\Program Files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL.vir Infected: not-a-virus:AdWare.Win32.MyWay.c skipped
C:\QooBox\Quarantine\catchme2008-02-21_210217.96.zip/bitsprx.dll Infected: Trojan.Win32.Pakes.cdw skipped
C:\QooBox\Quarantine\catchme2008-02-21_210217.96.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP104\A0016593.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP105\A0016640.dll Infected: not-a-virus:AdTool.Win32.WhenU.r skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP105\A0016641.exe Infected: not-a-virus:AdTool.Win32.WhenU.s skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP106\A0016788.dll Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP118\A0020423.dll Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP118\A0020424.dll Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP118\A0020425.dll Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP121\A0020574.DLL Infected: not-a-virus:AdWare.Win32.MyWay.c skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP122\change.log Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP70\A0009364.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP75\A0010902.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP76\A0010914.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP77\A0010927.exe Infected: not-a-virus:AdWare.Win32.Agent.zk skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP82\A0012142.dll Infected: not-a-virus:AdWare.Win32.TrafficSol.q skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP86\A0012338.EXE Infected: not-a-virus:AdWare.Win32.MyWay.b skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP86\A0012339.DLL Infected: not-a-virus:AdWare.Win32.MyWay.f skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP88\A0012669.DLL Infected: not-a-virus:AdWare.Win32.MyWay.c skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012695.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012696.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012697.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012698.exe/data0000.cab/wr-1-922.exe Infected: Trojan-Downloader.Win32.Small.gll skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012698.exe/data0000.cab/crack.exe/data0000.cab/is151099.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012698.exe/data0000.cab/crack.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012698.exe/data0000.cab/crack.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012698.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012698.exe Rsrc-Package: infected - 5 skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012699.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012700.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012701.dll Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012702.dll Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012703.dll Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012704.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012705.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012706.dll Infected: not-a-virus:AdWare.Win32.AdvertMen.a skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\bitsprx.dll Infected: Trojan.Win32.Pakes.cdw skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
A. You are using an illegally obtained piece of software called Daemon Tools. The crack you used was infected. Using the Add/Remove Program module in your Control Panel, UNINSTAll Daemon Tools. Once the program has been uninstalled, using Windows Explorer (Windows Key + E), DELETE the following folder and all its content: C:\Program Files\Daemon Tools<==Folder


B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\Documents and Settings\Lumpy\My Documents\filelib\Gangsters2Setup-dm(2).exe
C:\Documents and Settings\Lumpy\My Documents\filelib\Gangsters2Setup-dm.exe
C:\Documents and Settings\Lumpy\My Documents\filelib\GettysburgSetup-dm.exe
C:\Documents and Settings\Lumpy\My Documents\filelib\ResidentEvil3-dm.exe
C:\Program Files\LimeWire\DAEMONTools-Pro-Cracked-V-4.10.218[clean]
C:\WINDOWS\system32\drivers\thfhjgha.dat

Rootkit::
C:\WINDOWS\system32\bitsprx.dll

Driver::
esfjtggi

Folder::
C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools
C:\Program Files\DAEMON Tools Lite
C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools Pro

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8396A2B4-C0F4-4BDF-B6DF-DFC6030CC2BD}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitDownload]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RavAV]
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 08-02-22 - Lumpy 2008-02-22 0:40:28.3 - NTFSx86

Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Lumpy\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Documents and Settings\Lumpy\My Documents\filelib\Gangsters2Setup-dm(2).exe
C:\Documents and Settings\Lumpy\My Documents\filelib\Gangsters2Setup-dm.exe
C:\Documents and Settings\Lumpy\My Documents\filelib\GettysburgSetup-dm.exe
C:\Documents and Settings\Lumpy\My Documents\filelib\ResidentEvil3-dm.exe
C:\Program Files\LimeWire\DAEMONTools-Pro-Cracked-V-4.10.218[clean]
C:\WINDOWS\system32\drivers\thfhjgha.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools Pro
C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools Pro\dtpro.ini
C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools Pro\ImageCatalog\RecentlyUsedImages\{1ACBDEBE-56F9-4358-9668-03DDAABA7A1B}\Link.dat
C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools Pro\ImageCatalog\RecentlyUsedImages\Properties.dat
C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools Pro\ImageCatalog\Root\{E530E08A-1FD2-4490-94D7-E35978CDCF48}\MediaIcon.ico
C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools Pro\ImageCatalog\Root\{E530E08A-1FD2-4490-94D7-E35978CDCF48}\Properties.dat
C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools Pro\ImageCatalog\Root\Properties.dat
C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools
C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools\daemontools.ini
C:\Documents and Settings\Lumpy\My Documents\filelib\Gangsters2Setup-dm(2).exe
C:\Documents and Settings\Lumpy\My Documents\filelib\Gangsters2Setup-dm.exe
C:\Documents and Settings\Lumpy\My Documents\filelib\GettysburgSetup-dm.exe
C:\Documents and Settings\Lumpy\My Documents\filelib\ResidentEvil3-dm.exe
C:\WINDOWS\system32\bitsprx.dll
C:\WINDOWS\system32\drivers\thfhjgha.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_ESFJTGGI
——-\esfjtggi


((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 )))))))))))))))))))))))))))))))
.

2008-02-21 21:12 . 2008-02-21 21:12 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-02-21 21:12 . 2008-02-21 21:12 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-19 23:38 . 2008-02-19 23:38 d——– C:\Program Files\Trend Micro
2008-02-19 22:56 . 2008-02-19 23:03 d——– C:\Documents and Settings\Lumpy\Application Data\RegistrySmart
2008-02-18 21:09 . 2008-02-18 21:09 3,226 –a—— C:\WINDOWS\system32\tmp.reg
2008-02-18 21:04 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-02-18 21:04 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-02-18 21:04 . 2008-02-16 19:46 85,504 –a—— C:\WINDOWS\system32\VACFix.exe
2008-02-18 21:04 . 2008-02-08 10:37 82,432 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-02-18 21:04 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-02-18 09:42 . 2008-02-18 09:45 d——– C:\Program Files\Parental Control
2008-02-18 09:42 . 2008-02-18 09:42 d——– C:\Documents and Settings\Lumpy\Application Data\ParentalControl
2008-02-18 09:42 . 2008-02-22 00:45 d——– C:\Documents and Settings\All Users\Application Data\ParentalControl
2008-02-02 12:21 . 2008-02-02 12:21 d——– C:\Program Files\KONAMI
2008-01-23 22:49 . 2008-01-23 22:49 d——– C:\Documents and Settings\All Users\Application Data\Motive
2008-01-23 22:49 . 2005-07-12 00:28 69,632 –a—— C:\WINDOWS\system32\MCCDevice.dll
2008-01-23 22:49 . 2005-07-12 00:28 6,048 –a—— C:\WINDOWS\system32\MCC16.dll
2008-01-23 22:48 . 2008-01-29 09:48 d——– C:\Program Files\Common Files\Motive
2008-01-23 22:48 . 2008-01-23 22:49 29,540,732 –a—— C:\BellSouthIW.re~
2008-01-23 22:48 . 2002-02-13 19:53 6,345 -ra—— C:\WINDOWS\system32\DevMngr.vxd
2008-01-22 17:12 . 2003-02-28 18:26 139,536 –a—— C:\WINDOWS\system32\javaee.dll
2008-01-22 17:12 . 2003-02-28 18:26 46,352 –a—— C:\WINDOWS\setdebug.exe
2008-01-22 17:12 . 2003-02-28 16:54 7,315 –a—— C:\WINDOWS\system32\javasup.vxd
2008-01-22 17:12 . 2003-02-28 16:38 113 –a—— C:\WINDOWS\system32\zonedon.reg
2008-01-22 17:12 . 2003-02-28 16:38 113 –a—— C:\WINDOWS\system32\zonedoff.reg

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 06:38 ——— d—–w C:\Program Files\LimeWire
2008-02-22 06:37 ——— d—–w C:\Program Files\Incomplete
2008-02-22 03:52 ——— d—–w C:\Program Files\e-Sword
2008-02-22 01:17 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\AVG7
2008-02-08 12:12 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-08 05:21 ——— d—–w C:\Program Files\DivX
2008-01-12 01:14 ——— d—–w C:\Program Files\MSXML 6.0
2008-01-12 00:47 ——— d—–w C:\Program Files\MSXML 4.0
2008-01-06 04:39 715,248 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-12-26 06:22 ——— d—–w C:\Program Files\Java
2007-12-26 06:04 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\Grisoft
2007-12-26 05:40 ——— d—–w C:\Program Files\Serif
2007-12-26 05:32 ——— d—–w C:\Program Files\EA GAMES
2007-12-26 05:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2007-12-26 05:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-26 05:22 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-26 05:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-26 05:19 ——— d—–w C:\Program Files\Microsoft Games
2007-12-25 05:20 ——— d—–w C:\Program Files\Silent Hill
2007-12-25 05:18 720,896 —-a-w C:\WINDOWS\iun6002ev.exe
2007-12-24 19:29 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\IGN_DLM
2007-10-10 18:15 34,768 —-a-w C:\Documents and Settings\Lumpy\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-08-12 21:10 335872]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 16:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-12 19:51 185896]
"mm_server"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe" [2005-03-09 19:10 102400]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-24 03:24 282624]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-08 11:02 579072]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25 6731312]
"ParentalControl"="C:\Program Files\Parental Control\ParentalControl.exe" [2007-06-26 01:30 6088192]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-25 23:22 219136]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 00:56 53760 C:\WINDOWS\system32\narrator.exe]

C:\Documents and Settings\Lumpy\Start Menu\Programs\Startup\
TimeLeft.lnk - C:\Program Files\TimeLeft3\TimeLeft.exe [2007-01-11 03:56:51 1046016]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
MSI Wireless Utility.lnk - C:\Program Files\MSI\Common\RaUI.exe [2007-07-10 12:32:15 425984]
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-02-05 14:29:20 54512]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableClock"= 0 (0x0)
"NoDispCPL"= 0 (0x0)
"DisableRegistryTools"= 0 (0x0)
"DisableTaskMgr"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoMultiIE"= 0 (0x0)
"LWA"= 0 (0x0)
"LWB"= 0 (0x0)
"LWC"= 0 (0x0)
"LWD"= 0 (0x0)
"LWE"= 0 (0x0)
"LWF"= 0 (0x0)
"LWG"= 0 (0x0)
"LWH"= 0 (0x0)
"LWI"= 0 (0x0)
"LWJ"= 0 (0x0)
"LWK"= 0 (0x0)
"LWL"= 0 (0x0)
"LWM"= 0 (0x0)
"LWN"= 0 (0x0)
"LWO"= 0 (0x0)
"LWP"= 0 (0x0)
"LWQ"= 0 (0x0)
"LWR"= 0 (0x0)
"LWS"= 0 (0x0)
"LWT"= 0 (0x0)
"LWU"= 0 (0x0)
"LWV"= 0 (0x0)
"LWW"= 0 (0x0)
"LWX"= 0 (0x0)
"LWY"= 0 (0x0)
"LWZ"= 0 (0x0)
"NoRun"= 0 (0x0)
"NoFind"= 0 (0x0)

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoUpdate Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk
backup=C:\WINDOWS\pss\AutoUpdate Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
backup=C:\WINDOWS\pss\Billminder.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
backup=C:\WINDOWS\pss\Quicken Startup.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Wireless-B Notebook Adapter Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless-B Notebook Adapter Utility.lnk
backup=C:\WINDOWS\pss\Wireless-B Notebook Adapter Utility.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2007-03-12 12:49 153136 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
–a—— 2005-02-08 04:00 98304 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2006-09-25 14:54 229952 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
–a—— 2005-03-09 19:10 11776 C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2007-03-09 17:53 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-09-24 03:24 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-03-14 02:43 83608 C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2007-05-12 19:51 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"WebClient"=2 (0x2)
"TapiSrv"=3 (0x3)
"SharedAccess"=2 (0x2)
"SCardSvr"=3 (0x3)
"SamSs"=2 (0x2)
"RemoteAccess"=2 (0x2)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)
"mnmsrvc"=3 (0x3)
"Irmon"=2 (0x2)
"iPod Service"=3 (0x3)
"ImapiService"=3 (0x3)
"ERSvc"=2 (0x2)

R1 cp_drv;Crawler Parental Control Driver;C:\Documents and Settings\All Users\Application Data\ParentalControl\cp_drv.sys [2008-02-18 09:43]
R1 cp_tdifw_drv;cp_tdifw_drv;C:\Documents and Settings\All Users\Application Data\ParentalControl\cp_tdifw_drv.sys [2008-02-18 09:43]
R3 axsaki;axsaki;C:\WINDOWS\system32\DRIVERS\axsaki.sys [2003-03-30 21:38]
R3 axskbus;axskbus;C:\WINDOWS\system32\DRIVERS\axskbus.sys [2003-03-28 11:58]
S3 atimtai;atimtai;C:\WINDOWS\system32\DRIVERS\atimtai.sys [2001-08-17 12:48]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2750b1c1-69f7-11db-acb2-806d6172696f}]
\Shell\AutoRun\command - D:\BellSouth.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{529bcb50-b591-11db-9520-000f663bf8c6}]
\Shell\AutoRun\command - E:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{80514710-a727-11dc-9749-0019db91814c}]
\Shell\AutoRun\command - Desktop.ini
\Shell\explore\Command - Desktop.ini
\Shell\open\Command - Desktop.ini

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a09be9c0-689e-11db-9428-000f663bf8c6}]
\Shell\AutoRun\command - F:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a09be9c1-689e-11db-9428-000f663bf8c6}]
\Shell\AutoRun\command - Copy of Desktop.ini
\Shell\explore\Command - Copy of Desktop.ini
\Shell\open\Command - Copy of Desktop.ini

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a78c7c83-a82a-11dc-974c-0019db91814c}]
\Shell\AutoRun\command - Copy of Desktop.ini
\Shell\explore\Command - Copy of Desktop.ini
\Shell\open\Command - Copy of Desktop.ini

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b802da00-f2a5-11db-95ec-0008749c80da}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-02-18 22:26:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-10-17 22:32:12 C:\WINDOWS\Tasks\Low Battery Alarm Program.job"
"2008-02-22 09:30:00 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
- C:\Program Files\RegistrySmart\RegistrySmart.ex
- C:\Program Files\RegistrySmart
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-22 07:19:47
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
.
**************************************************************************
.
Completion time: 2008-02-22 7:22:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-22 13:22:53
ComboFix2.txt 2008-02-22 03:05:57
ComboFix3.txt 2008-02-22 01:22:00
ComboFix4.txt 2008-02-20 15:02:54
.
2008-02-13 13:21:10 — E O F —





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:30, on 2008-02-22
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Parental Control\ParentalControl.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\TimeLeft3\TimeLeft.exe
C:\WINDOWS\explorer.exe
C:\Program Files\MSI\Common\RaUI.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = wlan.pcci.edu
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mm_server] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ParentalControl] C:\Program Files\Parental Control\ParentalControl.Exe /SERVICE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: TimeLeft.lnk = C:\Program Files\TimeLeft3\TimeLeft.exe
O4 - Global Startup: MSI Wireless Utility.lnk = C:\Program Files\MSI\Common\RaUI.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162325755270
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162325746407
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Sophos AutoUpdate Service - Sony Corporation - (no file)

–
End of file - 6049 bytes
A. Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6u4.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u4-windowsi586-p.exe to install the newest version.


Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon.
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.


B. We have apparently deleted that pesky file. It must have been part of the "crack" that you were using. They are putting so much really evil stuff into those things right now that you are really compromising your system when you use these illegal tools. It took our biggest guns to rid your system of it. Next time you may not be so lucky.


C. After updating your Java, please post a fresh HijackThis log and tell me how your system is running. If all is well, we will proceed with the final cleanup procedures.


Trevuren
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:08, on 2008-02-22
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Parental Control\ParentalControl.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSI\Common\RaUI.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = wlan.pcci.edu
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mm_server] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ParentalControl] C:\Program Files\Parental Control\ParentalControl.Exe /SERVICE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: TimeLeft.lnk = C:\Program Files\TimeLeft3\TimeLeft.exe
O4 - Global Startup: MSI Wireless Utility.lnk = C:\Program Files\MSI\Common\RaUI.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162325755270
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162325746407
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Sophos AutoUpdate Service - Sony Corporation - (no file)

–
End of file - 5659 bytes
A. 1. Go to Start->Run and type in notepad and hit OK.

2. Then copy and paste the content of the following codebox into Notepad:

@Echo off
sc stop "Sophos AutoUpdate Service"
sc delete "Sophos AutoUpdate Service"
del delete.bat

3. Save the file as "delete.bat". Make sure to save it with the quotes. It should look like this on your desktop: [external image: Posted Image]

4. Double click delete.bat.


B. Please tell me how your system is running. If all is well, we will proceed with the final cleanup procedures.
Everything seems good. I haven't received any new notifications from AVG. The computer is overall running smoother. Is there any chance that bitsprx affected my cd drives (including virtual drives)?
My physical drive, one Alcohol virtual drive, and a Nero virtual drive all have stopped working. It says that the drivers are corrupted or missing, but when i attempt to download new drivers, it won't recognize them.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI