This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] How to remove Spyware / Antispyware shield

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good Morning Silver,
At last, here is the Kaspersky.txt & the latest Hijackdisk.log..

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Tuesday, March 04, 2008 3:40:14 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 3/03/2008
Kaspersky Anti-Virus database records: 594402
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan Statistics:
Total number of scanned objects: 111137
Number of viruses found: 32
Number of infected objects: 117
Number of suspicious objects: 0
Duration of the scan process: 03:31:28

Infected Object Name / Virus Name / Last Action
C:\Deckard\System Scanner\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BearShare_1469625.exe/WISE0106.BIN/stream/data0022 Infected: not-a-virus:AdWare.Win32.Agent.dd skipped
C:\Deckard\System Scanner\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BearShare_1469625.exe/WISE0106.BIN/stream Infected: not-a-virus:AdWare.Win32.Agent.dd skipped
C:\Deckard\System Scanner\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BearShare_1469625.exe/WISE0106.BIN Infected: not-a-virus:AdWare.Win32.Agent.dd skipped
C:\Deckard\System Scanner\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BearShare_1469625.exe WiseSFX: infected - 3 skipped
C:\Deckard\System Scanner\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BearShare_1469625.exe WiseSFXDropper: infected - 3 skipped
C:\Deckard\System Scanner\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\MediaBar.exe/stream/data0022 Infected: not-a-virus:AdWare.Win32.Agent.dd skipped
C:\Deckard\System Scanner\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\MediaBar.exe/stream Infected: not-a-virus:AdWare.Win32.Agent.dd skipped
C:\Deckard\System Scanner\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\MediaBar.exe NSIS: infected - 2 skipped
C:\Deckard\System Scanner\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\Temporary Directory 1 for injector.zip\injector.exe Infected: HackTool.Win32.Injecter.l skipped
C:\Deckard\System Scanner\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\Temporary Directory 2 for injector.zip\My-New-DLL-Injector v2.exe Infected: HackTool.Win32.Injecter.l skipped
C:\Deckard\System Scanner\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\Temporary Directory 5 for injector.zip\injector.exe Infected: HackTool.Win32.Injecter.l skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\ccSubSDK\submissions.idx Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.DAT Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\volatile.DAT Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\{5592F34D-7376-463C-BC71-71B0009FD52B}.DAT Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\{70B72BCD-4096-4B19-9B30-20D4514D2A96}.DAT Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\{BE87C47A-4F13-4D80-B7F8-09F8EC6F03D2}.DAT Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-03-04_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\222A786B.htm Infected: Trojan-Downloader.JS.Agent.cd skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\434C274D.htm Infected: Trojan-Downloader.JS.Agent.bx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5917378B.tmp Infected: Email-Worm.Win32.Warezov.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\775E2650.htm Infected: Trojan-Downloader.JS.Agent.hv skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7ECD2172.htm Infected: Trojan-Downloader.JS.Agent.hv skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7EE01D5D.htm Infected: Trojan-Downloader.JS.Agent.hv skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7EE77156.htm Infected: Exploit.JS.XMLCore.b skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7F0B3F2E.htm Infected: Exploit.HTML.VML.d skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\index.qbs Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\Shl_{E687360F-A6C3-46FF-BB37-81A0E2C28357}.ldb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\Shl_{E687360F-A6C3-46FF-BB37-81A0E2C28357}.sds Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\18487CBC.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\E9B48D81.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Symantec\NPMDataStore\CIMStore.xml Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\My Documents\BearShareV6int.exe/WISE0044.BIN/stream/data0005 Infected: not-a-virus:AdWare.Win32.Mostofate.aa skipped
C:\Documents and Settings\Compaq_Owner\My Documents\BearShareV6int.exe/WISE0044.BIN/stream Infected: not-a-virus:AdWare.Win32.Mostofate.aa skipped
C:\Documents and Settings\Compaq_Owner\My Documents\BearShareV6int.exe/WISE0044.BIN Infected: not-a-virus:AdWare.Win32.Mostofate.aa skipped
C:\Documents and Settings\Compaq_Owner\My Documents\BearShareV6int.exe WiseSFX: infected - 3 skipped
C:\Documents and Settings\Compaq_Owner\My Documents\BearShareV6int.exe WiseSFXDropper: infected - 3 skipped
C:\Documents and Settings\Compaq_Owner\My Documents\Gunz\Zul\SPAM\ReflexInjector V 1.0.exe Infected: HackTool.Win32.Injecter.l skipped
C:\Documents and Settings\Compaq_Owner\My Documents\Zainal\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Compaq_Owner\My Documents\Zainal\SmitfraudFix\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Compaq_Owner\My Documents\Zainal\SmitfraudFix\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Compaq_Owner\My Documents\Zainal\SmitfraudFix\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Compaq_Owner\My Documents\Zainal\SmitfraudFix\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Compaq_Owner\ntuser.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\eengine\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\chandir.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\chandir.idx Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\chn.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\chn.idx Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\D0000000.FCS Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\inuse.txt Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\L0000017.FCS Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\main.log Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs.idx Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_die.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_die.idx Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_dnd.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_dnd.idx Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_ext.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_ext.idx Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_rcv.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_rcv.idx Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\storydb.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\storydb.idx Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP290\A0158798.exe Infected: Backdoor.Win32.Agent.dbp skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP330\A0180417.DLL Infected: not-a-virus:AdWare.Win32.FunWeb.e skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180482.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180483.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180484.scr Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180485.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180493.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.at skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180495.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180496.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180497.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.af skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180498.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180499.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180500.SCR Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180501.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180502.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180503.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.a skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180504.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.an skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180505.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.aq skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180506.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bh skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180508.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180509.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ax skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180511.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180513.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180514.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180515.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ad skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180517.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180518.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180519.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180520.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180522.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180523.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180524.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.l skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180525.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180526.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180527.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP331\A0180538.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP337\A0182147.exe Infected: HackTool.Win32.Injecter.l skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP337\A0182151.exe Infected: HackTool.Win32.Injecter.l skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP361\A0186704.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP361\A0186717.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP361\A0186730.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP361\A0186746.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP361\A0186758.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP361\A0186774.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP361\A0186882.dll Infected: not-a-virus:AdWare.Win32.E404.i skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP365\A0187374.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP365\A0187386.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP365\A0187399.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP365\A0187412.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP365\A0187425.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP365\A0187438.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP366\A0187921.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP366\A0188005.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP367\A0188252.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP367\A0188288.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP367\A0188305.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP367\A0188325.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP367\A0188377.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP368\A0188434.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP368\A0188465.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP369\A0188498.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP369\A0188531.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP369\A0188546.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP369\A0189546.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP370\A0189570.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP371\A0189596.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP371\A0189612.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP371\A0190612.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP371\A0191612.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP371\A0191630.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP371\A0191642.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP371\A0192642.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP371\A0192902.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP371\A0192959.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP371\A0192984.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP371\A0192998.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP371\A0193013.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP376\A0193272.exe Infected: Trojan-Downloader.Win32.Zlob.ifo skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP376\A0193280.dll Infected: Trojan-Downloader.Win32.Zlob.ifp skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP376\A0193282.exe Infected: not-virus:Hoax.Win32.Gavec.t skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP379\A0193848.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP379\A0193856.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP379\A0193870.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP379\A0193870.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP379\A0193870.exe RarSFX: infected - 2 skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP379\A0193924.exe Infected: Trojan-Downloader.Win32.Agent.dxl skipped
C:\System Volume Information\_restore{D34137C1-F216-4803-BF12-FAFE117CE9FA}\RP379\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\NetLimit.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\gebxwvw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\JET4793.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped

Scan process completed.


Logfile of HijackThis v1.99.1
Scan saved at 3:41:35 AM, on 3/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Compaq_Owner\My Documents\Zainal\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.singnet.com.sg:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {3AC7F64E-6154-47B0-82B5-764ED4077F77} (DataStorage Class) - http://txn02.hkjc.com/BetSlip/object/eWinCtl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{98E2A609-A246-461A-B7BF-7B5E53E3245B}: NameServer = 165.21.83.88,165.21.100.88
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe



Once again, thanks a million for all the help. I've another question. What do I do with all the downloads , eg.
dss.exe , deljob.exe , erunt.zip & files & the SmitfraudFix ? Do I just leave it for future use or could I delete it ?

Thx & Rgds.
:woot:
Hi again Silver , I've yet another question, I've all these files : - eg . . AlbumArt…{22CCD8D5-06CF-49FE-BC7C-0C701F5B94AD}…Large AlbumArt…{290EF9BF2-06CF-49FE-BC7C-0C701F5B94AD}…Small AlbumArt…{22CCD8D5-26E4-474E-AB39-BF9A4695CFB1}…Large.JPG AlbumArt…{22CCD8D5-26E4-474E-AB39-BF9A4695CFB1}…SMALL.JPG All these files emerge in the same folder as my MP3 Audio folder. All these files are marked as TYPE - Lexmark Photo Editor 6.0 Document, when I tried to delete them , they prompt me that : - The File , AlbumArt…{22CCD8D5-06CF-49FE-BC7C-0C701F5B94AD}…Large…… is a system file. If you remove it, your computer or one of your programs may no longer work correctly. Are you sure you want to remove it to the recycle Bin ? [ Yes ] [ No ] P/S , sorry for yet another problem…. Thx & Rgds. :pullhair:
Hi Zainal_9202,

I'm relieved you got the Kaspersky scan posted OK! It actually looks pretty good but there are a few things to delete - you should also delete the tools we have used, they won't be any use in the future because they are constantly updated, I have listed everything here:

Use Windows Explorer (right-click Start, select Explore) to find and delete the following:

C:\Documents and Settings\Compaq_Owner\My Documents\BearShareV6int.exe
C:\WINDOWS\system32\gebxwvw.dll
C:\Deckard <– folder

I can't find much out about this program, it looks like some sort of game hack, and Kaspersky has flagged it as riskware - so I strongly recommend you delete it:

C:\Documents and Settings\Compaq_Owner\My Documents\Gunz\Zul\SPAM\ReflexInjector V 1.0.exe

If you wish to keep it please let me know and we can test it further.

Also delete DSS.exe, DelJob.exe, SmitfraudFix.exe and it's folder SmitfraudFix from your Desktop along with any logs you have kept.

Next, please open Norton Antivirus and clean the quarantined files area.


Re-hide hidden/system files and folders:
Click Start -> My Computer
Select the Tools menu, click Folder Options and select the View tab
Under the Hidden files and folders heading SELECT Do not show hidden files and folders
CHECK the Hide extensions for known file types option
CHECK the Hide protected operating system files (recommended) option
Press OK

You can now have another look for those AlbumArt files and they have probably disappeared. They are almost certainly what they appear to be - the little pictures associated with audio files and therefore nothing to worry about.


Create a new, clean System Restore point which you can use in case of future system problems:
Press Start->All Programs->Accessories->System Tools->System Restore
Select Create a restore point, then Next, type a name like All Clean then press the Create button and once it's done press Close

Now remove old, infected System Restore points:
Next click Start->Run and type cleanmgr in the box and press OK
Ensure the boxes for Recycle Bin, Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
Select the More Options tab, under System Restore press Clean up… and say Yes to the prompt
Press OK and Yes to confirm

If you have any problems with the above instructions please stop and let me know - your machine is not clean until they are complete.

————————————————————————

If the above went well, I think your machine is clean of malware :) here are some tips to help you keep it that way:

You have a good antivirus suite installed, however I recommend you also install antispyware software with real-time capabilities - this will protect you from a wider range of malware and also that it will protect you from system changes and spyware while you are working, not just removing malware after it has been installed. There are a range of paid-for and free packages available, a free one I can recommend is Windows Defender, available here:
http://www.microsoft.com/athome/security/s…re/default.mspx

I recommend you install a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.
Also: subscribe to the mailing list to get update notifications.

Please take care when downloading programs. One of the easiest ways to be infected is to download freeware/shareware programs which come laden with malware - this includes allowing websites to install browser plug-ins or ActiveX controls. Before downloading, it is crucial to check whether the source is reputable.
One way to check is to use McAfee SiteAdvisor. Copy the domain name into the space provided and SiteAdvisor will give you a report on the website which can help you decide if it is safe. They also have a toolbar for IE and Firefox which adds this functionality to your browser.

Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

Find out more about how to prevent infection in the future
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know that you have read this, and if there are any further issues.
Hi Sliver, With your tireless help , everything instructed went on smoothly including deleting of the ReflexInjector V 1.0.exe , DSS.exe, DelJob.exe, SmitfraudFix.exe & SmitfraudFix…BUT , I couldn't delete the following : - C:\WINDOWS\system32\gebxwvw.dll…. It prompt me Cannot delete gebxwvw.: It is being used by another person or program. I've closed all running programs & tried again but to no avail…. Awaiting your answer , before I start with the antispyware installation , custom hosts files & Win Patrol as recommended… there are two more folders : - Erunt & erunt.zip folder. Could I delete them as well.. I really wish to Thank You again for all the help , guide & information that helps me to understand more about software related issues. Once again Thanks a million… Rgds …. :woot:
Hi Zainal_9202,

C:\WINDOWS\system32\gebxwvw.dll…. It prompt me Cannot delete gebxwvw.: It is being used by another
person or program. I've closed all running programs & tried again but to no avail….

I'm sorry to tell you this but we may have one more issue to deal with.
Please open the HijackThis folder on your Desktop and rename the HijackThis program file HijackThis.exe to Scan.exe and post a new log for me to see.

Also, is your Norton Antivirus up to date?
Hi Silver ,
No problem, I've done as told & here's the log file… Yes, my Norton Antivirus was purchased online for a 2 years subscription & I always run Liveupdates for it….


Logfile of HijackThis v1.99.1
Scan saved at 5:23:19 PM, on 3/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\windows\system\hpsysdrv.exe
C:\Documents and Settings\Compaq_Owner\Desktop\Scan.exe.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.singnet.com.sg:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: (no name) - {0B52C7EC-D1A3-4054-923C-DD12567F28B1} - C:\WINDOWS\system32\gebxwvw.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: (no name) - {8718F9F9-F397-4804-B7C3-866961ED301B} - C:\WINDOWS\system32\ddayw.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {3AC7F64E-6154-47B0-82B5-764ED4077F77} (DataStorage Class) - http://txn02.hkjc.com/BetSlip/object/eWinCtl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{98E2A609-A246-461A-B7BF-7B5E53E3245B}: NameServer = 165.21.83.88,165.21.100.88
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: gebxwvw - C:\WINDOWS\SYSTEM32\gebxwvw.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe



Need to go now , I'm on the graveyard shift… I'll get back to you tomorrow morning.. Thanks a lot for all the help….

Rgds..
Hi,

There is a new infection on your machine which wasn't present when we started cleaning, the infection looks to have occurred between this post and this post. If you have any recollection of events during that period it might be helpful in preventing reinfection.

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • A log file will be created at C:\vundofix.txt, please post the contents of this in your next response.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

Once complete, please post the Vundofix report and a new HijackThis log.

Need to go now , I'm on the graveyard shift… I'll get back to you tomorrow morning.. Thanks a lot for all the help….

You're most welcome, we should have this resolved soon :)
Good Morning Silver,
SOS , SOS , SOS …. :pullhair: :pullhair: I 'm having problem running the VundoFix.exe, I managed to download it to my desktop but each time I , doubel click it , this error appeared : - Run-time error ' 339 ' - Component ' comdig32.ocx' or one of its dependencies not correctly registered : a file is missing or invalid…..
The hijackthis log is listed below …. I really couldn't recalled the actual events that occurreed between the two dates but the frequent sites that I surf thru are : - WWW.SINGAPORE Pools.sg , http://soccernet.espn.go.com/ , https://wm.statschippac.com/ & my son's : - http://sfront.ijji.com …

Logfile of HijackThis v1.99.1
Scan saved at 10:42:37 AM, on 3/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live Toolbar\msn_sl.exe
C:\Documents and Settings\Compaq_Owner\Desktop\VundoFix.exe
C:\Documents and Settings\Compaq_Owner\Desktop\Scan.exe.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.singnet.com.sg:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: (no name) - {0B52C7EC-D1A3-4054-923C-DD12567F28B1} - C:\WINDOWS\system32\gebxwvw.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9FD2B49E-98AA-4D91-AB9F-AEA38FE92CB4} - C:\WINDOWS\system32\ddayw.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {3AC7F64E-6154-47B0-82B5-764ED4077F77} (DataStorage Class) - http://txn02.hkjc.com/BetSlip/object/eWinCtl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{98E2A609-A246-461A-B7BF-7B5E53E3245B}: NameServer = 165.21.83.88,165.21.100.88
O20 - Winlogon Notify: gebxwvw - C:\WINDOWS\SYSTEM32\gebxwvw.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe


Rgds….. Thanks again & sorry for the trouble ..
Hi Zainal_9202,

I'm sorry that didn't work, please try this instead:

Download ComboFix to your desktop
  • Double click combofix.exe and follow the prompts
  • Note: Do not click ComboFix's window while it's running - it may cause it to stall!
  • If after ComboFix finishes you do not have internet access, then reboot your computer to restore it
  • When finished, it shall produce a log for you, please post it in your next response

Once complete, please post the ComboFix report and a new HijackThis log.
Morning Silver,
I'm just back from work.. Pls don't apologized instead I'm the one who is supposed to apologize for all the trouble..
As requested here are the ComboFix report and a new HijackThis log…

ComboFix 08-03-04.5 - Compaq_Owner 2008-03-06 10:45:55.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\ddayw.dll
C:\WINDOWS\system32\gebxwvw.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\update.exe
C:\WINDOWS\system32\wyadd.ini
C:\WINDOWS\system32\wyadd.ini2

.
((((((((((((((((((((((((( Files Created from 2008-02-06 to 2008-03-06 )))))))))))))))))))))))))))))))
.

2008-03-06 10:46 . 2008-03-06 10:46 6,736 –a—— C:\WINDOWS\system32\drivers\PROCEXP90.SYS
2008-03-06 10:39 . 2004-08-04 05:00 388,608 –a—— C:\CF18529.exe
2008-03-06 10:29 . 2008-03-06 10:29 d——– C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-03-05 18:52 . 2008-03-05 18:52 d——– C:\Program Files\Messenger Plus! Live
2008-03-05 18:08 . 2008-03-06 10:30 d——– C:\Documents and Settings\Compaq_Owner\Tracing
2008-03-05 18:01 . 2008-03-05 18:01 d——– C:\Program Files\Windows Live
2008-03-05 17:55 . 2008-03-05 17:57 d——– C:\Program Files\MessengerPlus! 3
2008-03-05 17:53 . 2008-03-05 18:06 d——– C:\Program Files\MSN Messenger
2008-03-05 17:47 . 2008-03-05 17:47 2,400,784 –a—— C:\Program Files\WLinstaller.exe
2008-03-04 17:50 . 2008-03-04 17:51 d——– C:\Documents and Settings\All Users\Application Data\WindowsLiveInstaller
2008-03-03 15:10 . 2008-03-03 15:10 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-03-03 15:10 . 2008-03-03 15:10 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-01 19:40 . 2008-03-05 17:55 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-01 13:33 . 2007-06-21 18:59 58,776 –a—— C:\WINDOWS\system32\ijjiPlugin2.dll
2008-03-01 13:28 . 2008-03-01 13:28 d——– C:\Program Files\NHN USA
2008-03-01 13:28 . 2008-01-16 18:25 679,936 –a—— C:\WINDOWS\system32\ijjiSetup.exe
2008-02-28 12:36 . 2008-02-28 12:39 d——– C:\Documents and Settings\Compaq_Owner\Application Data\McAfee.com Personal Firewall
2008-02-28 12:35 . 2008-02-28 12:35 d——– C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
2008-02-28 12:33 . 2008-03-01 10:05 28,896 –a—— C:\WINDOWS\system32\Status.MPF
2008-02-28 12:26 . 2008-02-28 12:33 d——– C:\WINDOWS\system32\mclsphlr
2008-02-28 12:25 . 2004-09-28 10:43 114,688 ——— C:\WINDOWS\system32\mclsp.dll
2008-02-28 12:25 . 2004-09-28 10:43 32,768 –a—— C:\WINDOWS\system32\instlsp.exe
2008-02-28 12:25 . 2004-09-28 10:43 11,264 –a—— C:\WINDOWS\system32\sporder.dll
2008-02-28 12:23 . 2008-03-01 11:11 d——– C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-02-27 00:05 . 2008-03-02 20:10 3,878 –a—— C:\WINDOWS\system32\tmp.reg
2008-02-26 17:19 . 2008-02-26 17:19 d——– C:\ijji
2008-02-25 16:24 . 2008-02-25 16:24 d——– C:\Program Files\Windows Sidebar
2008-02-25 16:22 . 2008-02-25 16:25 d——– C:\Program Files\Norton Internet Security
2008-02-25 16:21 . 2008-02-25 16:24 123,952 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-25 16:21 . 2008-02-25 16:24 60,800 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-25 16:21 . 2008-02-25 16:24 10,563 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-25 16:21 . 2008-02-25 16:24 805 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-07 05:43 . 2008-02-07 05:43 579,464 –a—— C:\WINDOWS\system32\SymNeti.dll
2008-02-07 05:43 . 2008-02-07 05:43 207,240 –a—— C:\WINDOWS\system32\SymRedir.dll
2008-02-07 05:43 . 2008-02-07 05:43 31,408 –a—— C:\WINDOWS\system32\drivers\SymIM.sys
2008-02-07 05:43 . 2008-02-07 05:43 13,021 –a—— C:\WINDOWS\system32\drivers\SymRedir.cat
2008-02-06 03:34 . 2008-02-06 03:34 188,464 –a—— C:\WINDOWS\system32\drivers\symtdi.sys
2008-02-06 03:34 . 2008-02-06 03:34 96,432 –a—— C:\WINDOWS\system32\drivers\symfw.sys
2008-02-06 03:34 . 2008-02-06 03:34 41,008 –a—— C:\WINDOWS\system32\drivers\symndisv.sys
2008-02-06 03:34 . 2008-02-06 03:34 38,576 –a—— C:\WINDOWS\system32\drivers\symids.sys
2008-02-06 03:34 . 2008-02-06 03:34 37,424 –a—— C:\WINDOWS\system32\drivers\symndis.sys
2008-02-06 03:34 . 2008-02-06 03:34 22,320 –a—— C:\WINDOWS\system32\drivers\symredrv.sys
2008-02-06 03:34 . 2008-02-06 03:34 13,616 –a—— C:\WINDOWS\system32\drivers\symdns.sys
2008-02-06 03:34 . 2008-02-06 03:34 1,612 –a—— C:\WINDOWS\system32\drivers\SymRedir.inf

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-06 02:39 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-05 10:00 18,103,296 —-a-w C:\Program Files\wlm_9.msi
2008-03-04 15:04 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-03-02 10:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-01 11:43 ——— d—–w C:\Documents and Settings\Compaq_Owner\Application Data\LimeWire
2008-03-01 05:28 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-03-01 04:08 ——— d—–w C:\Program Files\Three Rings Design
2008-02-26 09:30 ——— d–h–w C:\Documents and Settings\Compaq_Owner\Application Data\ijjigame
2008-02-25 08:26 ——— d—–w C:\Documents and Settings\Compaq_Owner\Application Data\Symantec
2008-02-25 08:24 ——— d—–w C:\Program Files\Symantec
2008-02-24 15:03 ——— d—–w C:\Program Files\Oberon Media
2008-02-24 15:02 ——— d–h–r C:\Documents and Settings\All Users\Application Data\yahoo!
2008-02-24 15:02 ——— d—–w C:\Program Files\Yahoo!
2008-02-24 15:02 ——— d—–w C:\Program Files\PopCap Games
2008-02-24 13:54 ——— d—–w C:\Program Files\Windows Media Connect 2
2008-02-08 09:26 ——— d—–w C:\Program Files\Lexmark 1200 Series
2008-02-04 20:27 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2008-02-04 20:27 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2008-02-04 20:27 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2008-02-02 07:07 ——— d—–w C:\Program Files\Common Files\INCA Shared
2008-02-02 03:55 409,088 —-a-w C:\WINDOWS\system32\drivers\EagleNt.sys
2008-02-01 22:55 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2008-02-01 22:55 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2008-02-01 22:55 10,545 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2008-02-01 01:51 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2008-02-01 01:51 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2008-02-01 01:51 279,088 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2008-01-28 02:20 ——— d—–w C:\Documents and Settings\Compaq_Owner\Application Data\BitZipper
2008-01-16 03:32 ——— d—–w C:\Program Files\Google
2008-01-16 03:30 ——— d—–w C:\Documents and Settings\Compaq_Owner\Application Data\Dev-Cpp
2008-01-16 03:29 ——— d—–w C:\Program Files\Qyule
2008-01-15 01:54 10,537 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-14 21:28 706 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-14 12:51 ——— d—–w C:\Program Files\Disc2Phone
2008-01-13 02:32 23,904 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-01-06 15:24 ——— d—–w C:\Documents and Settings\Compaq_Owner\Application Data\Uniblue
2007-11-16 11:58 138,413 —-a-w C:\Documents and Settings\Compaq_Owner\Application Data\mmg8o2y.exe
2007-11-16 11:07 138,413 —-a-w C:\Documents and Settings\Compaq_Owner\Application Data\ir4ubj2.exe
2007-11-16 09:51 138,413 —-a-w C:\Documents and Settings\Compaq_Owner\Application Data\lyt974f.exe
2007-11-12 06:24 3,813,376 —-a-w C:\Documents and Settings\All Users\bearflix.exe
2007-11-06 11:05 166,912 —-a-w C:\Documents and Settings\All Users\libmcrypt.dll
2007-11-05 08:10 3,584 —-a-w C:\Documents and Settings\All Users\BSidle.dll
2007-10-14 06:58 57,344 —-a-w C:\Documents and Settings\All Users\ammp3.dll
2007-10-02 07:28 843,776 —-a-w C:\Documents and Settings\All Users\libeay32.dll
2007-10-02 07:28 57,344 —-a-w C:\Documents and Settings\All Users\bfpreview.dll
2007-10-02 07:28 441,856 —-a-w C:\Documents and Settings\All Users\avformat-51.dll
2007-10-02 07:28 3,213,312 —-a-w C:\Documents and Settings\All Users\avcodec-51.dll
2007-10-02 07:28 27,648 —-a-w C:\Documents and Settings\All Users\avutil-49.dll
2007-10-02 07:28 196,608 —-a-w C:\Documents and Settings\All Users\libcurl.dll
2007-10-02 07:28 159,744 —-a-w C:\Documents and Settings\All Users\ssleay32.dll
2007-09-01 04:42 3,949,904 —-a-w C:\Program Files\MsgPlusLive-423.exe
2007-07-19 04:28 1,115,728 —-a-w C:\Documents and Settings\All Users\Application Data\pswi_preloaded.exe
2007-02-08 11:46 32 —-a-r C:\Documents and Settings\All Users\hash.dat
2006-02-18 17:28 12,288 —-a-w C:\WINDOWS\Fonts\RandFont.dll
2002-07-26 09:02 153,088 —-a-w C:\Documents and Settings\All Users\UNWISE.EXE
2007-01-20 15:03 22 –sha-w C:\WINDOWS\SMINST\HPCD.sys
2007-03-15 04:15 168 –sh–r C:\WINDOWS\system32\428BBF160F.sys
2007-03-15 16:09 6,686 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2008-02-07 12:05 349552 –a—— C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-02-25 16:23 116088 –a—— C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll [2008-02-07 12:05 349552]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-16 10:40 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-11-07 15:34 3739672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 05:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 05:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00 455168]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-22 00:56 16261632 C:\WINDOWS\RTHDCPL.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-21 01:06 7622656]
"PCDrProfiler"="" []
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2007-07-19 15:17 249856]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-09-18 12:20 180269]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"Lexmark 1200 Series"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 13:22 57344]
"MicrosoftUpdate"="C:\WINDOWS\system32\MSServx.exe" [ ]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [ ]
"BearFlix"="C:\Program Files\BearFlix\BearFlix.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-26 09:47 51048]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2008-02-07 14:49 718704]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]

C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2007-07-19 14:48:57 225280]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-02-07 05:43]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-01-13 10:32]
S3 Symantec RemoteAssist;Symantec RemoteAssist;"C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe" [2008-01-29 16:09]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-02-07 05:43]
S3 XDva039;XDva039;C:\WINDOWS\system32\XDva039.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{63b7122a-9bea-11db-a2f1-0019210a5ec2}]
\Shell\Auto\command - setup.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-03-05 14:11:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-03-03 15:55:14 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Compaq_Owner.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-06 10:54:47
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-03-06 10:58:39 - machine was rebooted [Compaq_Owner]
ComboFix-quarantined-files.txt 2008-03-06 02:58:35
.
2007-07-11 07:19:10 — E O F —


Logfile of HijackThis v1.99.1
Scan saved at 11:00:37 AM, on 3/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Documents and Settings\Compaq_Owner\Desktop\Scan.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.singnet.com.sg:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [MicrosoftUpdate] C:\WINDOWS\system32\MSServx.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [BearFlix] "C:\Program Files\BearFlix\BearFlix.exe" /pause
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {3AC7F64E-6154-47B0-82B5-764ED4077F77} (DataStorage Class) - http://txn02.hkjc.com/BetSlip/object/eWinCtl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{98E2A609-A246-461A-B7BF-7B5E53E3245B}: NameServer = 165.21.83.88,165.21.100.88
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)


Thx & Rgds…
P.S . . Take your time , as I'll be on Off Duty till Sunday nite..
Hi Zainal_9202 :)

You have a program called Messenger Plus! Live installed. When installing it offers a choice either to Install the sponsor program or I refuse to give my support, don't install the sponsor. The sponsor program is malware so if you installed it we need to remove it. Even if you didn't install the sponsor program I recommend you remove this program anyway as the developer is spreading malware for profit - read more information about this here.
To remove the program open Start->Control Panel->Add/Remove Programs, find and remove Messenger Plus! Live

I will assume you have removed this program for the remainder of the post, if for any reason you wish to keep it, please stop here and let me know.

————————————————————————

Check that ComboFix.exe is on your Desktop
  • Then open Notepad: press Start->Run, type notepad and click OK
  • Copy/paste the contents of the below code box into Notepad:
    File::
    C:\WINDOWS\system32\MSServx.exe
    C:\Program Files\MsgPlusLive-423.exe
    C:\Documents and Settings\Compaq_Owner\Application Data\mmg8o2y.exe
    C:\Documents and Settings\Compaq_Owner\Application Data\ir4ubj2.exe
    C:\Documents and Settings\Compaq_Owner\Application Data\lyt974f.exe
    Folder::
    C:\Documents and Settings\All Users\Application Data\Messenger Plus!
    C:\Program Files\Messenger Plus! Live
    C:\Program Files\MessengerPlus! 3
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MicrosoftUpdate"=-
  • Save this to your Desktop as CFScript.

    [external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
Note: Do not click ComboFix's window while it's running - it may cause it to stall!

Next:
Clean with MalwareBytes' Anti-Malware
  • Please download the Installer to your Desktop from here:
    http://www.besttechie.net/tools/mbam-setup.exe
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to both of these options:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure everything is checked, and click Remove Selected.
  • When finished, a log will open in Notepad. Please save it to your Desktop, and post the contents in your reply.
  • The log can also be found here if you need it:
    • Start->All Programs->Malwarebytes' Anti-Malware->Logs

Once complete, please post the new ComboFix report, the MalwareBytes Anti-Malware report and a new HijackThis log.
Hi ,
I've removed the Messenger Plus! Live.. Here are the required logs. Thanks for all he help..


ComboFix 08-03-04.5 - Compaq_Owner 2008-03-06 13:42:15.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.160 [GMT 8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Compaq_Owner\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\Documents and Settings\Compaq_Owner\Application Data\ir4ubj2.exe
C:\Documents and Settings\Compaq_Owner\Application Data\lyt974f.exe
C:\Documents and Settings\Compaq_Owner\Application Data\mmg8o2y.exe
C:\Program Files\MsgPlusLive-423.exe
C:\WINDOWS\system32\MSServx.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Compaq_Owner\Application Data\ir4ubj2.exe
C:\Documents and Settings\Compaq_Owner\Application Data\lyt974f.exe
C:\Documents and Settings\Compaq_Owner\Application Data\mmg8o2y.exe
C:\Program Files\MsgPlusLive-423.exe
D:\Autorun.inf

.
————— FMove —————

.
((((((((((((((((((((((((( Files Created from 2008-02-06 to 2008-03-06 )))))))))))))))))))))))))))))))
.

2008-03-06 13:29 . 2008-03-06 13:29 d——– C:\Documents and Settings\Compaq_Owner\Application Data\Malwarebytes
2008-03-06 13:28 . 2008-03-06 13:28 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-03-06 13:28 . 2008-03-06 13:28 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-06 10:39 . 2004-08-04 05:00 388,608 –a—— C:\CF18529.exe
2008-03-05 18:08 . 2008-03-06 10:55 d——– C:\Documents and Settings\Compaq_Owner\Tracing
2008-03-05 18:01 . 2008-03-05 18:01 d——– C:\Program Files\Windows Live
2008-03-05 17:53 . 2008-03-05 18:06 d——– C:\Program Files\MSN Messenger
2008-03-05 17:47 . 2008-03-05 17:47 2,400,784 –a—— C:\Program Files\WLinstaller.exe
2008-03-04 17:50 . 2008-03-04 17:51 d——– C:\Documents and Settings\All Users\Application Data\WindowsLiveInstaller
2008-03-03 15:10 . 2008-03-03 15:10 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-03-03 15:10 . 2008-03-03 15:10 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-01 19:40 . 2008-03-05 17:55 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-01 13:33 . 2007-06-21 18:59 58,776 –a—— C:\WINDOWS\system32\ijjiPlugin2.dll
2008-03-01 13:28 . 2008-03-01 13:28 d——– C:\Program Files\NHN USA
2008-03-01 13:28 . 2008-01-16 18:25 679,936 –a—— C:\WINDOWS\system32\ijjiSetup.exe
2008-02-28 12:36 . 2008-02-28 12:39 d——– C:\Documents and Settings\Compaq_Owner\Application Data\McAfee.com Personal Firewall
2008-02-28 12:35 . 2008-02-28 12:35 d——– C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
2008-02-28 12:33 . 2008-03-01 10:05 28,896 –a—— C:\WINDOWS\system32\Status.MPF
2008-02-28 12:26 . 2008-02-28 12:33 d——– C:\WINDOWS\system32\mclsphlr
2008-02-28 12:25 . 2004-09-28 10:43 114,688 ——— C:\WINDOWS\system32\mclsp.dll
2008-02-28 12:25 . 2004-09-28 10:43 32,768 –a—— C:\WINDOWS\system32\instlsp.exe
2008-02-28 12:25 . 2004-09-28 10:43 11,264 –a—— C:\WINDOWS\system32\sporder.dll
2008-02-28 12:23 . 2008-03-01 11:11 d——– C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-02-27 00:05 . 2008-03-02 20:10 3,878 –a—— C:\WINDOWS\system32\tmp.reg
2008-02-25 16:24 . 2008-02-25 16:24 d——– C:\Program Files\Windows Sidebar
2008-02-25 16:22 . 2008-02-25 16:25 d——– C:\Program Files\Norton Internet Security
2008-02-25 16:21 . 2008-02-25 16:24 123,952 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-25 16:21 . 2008-02-25 16:24 60,800 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-25 16:21 . 2008-02-25 16:24 10,563 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-25 16:21 . 2008-02-25 16:24 805 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-07 05:43 . 2008-02-07 05:43 579,464 –a—— C:\WINDOWS\system32\SymNeti.dll
2008-02-07 05:43 . 2008-02-07 05:43 207,240 –a—— C:\WINDOWS\system32\SymRedir.dll
2008-02-07 05:43 . 2008-02-07 05:43 31,408 –a—— C:\WINDOWS\system32\drivers\SymIM.sys
2008-02-07 05:43 . 2008-02-07 05:43 13,021 –a—— C:\WINDOWS\system32\drivers\SymRedir.cat
2008-02-06 03:34 . 2008-02-06 03:34 188,464 –a—— C:\WINDOWS\system32\drivers\symtdi.sys
2008-02-06 03:34 . 2008-02-06 03:34 96,432 –a—— C:\WINDOWS\system32\drivers\symfw.sys
2008-02-06 03:34 . 2008-02-06 03:34 41,008 –a—— C:\WINDOWS\system32\drivers\symndisv.sys
2008-02-06 03:34 . 2008-02-06 03:34 38,576 –a—— C:\WINDOWS\system32\drivers\symids.sys
2008-02-06 03:34 . 2008-02-06 03:34 37,424 –a—— C:\WINDOWS\system32\drivers\symndis.sys
2008-02-06 03:34 . 2008-02-06 03:34 22,320 –a—— C:\WINDOWS\system32\drivers\symredrv.sys
2008-02-06 03:34 . 2008-02-06 03:34 13,616 –a—— C:\WINDOWS\system32\drivers\symdns.sys
2008-02-06 03:34 . 2008-02-06 03:34 1,612 –a—— C:\WINDOWS\system32\drivers\SymRedir.inf

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-06 05:29 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-05 10:00 18,103,296 —-a-w C:\Program Files\wlm_9.msi
2008-03-04 15:04 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-03-02 10:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-01 11:43 ——— d—–w C:\Documents and Settings\Compaq_Owner\Application Data\LimeWire
2008-03-01 05:28 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-03-01 04:08 ——— d—–w C:\Program Files\Three Rings Design
2008-02-26 09:30 ——— d–h–w C:\Documents and Settings\Compaq_Owner\Application Data\ijjigame
2008-02-25 08:26 ——— d—–w C:\Documents and Settings\Compaq_Owner\Application Data\Symantec
2008-02-25 08:24 ——— d—–w C:\Program Files\Symantec
2008-02-24 15:03 ——— d—–w C:\Program Files\Oberon Media
2008-02-24 15:02 ——— d–h–r C:\Documents and Settings\All Users\Application Data\yahoo!
2008-02-24 15:02 ——— d—–w C:\Program Files\Yahoo!
2008-02-24 15:02 ——— d—–w C:\Program Files\PopCap Games
2008-02-24 13:54 ——— d—–w C:\Program Files\Windows Media Connect 2
2008-02-08 09:26 ——— d—–w C:\Program Files\Lexmark 1200 Series
2008-02-04 20:27 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2008-02-04 20:27 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2008-02-04 20:27 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2008-02-02 07:07 ——— d—–w C:\Program Files\Common Files\INCA Shared
2008-02-02 03:55 409,088 —-a-w C:\WINDOWS\system32\drivers\EagleNt.sys
2008-02-01 22:55 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2008-02-01 22:55 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2008-02-01 22:55 10,545 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2008-02-01 01:51 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2008-02-01 01:51 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2008-02-01 01:51 279,088 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2008-01-28 02:20 ——— d—–w C:\Documents and Settings\Compaq_Owner\Application Data\BitZipper
2008-01-16 03:32 ——— d—–w C:\Program Files\Google
2008-01-16 03:30 ——— d—–w C:\Documents and Settings\Compaq_Owner\Application Data\Dev-Cpp
2008-01-16 03:29 ——— d—–w C:\Program Files\Qyule
2008-01-15 01:54 10,537 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-14 21:28 706 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-14 12:51 ——— d—–w C:\Program Files\Disc2Phone
2008-01-13 02:32 23,904 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-01-06 15:24 ——— d—–w C:\Documents and Settings\Compaq_Owner\Application Data\Uniblue
2007-12-30 16:13 28,672 —-a-w C:\WINDOWS\system32\UnSCSK.exe
2007-11-12 06:24 3,813,376 —-a-w C:\Documents and Settings\All Users\bearflix.exe
2007-11-06 11:05 166,912 —-a-w C:\Documents and Settings\All Users\libmcrypt.dll
2007-11-05 08:10 3,584 —-a-w C:\Documents and Settings\All Users\BSidle.dll
2007-10-14 06:58 57,344 —-a-w C:\Documents and Settings\All Users\ammp3.dll
2007-10-02 07:28 843,776 —-a-w C:\Documents and Settings\All Users\libeay32.dll
2007-10-02 07:28 57,344 —-a-w C:\Documents and Settings\All Users\bfpreview.dll
2007-10-02 07:28 441,856 —-a-w C:\Documents and Settings\All Users\avformat-51.dll
2007-10-02 07:28 3,213,312 —-a-w C:\Documents and Settings\All Users\avcodec-51.dll
2007-10-02 07:28 27,648 —-a-w C:\Documents and Settings\All Users\avutil-49.dll
2007-10-02 07:28 196,608 —-a-w C:\Documents and Settings\All Users\libcurl.dll
2007-10-02 07:28 159,744 —-a-w C:\Documents and Settings\All Users\ssleay32.dll
2007-07-19 04:28 1,115,728 —-a-w C:\Documents and Settings\All Users\Application Data\pswi_preloaded.exe
2007-02-08 11:46 32 —-a-r C:\Documents and Settings\All Users\hash.dat
2006-02-18 17:28 12,288 —-a-w C:\WINDOWS\Fonts\RandFont.dll
2002-07-26 09:02 153,088 —-a-w C:\Documents and Settings\All Users\UNWISE.EXE
2007-01-20 15:03 22 –sha-w C:\WINDOWS\SMINST\HPCD.sys
2007-03-15 04:15 168 –sh–r C:\WINDOWS\system32\428BBF160F.sys
2007-03-15 16:09 6,686 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2008-02-07 12:05 349552 –a—— C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-02-25 16:23 116088 –a—— C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll [2008-02-07 12:05 349552]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-16 10:40 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-11-07 15:34 3739672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 05:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 05:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00 455168]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-22 00:56 16261632 C:\WINDOWS\RTHDCPL.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-21 01:06 7622656]
"PCDrProfiler"="" []
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2007-07-19 15:17 249856]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-09-18 12:20 180269]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"Lexmark 1200 Series"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 13:22 57344]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [ ]
"BearFlix"="C:\Program Files\BearFlix\BearFlix.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-26 09:47 51048]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2008-02-07 14:49 718704]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]

C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2007-07-19 14:48:57 225280]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-02-07 05:43]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-01-13 10:32]
S3 Symantec RemoteAssist;Symantec RemoteAssist;"C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe" [2008-01-29 16:09]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-02-07 05:43]
S3 XDva039;XDva039;C:\WINDOWS\system32\XDva039.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{63b7122a-9bea-11db-a2f1-0019210a5ec2}]
\Shell\Auto\command - setup.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-03-06 05:11:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-03-03 15:55:14 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Compaq_Owner.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-06 13:44:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-06 13:45:23
ComboFix-quarantined-files.txt 2008-03-06 05:45:14
ComboFix2.txt 2008-03-06 04:54:38
ComboFix3.txt 2008-03-06 02:58:40
.
2007-07-11 07:19:10 — E O F —



Malwarebytes' Anti-Malware 1.07
Database version: 461

Scan type: Quick Scan
Objects scanned: 28372
Time elapsed: 6 minute(s), 22 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijack) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4e7bd74f-2b8d-469e-86bd-fd60bb9aae3a} (Adware.OneToolBar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow\*.securemanaging.com (Trojan.Zlob) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



Logfile of HijackThis v1.99.1
Scan saved at 2:01:17 PM, on 3/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Compaq_Owner\Desktop\Scan.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.singnet.com.sg:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [BearFlix] "C:\Program Files\BearFlix\BearFlix.exe" /pause
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {3AC7F64E-6154-47B0-82B5-764ED4077F77} (DataStorage Class) - http://txn02.hkjc.com/BetSlip/object/eWinCtl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{98E2A609-A246-461A-B7BF-7B5E53E3245B}: NameServer = 165.21.83.88,165.21.100.88
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)


Rgds..
Hi Zainal_9202,

That looks pretty good, how is your machine running now?

Please open Notepad (press Start->Run, enter notepad and press OK)
Copy everything inside the code box below (Starting with REGEDIT4) and paste it into a new notepad file.
Note: Please copy and paste all the text at once, and check that there is NO blank line above REGEDIT4 and one blank line at the bottom.
REGEDIT4

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Change the Save As Type to All Files and save it as fix.reg to your Desktop.
Locate fix.reg on your Desktop, if you did it right it should look like this:[external image: Posted Image]
Double-click it, when it asks if you want to merge with the registry, click Yes.
You can then delete fix.reg

Now, reboot your computer

Once complete, please let me know if you had any problems with the instructions and tell me how your computer is behaving.
Hi Silver , All the instructions have been carried out successfully. The PC looks good…. :notworthy: :notworthy: :notworthy: Thanks for everything.. Is there any anything more that need to be done ? I've just hook up a 120GB , pocket drive & currently in the process of backing up the HDD. What do I do with the Combofix , Malwarebytes & Anti Malwarebytes folder ? By the way , remember the advice & tips that you posted two days back ? would you be kind enough to post them to me again…. Silver , once again I would like to thank you for all your tireless effort & help… Rgds & Thks a million… :woot:
Hi Zainal_9202,

You're very welcome and I'm glad that things are running well.
Yes, we need to clean up again and here are instructions for doing so:

Please delete VundoFix.exe and this folder if present:
C:\VundoFix Backups

Clean up with ComboFix:
  • Make sure ComboFix.exe is on your Desktop
  • Next press Start->Run, copy/paste the following command into the box and press OK:

    "%userprofile%\desktop\combofix.exe" /u

  • You should be informed that "ComboFix is uninstalled", press OK to close the window

You can now delete any remaining tools and logs from your Desktop, and you can remove MalwareBytes Anti-Malware via Add/Remove Programs if you wish, but I recommend you keep it installed as it is an excellent program (and free!).

————————————————————————
Here are some recommendations to help you keep your computer clean:

You have a good antivirus suite installed, however I recommend you also install antispyware software with real-time capabilities - this will protect you from a wider range of malware and also that it will protect you from system changes and spyware while you are working, not just removing malware after it has been installed. There are a range of paid-for and free packages available, a free one I can recommend is Windows Defender, available here:
http://www.microsoft.com/athome/security/s…re/default.mspx

I recommend you install a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.
Also: subscribe to the mailing list to get update notifications.

Please take care when downloading programs. One of the easiest ways to be infected is to download freeware/shareware programs which come laden with malware - this includes allowing websites to install browser plug-ins or ActiveX controls. Before downloading, it is crucial to check whether the source is reputable.
One way to check is to use McAfee SiteAdvisor. Copy the domain name into the space provided and SiteAdvisor will give you a report on the website which can help you decide if it is safe. They also have a toolbar for IE and Firefox which adds this functionality to your browser.

Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

Find out more about how to prevent infection in the future
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know that you have read this, and if there are any further issues.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI