This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] cont'd cant get rid of virus

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I start my computer in safe mode and run SDFix it goes through its process and restarts. When i log back on it opens and continues it's scan, then the screen goes blue and my computer restarts itself. It's running really slow and i can't get rid of this virus. I also tried to run a boot scan with avast.
Hi

Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt in your next reply
Deckard's System Scanner v20071014.68
Run by [removed] on 2008-02-09 18:38:24
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
94: 2008-02-10 02:38:31 UTC - RP202 - Deckard's System Scanner Restore Point
93: 2008-02-09 08:10:24 UTC - RP201 - System Checkpoint
92: 2008-02-08 06:44:52 UTC - RP200 - System Checkpoint
91: 2008-02-07 03:34:23 UTC - RP199 - ComboFix created restore point
90: 2008-02-06 23:24:28 UTC - RP198 - Removed HP Software Update


– First Restore Point –
1: 2007-11-11 09:16:36 UTC - RP109 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



– HijackThis Clone ————————————————————


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-02-09 18:39:33
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Yahoo!\Parental Controls\ypc.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\YPcservice.exe
C:\WINDOWS\RTHDCPL.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Yahoo!\browser\ycommon.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\WinTV\Ir.exe
C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Michael\Desktop\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: e404 helper - {F10587E9-0E47-4CBE-ABCD-7DD20B8622FF} - C:\Program Files\Helper\1202351811.dll (file missing)
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [YPC] C:\PROGRA~1\Yahoo!\PARENT~1\ypc.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [drmsrv32] C:\arbfikac.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [EPSON Stylus CX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAA.EXE /FU "C:\DOCUME~1\Michael\LOCALS~1\Temp\E_S38.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
O4 - Global Startup: Windows Desktop Search.lnk = ?
O4 - Global Startup: Wireless Configuration Utility HW.14.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?4f6e62efdf9b47a88711428b6f88b80c
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?4f6e62efdf9b47a88711428b6f88b80c
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: YPCLSP.dllO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://www.driveragent.com/files/driveragent.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\Program Files\WinTV\HCWTVServer.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: RCService - Unknown owner - C:\Program Files\gigabyte\RCService\RCService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPcservice.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

–
End of file - 14390 bytes

– File Associations ———————————————————–

All associations okay.


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.4.5.0) - c:\windows\system32\drivers\aegisp.sys
Hi

If you already have Combofix, please delete that copy and download it again as it's being updated regularly.

Please download Combofix from Bleeping Computer.

If you can't download it from there, please try these 2 alternative sites:

Forospyware
Geeks to Go
  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Click Start>Run copy/paste or type "%userprofile%\desktop\combofix.exe" /killall into the Run box and click OK.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.

In your next reply post:
ComboFix.txt
New HijackThis log taken after the above scan has run
((((((((((((((((((((((((( Files Created from 2008-01-10 to 2008-02-10 )))))))))))))))))))))))))))))))
.

2008-02-09 18:38 . 2008-02-09 18:38 d——– C:\Deckard
2008-02-08 21:28 . 2008-02-08 21:28 d——– C:\Documents and Settings\Mike's Mom\Application Data\acccore
2008-02-06 19:51 . 2008-02-06 19:51 268 –ah—– C:\sqmdata17.sqm
2008-02-06 19:51 . 2008-02-06 19:51 244 –ah—– C:\sqmnoopt17.sqm
2008-02-06 19:32 . 2004-08-03 23:56 388,608 –a—— C:\kmd.exe
2008-02-06 19:17 . 2008-02-06 19:17 268 –ah—– C:\sqmdata16.sqm
2008-02-06 19:17 . 2008-02-06 19:17 244 –ah—– C:\sqmnoopt16.sqm
2008-02-06 19:02 . 2008-02-06 19:02 268 –ah—– C:\sqmdata15.sqm
2008-02-06 19:02 . 2008-02-06 19:02 244 –ah—– C:\sqmnoopt15.sqm
2008-02-06 18:36 . 2008-02-06 18:36 3,793,862 –a—— C:\WINDOWS\zwFqOxVylq.exe
2008-02-06 18:35 . 2008-02-06 18:46 d——– C:\WINDOWS\cblmwrrl
2008-02-06 18:35 . 2008-02-06 18:35 256,000 –a—— C:\WINDOWS\system32\apiuser32.dll
2008-02-06 18:35 . 2008-02-06 18:35 184,832 –a—— C:\WINDOWS\mfcliryx.dll
2008-02-06 18:35 . 2008-02-06 18:35 89,617 –a—— C:\WINDOWS\system32\rxjddnvj.exe
2008-02-06 18:35 . 2008-02-06 18:35 89,617 –a—— C:\WINDOWS\lelezwro.exe
2008-02-06 18:35 . 2008-02-06 18:35 58,368 –a—— C:\wpohl.exe
2008-02-06 18:35 . 2008-02-06 18:35 54,764 –a—— C:\WINDOWS\system32\jnhjkfrn
2008-02-06 18:35 . 2008-02-06 18:35 39,424 –a—— C:\WINDOWS\wpydgfwj.exe
2008-02-06 18:35 . 2008-02-06 18:35 32,768 –a—— C:\arbfikac.exe
2008-02-06 18:35 . 2008-02-06 18:35 3,584 –a—— C:\qrwkjyd.exe
2008-02-05 16:03 . 2008-02-05 16:03 d——– C:\Documents and Settings\Jason\WINDOWS
2008-02-04 17:07 . 2008-02-04 17:24 d——– C:\Program Files\Wolfenstein - Enemy Territory
2008-02-03 00:08 . 2008-02-04 20:48 d——– C:\vcs5BGEffects
2008-02-03 00:06 . 2008-02-03 00:16 d——– C:\Program Files\AV Vcs 6.0 DIAMOND
2008-02-02 21:01 . 2008-02-02 21:01 dr-h—– C:\Documents and Settings\Mike's Mom\Application Data\SecuROM
2008-02-02 12:10 . 2008-02-02 12:10 dr-h—– C:\Documents and Settings\Guest\Application Data\SecuROM
2008-02-02 00:18 . 2008-02-02 00:18 dr-h—– C:\Documents and Settings\Jason\Application Data\SecuROM
2008-01-31 20:50 . 2008-01-31 20:50 d——– C:\Program Files\RivaTuner v2.06
2008-01-31 15:10 . 2008-01-31 15:10 d——– C:\Program Files\uTorrent
2008-01-31 15:10 . 2008-02-10 04:41 d——– C:\Documents and Settings\Michael\Application Data\uTorrent
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\Common Files\Motive
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\ATT
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Documents and Settings\All Users\Application Data\Motive
2008-01-30 14:54 . 2008-01-30 14:54 268 –ah—– C:\sqmdata14.sqm
2008-01-30 14:54 . 2008-01-30 14:54 244 –ah—– C:\sqmnoopt14.sqm
2008-01-30 14:30 . 2008-01-30 14:30 d——– C:\WINDOWS\ERUNT
2008-01-30 14:26 . 2008-02-09 13:44 d——– C:\SDFix
2008-01-30 14:12 . 2008-01-30 14:12 268 –ah—– C:\sqmdata13.sqm
2008-01-30 14:12 . 2008-01-30 14:12 244 –ah—– C:\sqmnoopt13.sqm
2008-01-30 13:00 . 2008-01-30 13:00 268 –ah—– C:\sqmdata12.sqm
2008-01-30 13:00 . 2008-01-30 13:00 244 –ah—– C:\sqmnoopt12.sqm
2008-01-29 19:32 . 2008-01-29 19:32 268 –ah—– C:\sqmdata11.sqm
2008-01-29 19:32 . 2008-01-29 19:32 244 –ah—– C:\sqmnoopt11.sqm
2008-01-26 20:47 . 2008-01-26 20:47 d——– C:\Documents and Settings\Jason\.jagex_cache_32
2008-01-26 20:19 . 2008-01-26 20:19 d——– C:\Documents and Settings\Michael\Application Data\EPSON
2008-01-22 22:45 . 2008-01-27 22:05 d——– C:\Program Files\DNA
2008-01-22 22:45 . 2008-01-25 12:47 d——– C:\Documents and Settings\Michael\Application Data\BitTorrent
2008-01-21 00:59 . 2008-01-21 00:59 244 –ah—– C:\sqmnoopt10.sqm
2008-01-21 00:59 . 2008-01-21 00:59 232 –ah—– C:\sqmdata10.sqm
2008-01-17 16:13 . 2008-01-17 16:47 d——– C:\HLServer
2008-01-17 16:02 . 2008-01-17 16:46 d——– C:\Documents and Settings\Michael\Application Data\GetRightToGo
2008-01-17 14:16 . 2008-01-17 14:16 268 –ah—– C:\sqmdata09.sqm
2008-01-17 14:16 . 2008-01-17 14:16 244 –ah—– C:\sqmnoopt09.sqm
2008-01-12 13:22 . 2008-01-12 13:22 d——– C:\Documents and Settings\Mike's Mom\Application Data\Disney Interactive Studios

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-10 09:32 ——— d—–w C:\Program Files\Steam
2008-02-10 02:33 6,776 —-a-w C:\Documents and Settings\All Users\Application Data\ypinfo.bin
2008-02-09 03:38 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\Yahoo!
2008-02-09 02:26 ——— d—–w C:\Documents and Settings\Michael\Application Data\LimeWire
2008-02-08 04:00 ——— d—–w C:\Program Files\WinTV
2008-02-06 23:46 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-06 23:24 ——— d—–w C:\Program Files\HP
2008-02-06 01:14 ——— d—–w C:\Program Files\AIMTunes
2008-02-01 23:15 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-01 23:15 ——— d—–w C:\Program Files\Sierra
2008-01-30 22:51 ——— d—–w C:\Program Files\Real
2008-01-29 21:05 ——— d—–w C:\Documents and Settings\Michael\Application Data\Xfire
2008-01-17 23:58 ——— d—–w C:\Documents and Settings\Michael\Application Data\IGN_DLM
2008-01-10 01:30 ——— d—–w C:\Documents and Settings\Jason\Application Data\Disney Interactive Studios
2008-01-07 05:34 ——— d—–w C:\Documents and Settings\Michael\Application Data\Disney Interactive Studios
2008-01-07 01:59 ——— d—–w C:\Documents and Settings\Jason\Application Data\Ahead
2007-12-31 15:21 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\DivX
2007-12-30 06:54 ——— d—–w C:\Program Files\Audacity
2007-12-26 06:55 ——— d—–w C:\Program Files\ACE-HIGH MP3 WAV WMA OGG Converter
2007-12-26 06:52 ——— d—–w C:\Program Files\MP3 Converter Simple
2007-12-23 16:24 ——— d—–w C:\Program Files\QuickTime
2007-12-22 23:37 ——— d—–w C:\Program Files\iTunes
2007-12-22 23:37 ——— d—–w C:\Program Files\iPod
2007-12-22 23:11 ——— d—–w C:\Program Files\Common Files\Download Manager
2007-12-22 02:35 ——— d—–w C:\Program Files\AV Vcs 5.0 DIAMOND
2007-12-20 01:56 ——— d—–w C:\Program Files\Illustrate
2007-12-17 01:02 ——— d—–w C:\Documents and Settings\Jason\Application Data\DivX
2007-12-14 22:17 ——— d—–w C:\Program Files\DivX
2007-12-12 01:12 ——— d—–w C:\Documents and Settings\valuable customer\Application Data\HP
2007-12-10 07:00 ——— d—–w C:\Program Files\OOBOX
2007-12-03 06:52 47,360 —-a-w C:\Documents and Settings\Michael\Application Data\pcouffin.sys
2007-12-03 06:43 356,352 —-a-w C:\WINDOWS\eSellerateEngine.dll
2007-10-11 03:05 22,328 —-a-w C:\Documents and Settings\Michael\Application Data\PnkBstrK.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}]
C:\Program Files\Helper\1202351811.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 17:05 143360]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"Steam"="c:\program files\steam\steam.exe" [2007-11-29 17:33 1266936]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 13:57 1103480]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-09-29 12:22 50528]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24 1694208]
"EPSON Stylus CX4400 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAA.exe" [2007-01-25 05:00 179200]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 01:33 16132608 C:\WINDOWS\RTHDCPL.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 23:43 8466432]
"nwiz"="nwiz.exe" [2007-06-28 23:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-28 23:43 81920]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 17:08 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 17:09 842584]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 08:30 81920]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" [ ]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 15:19 129536]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 23:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2007-06-26 12:48 509224]
"YPC"="C:\PROGRA~1\Yahoo!\PARENT~1\ypc.exe" [2005-02-11 17:14 352256]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2006-09-08 15:47 277296]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51 39792]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2007-11-06 19:09 166304]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-06 18:28 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]
"drmsrv32"="C:\arbfikac.exe" [2008-02-06 18:35 32768]

C:\Documents and Settings\valuable customer\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

C:\Documents and Settings\Guest\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

C:\Documents and Settings\Mike's Mom\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoStart IR.lnk - C:\Program Files\WinTV\Ir.exe [2007-10-10 16:33:07 106551]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 21:44:08 257752]
Wireless Configuration Utility HW.14.lnk - C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe [2007-06-07 17:05:22 634880]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 12:11 233472]

R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2006-09-08 15:47]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 13:38]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-06 18:58]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-06 19:09]
R3 hcw18bda;Hauppauge WinTV 418 Driver;C:\WINDOWS\system32\drivers\hcw18bda.sys [2007-05-10 10:43]
R3 MSHUSBVideo;NX6000 Filter Driver;C:\WINDOWS\system32\Drivers\nx6000.sys [2006-08-23 16:33]
S2 RCService;RCService;"C:\Program Files\gigabyte\RCService\RCService.exe" []
S3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys []
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2007-09-25 17:18]
S3 HauppaugeTVServer;HauppaugeTVServer;C:\PROGRA~1\WinTV\HCWTVS~1.EXE [2007-02-20 14:11]
S3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;C:\WINDOWS\system32\DRIVERS\RTL8187B.sys [2007-05-04 04:40]
S3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2002-10-01 17:57]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-06 19:10]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-07 05:00:00 C:\WINDOWS\Tasks\!Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-02-08 04:00:00 C:\WINDOWS\Tasks\!smallville.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-02-07 06:01:13 C:\WINDOWS\Tasks\Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\BGRecorder.exeC -c3 -ntod -startr:Bionic_Woman_1114_2100###.mpg -qdef -limit:3660
"2008-02-10 13:38:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-08 04:05:14 C:\WINDOWS\Tasks\smallville.job"
- C:\PROGRA~1\WinTV\BGRecorder.exe8 -c12 -ntod -startr:smallville###.mpg -qdef -limit:3600
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-10 06:00:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-10 6:02:32
ComboFix-quarantined-files.txt 2008-02-10 14:02:29
ComboFix2.txt 2008-02-07 03:44:33
.
2008-01-09 07:46:14 — E O F —
Hi

Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\sqmdata17.sqm
C:\sqmnoopt17.sqm
C:\sqmdata16.sqm
C:\sqmnoopt16.sqm
C:\sqmdata15.sqm
C:\sqmnoopt15.sqm
C:\WINDOWS\zwFqOxVylq.exe
C:\WINDOWS\system32\apiuser32.dll
C:\WINDOWS\mfcliryx.dll
C:\WINDOWS\system32\rxjddnvj.exe
C:\WINDOWS\lelezwro.exe
C:\wpohl.exe
C:\WINDOWS\system32\jnhjkfrn
C:\WINDOWS\wpydgfwj.exe
C:\arbfikac.exe
C:\qrwkjyd.exe
C:\sqmdata14.sqm
C:\sqmnoopt14.sqm
C:\sqmdata13.sqm
C:\sqmnoopt13.sqm
C:\sqmdata12.sqm
C:\sqmnoopt12.sqm
C:\sqmdata11.sqm
C:\sqmnoopt11.sqm
C:\sqmnoopt10.sqm
C:\sqmdata10.sqm
C:\sqmdata09.sqm
C:\sqmnoopt09.sqm

Folder::
C:\WINDOWS\cblmwrrl
C:\SDFix
C:\Program Files\Helper

DirLook::
C:\Documents and Settings\Jason\WINDOWS

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"drmsrv32"=-

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Go to Start > Control Panel > Display Properties > Desktop > Customize Desktop… > Web tab
Select everything named Privacy Protection or privacy_danger you find in there and press the Delete button on the right.
Hit OK then Apply in previous window.


In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run
ComboFix 08-02.05.3 - Michael 2008-02-10 15:11:45.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2347 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Michael\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\arbfikac.exe
C:\qrwkjyd.exe
C:\sqmdata09.sqm
C:\sqmdata10.sqm
C:\sqmdata11.sqm
C:\sqmdata12.sqm
C:\sqmdata13.sqm
C:\sqmdata14.sqm
C:\sqmdata15.sqm
C:\sqmdata16.sqm
C:\sqmdata17.sqm
C:\sqmnoopt09.sqm
C:\sqmnoopt10.sqm
C:\sqmnoopt11.sqm
C:\sqmnoopt12.sqm
C:\sqmnoopt13.sqm
C:\sqmnoopt14.sqm
C:\sqmnoopt15.sqm
C:\sqmnoopt16.sqm
C:\sqmnoopt17.sqm
C:\WINDOWS\lelezwro.exe
C:\WINDOWS\mfcliryx.dll
C:\WINDOWS\system32\apiuser32.dll
C:\WINDOWS\system32\jnhjkfrn
C:\WINDOWS\system32\rxjddnvj.exe
C:\WINDOWS\wpydgfwj.exe
C:\WINDOWS\zwFqOxVylq.exe
C:\wpohl.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\jnhjkfrn
C:\arbfikac.exe
C:\qrwkjyd.exe
C:\SDFix
C:\SDFix\apps\assosfix.reg
C:\SDFix\apps\cliptext.exe
C:\SDFix\apps\download.exe
C:\SDFix\apps\dummy.exe
C:\SDFix\apps\dummy.sys
C:\SDFix\apps\Enable_Command_Prompt.reg
C:\SDFix\apps\ERDNT.E_E
C:\SDFix\apps\ERDNTDOS.LOC
C:\SDFix\apps\ERDNTWIN.LOC
C:\SDFix\apps\ERUNT.EXE
C:\SDFix\apps\ERUNT.LOC
C:\SDFix\apps\fix.reg
C:\SDFix\apps\FixBH.reg
C:\SDFix\apps\FIXCU.reg
C:\SDFix\apps\FIXLM.reg
C:\SDFix\apps\FixPath.exe
C:\SDFix\apps\FixRedir.reg
C:\SDFix\apps\FixSchedule.reg
C:\SDFix\apps\FixSubSystems.reg
C:\SDFix\apps\FixWebCheck.reg
C:\SDFix\apps\fixXP.reg
C:\SDFix\apps\FixXPsp2.reg
C:\SDFix\apps\HPFix.reg
C:\SDFix\apps\HPFix2.reg
C:\SDFix\apps\HPFix3.reg
C:\SDFix\apps\HPFix4.reg
C:\SDFix\apps\isadmin.exe
C:\SDFix\apps\leg2.txt
C:\SDFix\apps\legacy.txt
C:\SDFix\apps\legacybk.txt
C:\SDFix\apps\locate.com
C:\SDFix\apps\LS.exe
C:\SDFix\apps\MD5File.exe
C:\SDFix\apps\MyGcpvFix.reg
C:\SDFix\apps\MyGkFix2.reg
C:\SDFix\apps\Process.exe
C:\SDFix\apps\procs.exe
C:\SDFix\apps\psservice.exe
C:\SDFix\apps\RegDACL.exe
C:\SDFix\apps\regedit.exe
C:\SDFix\apps\Rem.txt
C:\SDFix\apps\Rem2.txt
C:\SDFix\apps\Replace\W2K.exe
C:\SDFix\apps\Replace\w2k\beep.sys
C:\SDFix\apps\Replace\w2k\null.sys
C:\SDFix\apps\Replace\XP.exe
C:\SDFix\apps\Replace\xp\beep.sys
C:\SDFix\apps\Replace\xp\null.sys
C:\SDFix\apps\Reset_AppInit_DLLs.reg
C:\SDFix\apps\RestartIt!.exe
C:\SDFix\apps\Restore_SecurityCenter.reg
C:\SDFix\apps\Restore_SharedAccess.reg
C:\SDFix\apps\sc.exe
C:\SDFix\apps\SecPro1.reg
C:\SDFix\apps\SecPro2.reg
C:\SDFix\apps\SecPro3.reg
C:\SDFix\apps\SecPro4.reg
C:\SDFix\apps\SecurityProviders.reg
C:\SDFix\apps\SF.exe
C:\SDFix\apps\shutdown.exe
C:\SDFix\apps\srv2.txt
C:\SDFix\apps\srv2bk.txt
C:\SDFix\apps\svc.txt
C:\SDFix\apps\svcbk.txt
C:\SDFix\apps\swreg.exe
C:\SDFix\apps\swsc.exe
C:\SDFix\apps\unzip.exe
C:\SDFix\apps\WINMSG.EXE
C:\SDFix\apps\winsec.reg
C:\SDFix\apps\zip.exe
C:\SDFix\attrib.exe
C:\SDFix\backups\backupreg.zip
C:\SDFix\backups\backups.zip
C:\SDFix\backups_old1\backupreg.zip
C:\SDFix\backups_old1\backups.zip
C:\SDFix\backups_old2\backupreg.zip
C:\SDFix\backups_old2\backups.zip
C:\SDFix\backups_old3\attrib.exe
C:\SDFix\backups_old3\backupreg.zip
C:\SDFix\backups_old3\backups.zip
C:\SDFix\backups_old3\find.exe
C:\SDFix\backups_old3\findstr.exe
C:\SDFix\backups_old3\regedit.exe
C:\SDFix\bpTEST1.TXT
C:\SDFix\bpTEST3.TXT
C:\SDFix\catchme.exe
C:\SDFix\Catchme.log
C:\SDFix\CheckRuns.txt
C:\SDFix\clean.reg
C:\SDFix\delzip0.txt
C:\SDFix\dest.txt
C:\SDFix\dummy.exe
C:\SDFix\dummy.sys
C:\SDFix\FileList1.txt
C:\SDFix\FileList2.txt
C:\SDFix\find.exe
C:\SDFix\Find.txt
C:\SDFix\Findbhos1.txt
C:\SDFix\FindMurlo.txt
C:\SDFix\Findrun.txt
C:\SDFix\Findrun155.txt
C:\SDFix\Findrun2.txt
C:\SDFix\Findrun3.txt
C:\SDFix\Findrun30.txt
C:\SDFix\Findrun31.txt
C:\SDFix\findstr.exe
C:\SDFix\Findzip.txt
C:\SDFix\HOSTS
C:\SDFix\ndloc.txt
C:\SDFix\Patched2.txt
C:\SDFix\regedit.exe
C:\SDFix\Report.txt
C:\SDFix\Report_old_1.txt
C:\SDFix\Report_old_2.txt
C:\SDFix\Report_old_3.txt
C:\SDFix\RunThis.bat
C:\SDFix\SDFIX_ReadMe_Online.url
C:\SDFix\TEST800.TXT
C:\SDFix\TEST801.TXT
C:\SDFix\TEST802.TXT
C:\SDFix\TEST803.TXT
C:\SDFix\TEST804.TXT
C:\SDFix\TEST805.TXT
C:\SDFix\TEST806.TXT
C:\SDFix\TEST808.TXT
C:\SDFix\TEST811.TXT
C:\SDFix\TEST812.TXT
C:\SDFix\TESTADS1.txt
C:\SDFix\TESTADS2.txt
C:\SDFix\TESTADS3.txt
C:\SDFix\TESTADS4.txt
C:\SDFix\TESTADS5.txt
C:\SDFix\TESTADS6.txt
C:\SDFix\TESTSecPro2.txt
C:\sqmdata09.sqm
C:\sqmdata10.sqm
C:\sqmdata11.sqm
C:\sqmdata12.sqm
C:\sqmdata13.sqm
C:\sqmdata14.sqm
C:\sqmdata15.sqm
C:\sqmdata16.sqm
C:\sqmdata17.sqm
C:\sqmnoopt09.sqm
C:\sqmnoopt10.sqm
C:\sqmnoopt11.sqm
C:\sqmnoopt12.sqm
C:\sqmnoopt13.sqm
C:\sqmnoopt14.sqm
C:\sqmnoopt15.sqm
C:\sqmnoopt16.sqm
C:\sqmnoopt17.sqm
C:\WINDOWS\cblmwrrl
C:\WINDOWS\cblmwrrl\Thumbs.db
C:\WINDOWS\lelezwro.exe
C:\WINDOWS\mfcliryx.dll
C:\WINDOWS\system32\apiuser32.dll
C:\WINDOWS\system32\jnhjkfrn
C:\WINDOWS\system32\rxjddnvj.exe
C:\WINDOWS\wpydgfwj.exe
C:\WINDOWS\zwFqOxVylq.exe
C:\wpohl.exe

.
((((((((((((((((((((((((( Files Created from 2008-01-10 to 2008-02-10 )))))))))))))))))))))))))))))))
.

2008-02-10 06:00 . 2004-08-03 23:56 388,608 –a—— C:\kmd.exe
2008-02-09 18:38 . 2008-02-09 18:38 d——– C:\Deckard
2008-02-08 21:28 . 2008-02-08 21:28 d——– C:\Documents and Settings\Mike's Mom\Application Data\acccore
2008-02-05 16:03 . 2008-02-05 16:03 d——– C:\Documents and Settings\Jason\WINDOWS
2008-02-04 17:07 . 2008-02-04 17:24 d——– C:\Program Files\Wolfenstein - Enemy Territory
2008-02-03 00:08 . 2008-02-04 20:48 d——– C:\vcs5BGEffects
2008-02-03 00:06 . 2008-02-03 00:16 d——– C:\Program Files\AV Vcs 6.0 DIAMOND
2008-02-02 21:01 . 2008-02-02 21:01 dr-h—– C:\Documents and Settings\Mike's Mom\Application Data\SecuROM
2008-02-02 12:10 . 2008-02-02 12:10 dr-h—– C:\Documents and Settings\Guest\Application Data\SecuROM
2008-02-02 00:18 . 2008-02-02 00:18 dr-h—– C:\Documents and Settings\Jason\Application Data\SecuROM
2008-01-31 20:50 . 2008-01-31 20:50 d——– C:\Program Files\RivaTuner v2.06
2008-01-31 15:10 . 2008-01-31 15:10 d——– C:\Program Files\uTorrent
2008-01-31 15:10 . 2008-02-10 15:04 d——– C:\Documents and Settings\Michael\Application Data\uTorrent
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\Common Files\Motive
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\ATT
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Documents and Settings\All Users\Application Data\Motive
2008-01-30 14:30 . 2008-01-30 14:30 d——– C:\WINDOWS\ERUNT
2008-01-26 20:47 . 2008-01-26 20:47 d——– C:\Documents and Settings\Jason\.jagex_cache_32
2008-01-26 20:19 . 2008-01-26 20:19 d——– C:\Documents and Settings\Michael\Application Data\EPSON
2008-01-22 22:45 . 2008-01-27 22:05 d——– C:\Program Files\DNA
2008-01-22 22:45 . 2008-01-25 12:47 d——– C:\Documents and Settings\Michael\Application Data\BitTorrent
2008-01-17 16:13 . 2008-01-17 16:47 d——– C:\HLServer
2008-01-17 16:02 . 2008-01-17 16:46 d——– C:\Documents and Settings\Michael\Application Data\GetRightToGo
2008-01-12 13:22 . 2008-01-12 13:22 d——– C:\Documents and Settings\Mike's Mom\Application Data\Disney Interactive Studios

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-10 23:17 ——— d—–w C:\Program Files\Steam
2008-02-10 02:33 6,776 —-a-w C:\Documents and Settings\All Users\Application Data\ypinfo.bin
2008-02-09 03:38 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\Yahoo!
2008-02-09 02:26 ——— d—–w C:\Documents and Settings\Michael\Application Data\LimeWire
2008-02-08 04:00 ——— d—–w C:\Program Files\WinTV
2008-02-06 23:46 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-06 23:24 ——— d—–w C:\Program Files\HP
2008-02-06 01:14 ——— d—–w C:\Program Files\AIMTunes
2008-02-01 23:15 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-01 23:15 ——— d—–w C:\Program Files\Sierra
2008-01-30 22:51 ——— d—–w C:\Program Files\Real
2008-01-29 21:05 ——— d—–w C:\Documents and Settings\Michael\Application Data\Xfire
2008-01-17 23:58 ——— d—–w C:\Documents and Settings\Michael\Application Data\IGN_DLM
2008-01-10 01:30 ——— d—–w C:\Documents and Settings\Jason\Application Data\Disney Interactive Studios
2008-01-07 05:34 ——— d—–w C:\Documents and Settings\Michael\Application Data\Disney Interactive Studios
2008-01-07 01:59 ——— d—–w C:\Documents and Settings\Jason\Application Data\Ahead
2007-12-31 15:21 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\DivX
2007-12-30 06:54 ——— d—–w C:\Program Files\Audacity
2007-12-26 06:55 ——— d—–w C:\Program Files\ACE-HIGH MP3 WAV WMA OGG Converter
2007-12-26 06:52 ——— d—–w C:\Program Files\MP3 Converter Simple
2007-12-23 16:24 ——— d—–w C:\Program Files\QuickTime
2007-12-22 23:37 ——— d—–w C:\Program Files\iTunes
2007-12-22 23:37 ——— d—–w C:\Program Files\iPod
2007-12-22 23:11 ——— d—–w C:\Program Files\Common Files\Download Manager
2007-12-22 02:35 ——— d—–w C:\Program Files\AV Vcs 5.0 DIAMOND
2007-12-20 01:56 ——— d—–w C:\Program Files\Illustrate
2007-12-17 01:02 ——— d—–w C:\Documents and Settings\Jason\Application Data\DivX
2007-12-14 22:17 ——— d—–w C:\Program Files\DivX
2007-12-12 01:12 ——— d—–w C:\Documents and Settings\valuable customer\Application Data\HP
2007-12-10 07:00 ——— d—–w C:\Program Files\OOBOX
2007-12-03 06:52 47,360 —-a-w C:\Documents and Settings\Michael\Application Data\pcouffin.sys
2007-12-03 06:43 356,352 —-a-w C:\WINDOWS\eSellerateEngine.dll
2007-10-11 03:05 22,328 —-a-w C:\Documents and Settings\Michael\Application Data\PnkBstrK.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Documents and Settings\Jason\WINDOWS —-



((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 17:05 143360]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"Steam"="c:\program files\steam\steam.exe" [2007-11-29 17:33 1266936]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 13:57 1103480]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-09-29 12:22 50528]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24 1694208]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 01:33 16132608 C:\WINDOWS\RTHDCPL.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 23:43 8466432]
"nwiz"="nwiz.exe" [2007-06-28 23:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-28 23:43 81920]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 17:08 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 17:09 842584]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 08:30 81920]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" [ ]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 15:19 129536]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 23:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2007-06-26 12:48 509224]
"YPC"="C:\PROGRA~1\Yahoo!\PARENT~1\ypc.exe" [2005-02-11 17:14 352256]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2006-09-08 15:47 277296]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51 39792]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2007-11-06 19:09 166304]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-06 18:28 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]

C:\Documents and Settings\valuable customer\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

C:\Documents and Settings\Guest\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

C:\Documents and Settings\Mike's Mom\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoStart IR.lnk - C:\Program Files\WinTV\Ir.exe [2007-10-10 16:33:07 106551]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 21:44:08 257752]
Wireless Configuration Utility HW.14.lnk - C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe [2007-06-07 17:05:22 634880]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 12:11 233472]

R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2006-09-08 15:47]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 13:38]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-06 18:58]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-06 19:09]
R3 hcw18bda;Hauppauge WinTV 418 Driver;C:\WINDOWS\system32\drivers\hcw18bda.sys [2007-05-10 10:43]
R3 MSHUSBVideo;NX6000 Filter Driver;C:\WINDOWS\system32\Drivers\nx6000.sys [2006-08-23 16:33]
S1 jnhjkfrn;jnhjkfrn;C:\WINDOWS\system32\jnhjkfrn []
S2 RCService;RCService;"C:\Program Files\gigabyte\RCService\RCService.exe" []
S3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys []
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2007-09-25 17:18]
S3 HauppaugeTVServer;HauppaugeTVServer;C:\PROGRA~1\WinTV\HCWTVS~1.EXE [2007-02-20 14:11]
S3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;C:\WINDOWS\system32\DRIVERS\RTL8187B.sys [2007-05-04 04:40]
S3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2002-10-01 17:57]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-06 19:10]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-07 05:00:00 C:\WINDOWS\Tasks\!Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-02-08 04:00:00 C:\WINDOWS\Tasks\!smallville.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-02-07 06:01:13 C:\WINDOWS\Tasks\Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\BGRecorder.exeC -c3 -ntod -startr:Bionic_Woman_1114_2100###.mpg -qdef -limit:3660
"2008-02-10 22:38:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-08 04:05:14 C:\WINDOWS\Tasks\smallville.job"
- C:\PROGRA~1\WinTV\BGRecorder.exe8 -c12 -ntod -startr:smallville###.mpg -qdef -limit:3600
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-10 15:18:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\Program Files\Zune\ZuneNss.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\system32\YPCSER~1.EXE
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-02-10 15:20:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-10 23:20:49
ComboFix2.txt 2008-02-10 14:02:32
ComboFix3.txt 2008-02-07 03:44:33
.
2008-01-09 07:46:14 — E O F —
the one above i forgot to turn off my antivirus and disconnect from the internet


((((((((((((((((((((((((( Files Created from 2008-01-10 to 2008-02-10 )))))))))))))))))))))))))))))))
.

2008-02-10 15:40 . 2008-02-10 15:43 d——– C:\Program Files\Helper
2008-02-10 15:40 . 2008-02-10 15:43 58,368 –a—— C:\wpohl.exe
2008-02-10 15:40 . 2008-02-10 15:40 54,764 –a—— C:\WINDOWS\system32\4fdw.dll
2008-02-10 15:40 . 2008-02-10 15:43 6,638 –a—— C:\WINDOWS\system32\conf.dat
2008-02-10 15:40 . 2008-02-10 15:43 3,584 –a—— C:\qrwkjyd.exe
2008-02-10 15:40 . 2008-02-10 15:44 2 –a—— C:\-1401996986
2008-02-10 15:39 . 2008-02-10 15:39 40,960 –a—— C:\WINDOWS\system32\wvuvuvv.dll
2008-02-10 15:34 . 2008-02-10 15:35 d——– C:\WINDOWS\LastGood
2008-02-10 15:25 . 2008-02-10 15:25 d——– C:\Program Files\THQ
2008-02-10 15:10 . 2004-08-03 23:56 388,608 –a—— C:\kmd.exe
2008-02-09 18:38 . 2008-02-09 18:38 d——– C:\Deckard
2008-02-08 21:28 . 2008-02-08 21:28 d——– C:\Documents and Settings\Mike's Mom\Application Data\acccore
2008-02-05 16:03 . 2008-02-05 16:03 d——– C:\Documents and Settings\Jason\WINDOWS
2008-02-04 17:07 . 2008-02-04 17:24 d——– C:\Program Files\Wolfenstein - Enemy Territory
2008-02-03 00:08 . 2008-02-04 20:48 d——– C:\vcs5BGEffects
2008-02-03 00:06 . 2008-02-03 00:16 d——– C:\Program Files\AV Vcs 6.0 DIAMOND
2008-02-02 21:01 . 2008-02-02 21:01 dr-h—– C:\Documents and Settings\Mike's Mom\Application Data\SecuROM
2008-02-02 12:10 . 2008-02-02 12:10 dr-h—– C:\Documents and Settings\Guest\Application Data\SecuROM
2008-02-02 00:18 . 2008-02-02 00:18 dr-h—– C:\Documents and Settings\Jason\Application Data\SecuROM
2008-01-31 20:50 . 2008-01-31 20:50 d——– C:\Program Files\RivaTuner v2.06
2008-01-31 15:10 . 2008-01-31 15:10 d——– C:\Program Files\uTorrent
2008-01-31 15:10 . 2008-02-10 15:36 d——– C:\Documents and Settings\Michael\Application Data\uTorrent
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\Common Files\Motive
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\ATT
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Documents and Settings\All Users\Application Data\Motive
2008-01-30 14:30 . 2008-01-30 14:30 d——– C:\WINDOWS\ERUNT
2008-01-26 20:47 . 2008-01-26 20:47 d——– C:\Documents and Settings\Jason\.jagex_cache_32
2008-01-26 20:19 . 2008-01-26 20:19 d——– C:\Documents and Settings\Michael\Application Data\EPSON
2008-01-22 22:45 . 2008-01-27 22:05 d——– C:\Program Files\DNA
2008-01-22 22:45 . 2008-01-25 12:47 d——– C:\Documents and Settings\Michael\Application Data\BitTorrent
2008-01-17 16:13 . 2008-01-17 16:47 d——– C:\HLServer
2008-01-17 16:02 . 2008-01-17 16:46 d——– C:\Documents and Settings\Michael\Application Data\GetRightToGo
2008-01-12 13:22 . 2008-01-12 13:22 d——– C:\Documents and Settings\Mike's Mom\Application Data\Disney Interactive Studios

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-10 23:42 ——— d—–w C:\Program Files\Steam
2008-02-10 02:33 6,776 —-a-w C:\Documents and Settings\All Users\Application Data\ypinfo.bin
2008-02-09 03:38 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\Yahoo!
2008-02-09 02:26 ——— d—–w C:\Documents and Settings\Michael\Application Data\LimeWire
2008-02-08 04:00 ——— d—–w C:\Program Files\WinTV
2008-02-06 23:46 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-06 23:24 ——— d—–w C:\Program Files\HP
2008-02-06 01:14 ——— d—–w C:\Program Files\AIMTunes
2008-02-01 23:15 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-01 23:15 ——— d—–w C:\Program Files\Sierra
2008-01-30 22:51 ——— d—–w C:\Program Files\Real
2008-01-29 21:05 ——— d—–w C:\Documents and Settings\Michael\Application Data\Xfire
2008-01-17 23:58 ——— d—–w C:\Documents and Settings\Michael\Application Data\IGN_DLM
2008-01-10 01:30 ——— d—–w C:\Documents and Settings\Jason\Application Data\Disney Interactive Studios
2008-01-07 05:34 ——— d—–w C:\Documents and Settings\Michael\Application Data\Disney Interactive Studios
2008-01-07 01:59 ——— d—–w C:\Documents and Settings\Jason\Application Data\Ahead
2007-12-31 15:21 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\DivX
2007-12-30 06:54 ——— d—–w C:\Program Files\Audacity
2007-12-26 06:55 ——— d—–w C:\Program Files\ACE-HIGH MP3 WAV WMA OGG Converter
2007-12-26 06:52 ——— d—–w C:\Program Files\MP3 Converter Simple
2007-12-23 16:24 ——— d—–w C:\Program Files\QuickTime
2007-12-22 23:37 ——— d—–w C:\Program Files\iTunes
2007-12-22 23:37 ——— d—–w C:\Program Files\iPod
2007-12-22 23:11 ——— d—–w C:\Program Files\Common Files\Download Manager
2007-12-22 02:35 ——— d—–w C:\Program Files\AV Vcs 5.0 DIAMOND
2007-12-20 01:56 ——— d—–w C:\Program Files\Illustrate
2007-12-17 01:02 ——— d—–w C:\Documents and Settings\Jason\Application Data\DivX
2007-12-14 22:17 ——— d—–w C:\Program Files\DivX
2007-12-12 01:12 ——— d—–w C:\Documents and Settings\valuable customer\Application Data\HP
2007-12-10 07:00 ——— d—–w C:\Program Files\OOBOX
2007-12-03 06:52 47,360 —-a-w C:\Documents and Settings\Michael\Application Data\pcouffin.sys
2007-12-03 06:43 356,352 —-a-w C:\WINDOWS\eSellerateEngine.dll
2007-10-11 03:05 22,328 —-a-w C:\Documents and Settings\Michael\Application Data\PnkBstrK.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6607E676-1BDE-4cb3-9913-4DC5EBCAE35E}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}]
2008-02-10 15:43 12800 –a—— C:\Program Files\Helper\1202687036.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 17:05 143360]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"Steam"="c:\program files\steam\steam.exe" [2007-11-29 17:33 1266936]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 13:57 1103480]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-09-29 12:22 50528]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24 1694208]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 01:33 16132608 C:\WINDOWS\RTHDCPL.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 23:43 8466432]
"nwiz"="nwiz.exe" [2007-06-28 23:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-28 23:43 81920]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 17:08 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 17:09 842584]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 08:30 81920]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" [ ]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 15:19 129536]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 23:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2007-06-26 12:48 509224]
"YPC"="C:\PROGRA~1\Yahoo!\PARENT~1\ypc.exe" [2005-02-11 17:14 352256]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2006-09-08 15:47 277296]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51 39792]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2007-11-06 19:09 166304]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-06 18:28 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]

C:\Documents and Settings\valuable customer\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

C:\Documents and Settings\Guest\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

C:\Documents and Settings\Mike's Mom\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoStart IR.lnk - C:\Program Files\WinTV\Ir.exe [2007-10-10 16:33:07 106551]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 21:44:08 257752]
Wireless Configuration Utility HW.14.lnk - C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe [2007-06-07 17:05:22 634880]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 12:11 233472]
"{E180F496-8A4B-44E2-9FE0-0364E345DB7F}"= C:\WINDOWS\system32\wvuvuvv.dll [2008-02-10 15:39 40960]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuvuvv]
wvuvuvv.dll 2008-02-10 15:39 40960 C:\WINDOWS\system32\wvuvuvv.dll

R1 4fdw;4fdw;C:\WINDOWS\system32\4fdw.dll [2008-02-10 15:40]
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2006-09-08 15:47]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 13:38]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-06 18:58]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-06 19:09]
R3 hcw18bda;Hauppauge WinTV 418 Driver;C:\WINDOWS\system32\drivers\hcw18bda.sys [2007-05-10 10:43]
R3 MSHUSBVideo;NX6000 Filter Driver;C:\WINDOWS\system32\Drivers\nx6000.sys [2006-08-23 16:33]
S1 jnhjkfrn;jnhjkfrn;C:\WINDOWS\system32\jnhjkfrn []
S2 RCService;RCService;"C:\Program Files\gigabyte\RCService\RCService.exe" []
S3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys []
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2007-09-25 17:18]
S3 HauppaugeTVServer;HauppaugeTVServer;C:\PROGRA~1\WinTV\HCWTVS~1.EXE [2007-02-20 14:11]
S3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;C:\WINDOWS\system32\DRIVERS\RTL8187B.sys [2007-05-04 04:40]
S3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2002-10-01 17:57]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-06 19:10]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-07 05:00:00 C:\WINDOWS\Tasks\!Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-02-08 04:00:00 C:\WINDOWS\Tasks\!smallville.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-02-07 06:01:13 C:\WINDOWS\Tasks\Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\BGRecorder.exeC -c3 -ntod -startr:Bionic_Woman_1114_2100###.mpg -qdef -limit:3660
"2008-02-10 23:38:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-08 04:05:14 C:\WINDOWS\Tasks\smallville.job"
- C:\PROGRA~1\WinTV\BGRecorder.exe8 -c12 -ntod -startr:smallville###.mpg -qdef -limit:3600
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-10 15:45:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\wvuvuvv.dll
.
Completion time: 2008-02-10 15:47:41
ComboFix-quarantined-files.txt 2008-02-10 23:47:38
ComboFix2.txt 2008-02-10 23:20:53
ComboFix3.txt 2008-02-10 14:02:32
ComboFix4.txt 2008-02-07 03:44:33
.
2008-01-09 07:46:14 — E O F —
Hi

Download RustBFix from one of the following locations…

http://www.uploads.ejvindh.net/rustbfix.exe

http://uploads.ejvindh.andymanchesta.com/Rustbfix.exe

…and save it to your desktop.

Double click on rustbfix.exe to run the tool. If a Rustock.b-infection is found, you will shortly hereafter be asked to reboot the computer. The reboot will probably take quite a while, and perhaps 2 reboots will be needed. But this will happen automatically. After the reboot 2 logfiles will open (%root%\avenger.txt & %root%\rustbfix\pelog.txt). Post the content of these logfiles along with a new HijackThis log.
I just ran a boot scan with avast then saw your post did it and heres the result ************************* Rustock.b-fix v. 1.01 – By ejvindh ************************* Sun 02/10/2008 18:46:27.04 No Rustock.b-rootkits found ******************************* End of Logfile ********************************
Hi

We now suggest that you install the Windows Recovery Console. The Windows recovery console will allow you to boot up into a special recovery mode that allows us to help you in the case that your computer has a problem after an attempted removal of malware.

Go to Microsoft's website => http://support.microsoft.com/kb/310994
Select the download that's appropriate for your Operating System

[external image: Posted Image]


Download the file & save it as it's originally named, next to ComboFix.exe.

[external image: Posted Image]

Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please post the contents of that log.

Please do not reboot your machine until we have reviewed the log.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
Hi
No need to disable anything now. I added a switch that will do all the work ;)

Remember to disconnect from the Internet before carrying out the next instruction, but to save the CFScript file first.


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

KillAll::
 
File::
C:\wpohl.exe
C:\qrwkjyd.exe
C:\-1401996986
C:\WINDOWS\system32\wvuvuvv.dll
C:\WINDOWS\system32\4fdw.dll
C:\WINDOWS\system32\jnhjkfrn

Folder::
C:\Program Files\Helper

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6607E676-1BDE-4cb3-9913-4DC5EBCAE35E}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{E180F496-8A4B-44E2-9FE0-0364E345DB7F}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuvuvv]
 
Driver::
4fdw
jnhjkfrn

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run
I restarted my computer and tried it again, then it worked and here's the log


ComboFix 08-02.05.3 - Michael 2008-02-11 15:51:11.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2652 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Michael\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\-1401996986
C:\qrwkjyd.exe
C:\WINDOWS\system32\4fdw.dll
C:\WINDOWS\system32\jnhjkfrn
C:\WINDOWS\system32\wvuvuvv.dll
C:\wpohl.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\4fdw.dll
C:\WINDOWS\system32\sstqp.dll
C:\-1401996986
C:\Program Files\Helper
C:\Program Files\Helper\1202686806.dll
C:\Program Files\Helper\1202686807.dll
C:\Program Files\Helper\1202686808.dll
C:\Program Files\Helper\1202686907.dll
C:\Program Files\Helper\1202687020.dll
C:\Program Files\Helper\1202687035.dll
C:\Program Files\Helper\1202687036.dll
C:\qrwkjyd.exe
C:\WINDOWS\system32\4fdw.dll
C:\WINDOWS\system32\anqbacrd.dll
C:\WINDOWS\system32\conf.dat
C:\WINDOWS\system32\pqtss.ini
C:\WINDOWS\system32\pqtss.ini2
C:\WINDOWS\system32\sstqp.dll
C:\WINDOWS\system32\wvuvuvv.dll
C:\wpohl.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\4fdw
——-\jnhjkfrn


((((((((((((((((((((((((( Files Created from 2008-01-12 to 2008-02-12 )))))))))))))))))))))))))))))))
.

2008-02-11 05:21 . 2004-08-03 23:00 260,272 –a—— C:\cmldr
2008-02-10 18:46 . 2008-02-10 18:46 d——– C:\Rustbfix
2008-02-10 17:29 . 2008-02-10 17:29 24,576 –a—— C:\WINDOWS\system32\VundoFixSVC.exe
2008-02-10 17:20 . 2008-02-10 17:31 d——– C:\VundoFix Backups
2008-02-10 15:45 . 2004-08-03 23:56 388,608 –a—— C:\kmd.exe
2008-02-09 18:38 . 2008-02-09 18:38 d——– C:\Deckard
2008-02-08 21:28 . 2008-02-08 21:28 d——– C:\Documents and Settings\Mike's Mom\Application Data\acccore
2008-02-05 16:03 . 2008-02-05 16:03 d——– C:\Documents and Settings\Jason\WINDOWS
2008-02-04 17:07 . 2008-02-04 17:24 d——– C:\Program Files\Wolfenstein - Enemy Territory
2008-02-03 00:08 . 2008-02-04 20:48 d——– C:\vcs5BGEffects
2008-02-03 00:06 . 2008-02-03 00:16 d——– C:\Program Files\AV Vcs 6.0 DIAMOND
2008-02-02 21:01 . 2008-02-02 21:01 dr-h—– C:\Documents and Settings\Mike's Mom\Application Data\SecuROM
2008-02-02 12:10 . 2008-02-02 12:10 dr-h—– C:\Documents and Settings\Guest\Application Data\SecuROM
2008-02-02 00:18 . 2008-02-02 00:18 dr-h—– C:\Documents and Settings\Jason\Application Data\SecuROM
2008-01-31 20:50 . 2008-01-31 20:50 d——– C:\Program Files\RivaTuner v2.06
2008-01-31 15:10 . 2008-01-31 15:10 d——– C:\Program Files\uTorrent
2008-01-31 15:10 . 2008-02-11 15:21 d——– C:\Documents and Settings\Michael\Application Data\uTorrent
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\Common Files\Motive
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\ATT
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Documents and Settings\All Users\Application Data\Motive
2008-01-30 14:30 . 2008-01-30 14:30 d——– C:\WINDOWS\ERUNT
2008-01-26 20:47 . 2008-01-26 20:47 d——– C:\Documents and Settings\Jason\.jagex_cache_32
2008-01-26 20:19 . 2008-01-26 20:19 d——– C:\Documents and Settings\Michael\Application Data\EPSON
2008-01-22 22:45 . 2008-01-27 22:05 d——– C:\Program Files\DNA
2008-01-22 22:45 . 2008-01-25 12:47 d——– C:\Documents and Settings\Michael\Application Data\BitTorrent
2008-01-17 16:13 . 2008-01-17 16:47 d——– C:\HLServer
2008-01-17 16:02 . 2008-01-17 16:46 d——– C:\Documents and Settings\Michael\Application Data\GetRightToGo
2008-01-12 13:22 . 2008-01-12 13:22 d——– C:\Documents and Settings\Mike's Mom\Application Data\Disney Interactive Studios

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-12 00:00 ——— d—–w C:\Program Files\Steam
2008-02-11 07:12 6,776 —-a-w C:\Documents and Settings\All Users\Application Data\ypinfo.bin
2008-02-09 03:38 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\Yahoo!
2008-02-09 02:26 ——— d—–w C:\Documents and Settings\Michael\Application Data\LimeWire
2008-02-08 04:00 ——— d—–w C:\Program Files\WinTV
2008-02-06 23:46 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-06 23:24 ——— d—–w C:\Program Files\HP
2008-02-06 01:14 ——— d—–w C:\Program Files\AIMTunes
2008-02-01 23:15 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-01 23:15 ——— d—–w C:\Program Files\Sierra
2008-01-30 22:51 ——— d—–w C:\Program Files\Real
2008-01-29 21:05 ——— d—–w C:\Documents and Settings\Michael\Application Data\Xfire
2008-01-17 23:58 ——— d—–w C:\Documents and Settings\Michael\Application Data\IGN_DLM
2008-01-10 01:30 ——— d—–w C:\Documents and Settings\Jason\Application Data\Disney Interactive Studios
2008-01-07 05:34 ——— d—–w C:\Documents and Settings\Michael\Application Data\Disney Interactive Studios
2008-01-07 01:59 ——— d—–w C:\Documents and Settings\Jason\Application Data\Ahead
2007-12-31 15:21 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\DivX
2007-12-30 06:54 ——— d—–w C:\Program Files\Audacity
2007-12-26 06:55 ——— d—–w C:\Program Files\ACE-HIGH MP3 WAV WMA OGG Converter
2007-12-26 06:52 ——— d—–w C:\Program Files\MP3 Converter Simple
2007-12-23 16:24 ——— d—–w C:\Program Files\QuickTime
2007-12-22 23:37 ——— d—–w C:\Program Files\iTunes
2007-12-22 23:37 ——— d—–w C:\Program Files\iPod
2007-12-22 23:11 ——— d—–w C:\Program Files\Common Files\Download Manager
2007-12-22 02:35 ——— d—–w C:\Program Files\AV Vcs 5.0 DIAMOND
2007-12-20 01:56 ——— d—–w C:\Program Files\Illustrate
2007-12-17 01:02 ——— d—–w C:\Documents and Settings\Jason\Application Data\DivX
2007-12-14 22:17 ——— d—–w C:\Program Files\DivX
2007-12-12 01:12 ——— d—–w C:\Documents and Settings\valuable customer\Application Data\HP
2007-12-03 06:52 47,360 —-a-w C:\Documents and Settings\Michael\Application Data\pcouffin.sys
2007-12-03 06:43 356,352 —-a-w C:\WINDOWS\eSellerateEngine.dll
2007-10-11 03:05 22,328 —-a-w C:\Documents and Settings\Michael\Application Data\PnkBstrK.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 17:05 143360]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"Steam"="c:\program files\steam\steam.exe" [2007-11-29 17:33 1266936]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 13:57 1103480]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-09-29 12:22 50528]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24 1694208]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 01:33 16132608 C:\WINDOWS\RTHDCPL.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 23:43 8466432]
"nwiz"="nwiz.exe" [2007-06-28 23:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-28 23:43 81920]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 17:08 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 17:09 842584]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 08:30 81920]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" [ ]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 15:19 129536]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 23:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2007-06-26 12:48 509224]
"YPC"="C:\PROGRA~1\Yahoo!\PARENT~1\ypc.exe" [2005-02-11 17:14 352256]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2006-09-08 15:47 277296]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51 39792]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2007-11-06 19:09 166304]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-06 18:28 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]

C:\Documents and Settings\valuable customer\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

C:\Documents and Settings\Guest\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

C:\Documents and Settings\Mike's Mom\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoStart IR.lnk - C:\Program Files\WinTV\Ir.exe [2007-10-10 16:33:07 106551]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 21:44:08 257752]
Wireless Configuration Utility HW.14.lnk - C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe [2007-06-07 17:05:22 634880]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 12:11 233472]

R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2006-09-08 15:47]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 13:38]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-06 18:58]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-06 19:09]
R3 hcw18bda;Hauppauge WinTV 418 Driver;C:\WINDOWS\system32\drivers\hcw18bda.sys [2007-05-10 10:43]
R3 MSHUSBVideo;NX6000 Filter Driver;C:\WINDOWS\system32\Drivers\nx6000.sys [2006-08-23 16:33]
S2 RCService;RCService;"C:\Program Files\gigabyte\RCService\RCService.exe" []
S3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys []
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2007-09-25 17:18]
S3 HauppaugeTVServer;HauppaugeTVServer;C:\PROGRA~1\WinTV\HCWTVS~1.EXE [2007-02-20 14:11]
S3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;C:\WINDOWS\system32\DRIVERS\RTL8187B.sys [2007-05-04 04:40]
S3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2002-10-01 17:57]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-06 19:10]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-07 05:00:00 C:\WINDOWS\Tasks\!Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-02-08 04:00:00 C:\WINDOWS\Tasks\!smallville.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-02-07 06:01:13 C:\WINDOWS\Tasks\Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\BGRecorder.exeC -c3 -ntod -startr:Bionic_Woman_1114_2100###.mpg -qdef -limit:3660
"2008-02-11 23:38:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-08 04:05:14 C:\WINDOWS\Tasks\smallville.job"
- C:\PROGRA~1\WinTV\BGRecorder.exe8 -c12 -ntod -startr:smallville###.mpg -qdef -limit:3600
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-11 16:00:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\Program Files\Zune\ZuneNss.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\system32\YPCSER~1.EXE
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-02-11 16:02:52 - machine was rebooted [Michael]
ComboFix-quarantined-files.txt 2008-02-12 00:02:49
ComboFix2.txt 2008-02-10 23:47:42
ComboFix3.txt 2008-02-10 23:20:53
ComboFix4.txt 2008-02-10 14:02:32
ComboFix5.txt 2008-02-07 03:44:33
.
2008-01-09 07:46:14 — E O F —

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI