This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Seeking VUNDO Trogan removal help

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, My XP pc becomes impossibly bogged down at times. I hope you can help me remove this problem.
Hours of patient work following advice+ procedures claiming to remove a VUNDO Trojan, but each time I boot I'm greeted by McAfee's Warning: "McAfee has detected an infected file that cannot be repaired. (or Quarantined).
Detection: Vundo (Trojan), Vundo (Trojan) File Path: C:\WINDOWS\system32\pmkjj.dll"

My set up:
Windows Home edition ver. 2002 XP
Svc Pack 2 Critical updates performed.
McAfee Ver 7.2, Build 7.2.151
IExplorer 6.0.2900.2180

This is what I've done:
A. - Ran McAfee's FULL Scan+manual process for removing "VUNDO" , After several hours Scan finishes with a encouraging report of 14 to 17 bad thingsincluding the VUNDO stuff found and dealt with . A hard boot is requested to put the lid on. But VUNDO trojan Warning still shows up after IE is launched
B. - Spybot and LavaSoft don't detect.
C. - VUNDOFIX.exe does not detect.
D. - McAfee Tech support insisted I delete all Spy detect s/w: Lavasoft, spybot etc. dble check all updates and do Step A again. Still, ineffective results.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:34:36 PM, on 3/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\QuickTime\qttask .exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched .exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray .exe
C:\WINDOWS\system32\igfxtray .exe
C:\WINDOWS\system32\ps2 .exe
C:\WINDOWS\system32\hkcmd .exe
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\iTunes\iTunesHelper .exe
C:\Program Files\QuickTime\qttask .exe
C:\windows\system\hpsysdrv .exe
C:\WINDOWS\system32\hphmon06 .exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\TrueAssistant\TrueAssistant.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask .exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\WINDOWS\system32\ctfmon .exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: {b44b7a01-62a7-9bfb-75e4-d35defe4b322} - {223b4efe-d53d-4e57-bfb9-7a2610a7b44b} - (no file)
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {8F9E2BE3-766D-4831-BB0E-766D5B819995} - (no file)
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: (no name) - {A30E6CC8-74B4-40E3-833C-15AAE3799624} - C:\WINDOWS\system32\pmkjj.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {CA4F0D8D-5F2B-4F16-838A-8D52249EAB21} - (no file)
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [b4fe43bd] rundll32.exe "C:\WINDOWS\system32\wgwqcuwb.dll",b
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe AcRdB7_0_0
O4 - HKCU\..\Run: [QdrModule11] "C:\Program Files\QdrModule\QdrModule11.exe"
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\RunOnce: [CheckNetworkConnection] "C:\Program Files\Support.com\providerComcast\desktopdoctor.exe" /flow /flow=diagnosenetwork /trayclick=true /haveconfirmedwiring=true /haverenewed=true /haverestartedmodem=true /onrestart=true /havehealed=true /issuenumber=625c2af8-00f4-4c0d-830a-7b8be1e00372
O4 - Startup: Netscape Online Setup Wizard.lnk = C:\Program Files\Netscape Online\SetupWd.exe
O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Add To HP Organize… - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c18.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: hggedec - hggedec.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Software Jukebox v2.0 Service - Unknown owner - C:\Program Files\Common Files\MSJB NA01D Shared\Service\Software Jukebox v2.0 Service File.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 13380 bytes
Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems. HijackThis logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that it happens.

Please reply to this thread, do not start another.
Please tell me about any problems that have occurred during the fix.
Please tell me of any other symptoms you may be having as these can help also.
Please try as much as possible not to run anything while executing a fix.

As I am still in training, everything that I post to you, must be checked by one of the teachers. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long.

If you follow these instructions, everything should go smoothly.

we are currently looking at your log now and will be back as soon as possible with your instructions.
while you are waiting one other thing that can be of good use is an uninstall list so please do the following

Make an uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in your next reply.


Gringo
Hello piechase

:multiple Anti Virus programs:

It looks like you are operating your computer with multiple Anti Virus programs running in memory at once:

mcafee and
norton


Anti-virus programs take up an enormous amount of your computer's resources when they are actively scanning your computer. Having two anti-virus programs running at the same time can cause your computer to run very slow, become unstable and even, in rare cases, crash.

Please remove one of them.

:disable Ad-Aware 2007:

  • First please disable Ad-Aware 2007 as it may interfere with repairs.

  • Click the Settings button, Auto Scans tab, and under "Scan on Ad-Aware startup",
  • be sure both selections for "No automated scan" are checked (green).
  • Then click Save and close Ad-Aware.

    remember to turn this back on when we finish with the repairs

:run combofix:

Download Combofix from any of the links below, and save it to your desktop. For information regarding this download, please visit this webpage: how-to-use-combofix

Link 1
Link 2
Link 3

**Note: It is important that it is saved directly to your desktop**

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note:Do not mouseclick combofix's window while it's running. That may cause it to stall


:information and logs:

In your next post I need the following

1.let me know about the antiviruses
2.send me the log from combofix
3.let me have a new hijackthis log
4.and let me have the uninstall list

Gringo
Gringo,

Thank You.

1- Ad-Aware was in disabled state and remains so, per your request.

1A- I chose to remove Norton, but it's not letting me de-install 2 segments: "NORTON WMI update" & "LiveReg (Symantec corp)".

2- ComboFix: It proceded normally to the "Scanning for infected files…….." Then I got "ERROR : This machine already has a recovery console installed — ABORTING operations. " (comment: I turned off all apps per request except McAfee, I have the comcast McAfee which has no hi-level control, I went ahead with combofix attempt. I tried 2x , same result.

3 New hijackthis log follows.
4 uninstall list follows.

Thks, Jim

3 - Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:36:10 AM, on 3/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\AGRSMMSG.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask .exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\TrueAssistant\TrueAssistant.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: {b44b7a01-62a7-9bfb-75e4-d35defe4b322} - {223b4efe-d53d-4e57-bfb9-7a2610a7b44b} - (no file)
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: (no name) - {766A6DBB-96EF-40DD-9DA0-337D71137ED9} - C:\WINDOWS\system32\pmkjj.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {8F9E2BE3-766D-4831-BB0E-766D5B819995} - (no file)
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {CA4F0D8D-5F2B-4F16-838A-8D52249EAB21} - (no file)
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [b4fe43bd] rundll32.exe "C:\WINDOWS\system32\wgwqcuwb.dll",b
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe AcRdB7_0_0
O4 - HKCU\..\Run: [QdrModule11] "C:\Program Files\QdrModule\QdrModule11.exe"
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\RunOnce: [CheckNetworkConnection] "C:\Program Files\Support.com\providerComcast\desktopdoctor.exe" /flow /flow=diagnosenetwork /trayclick=true /haveconfirmedwiring=true /haverenewed=true /haverestartedmodem=true /onrestart=true /havehealed=true /issuenumber=625c2af8-00f4-4c0d-830a-7b8be1e00372
O4 - Startup: Netscape Online Setup Wizard.lnk = C:\Program Files\Netscape Online\SetupWd.exe
O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Add To HP Organize… - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c18.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: hggedec - hggedec.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Software Jukebox v2.0 Service - Unknown owner - C:\Program Files\Common Files\MSJB NA01D Shared\Service\Software Jukebox v2.0 Service File.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 12818 bytes

4 - UnInstall List:
Ad-Aware 2007
Adobe Flash Player ActiveX
Adobe Reader 7.0
Agere Systems PCI Soft Modem
CC_ccProxyMSI
CC_ccStart
Comcast High-Speed Internet Install Wizard
Comcast Toolbar
Desktop Doctor
DivX Web Player
Easy Internet Sign-up
EasyChange Powered by TrueSwitch
FirstClass® Client
Google Earth
Help and Support Additions
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Windows XP (KB935448)
HP Deskjet Preloaded Printer Drivers
HP Image Zone 4.2
HP Image Zone Plus 4.2
HP Organize
HP Photo & Imaging 3.5 - HP Devices
HP PSC & OfficeJet 4.0
HP Software Update
HPIZ402
Intel® Graphics Media Accelerator Driver
IntelliMover Data Transfer Demo
Internet Speed Monitor
InterVideo WinDVD Creator 2
InterVideo WinDVD Player
iTunes
J2SE Runtime Environment 5.0 Update 3
Java 2 Runtime Environment, SE v1.4.2_03
KBD
Learn2 Player (Uninstall Only)
LimeWire 4.12.11
LiveReg (Symantec Corporation)
Macromedia Shockwave Player
McAfee SecurityCenter
Medieval Total War
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Excel 97
Microsoft Office 2003 Web Components
Microsoft Office Standard Edition 2003
Microsoft Office XP Web Components
Microsoft Plus! Dancer LE
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Word 97
Microsoft Works 7.0
Mozilla Firefox (2.0.0.12)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
Musicmatch® Jukebox
muvee autoProducer 3.5 magicMoments - HPD
Netscape Online
Norton AntiVirus 2004
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Personal Firewall
Norton WMI Update
NVIDIA GART Driver
PC-Doctor for Windows
PCFriendly
Photosmart 320,370,7400,8100,8400 Series
Picasa 2
PS2
Quicken 2004
QuickTime
RealPlayer
SecondLife (remove only)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB946026)
Shutterfly Plugin
Skype 3.0
Skype Plugin Manager
Software Jukebox 2.0 NA-01D
Sonic RecordNow!
SoulSeek Client 156
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Updates from HP
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Viewpoint Toolbar (Remove Only)
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Yahoo! Toolbar
Hello Gringo,

All the minor issues I reported at 9:40 AM are resolved. I've delivered to you everything you requested to help me repair the VUNDO Trojan prob.

Here's the ComboFix file:
Is this everything we need to proceed?
Thanks,
Jim

ComboFix 08-03-10.1 - HP_Owner 2008-03-11 22:21:08.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.177 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\HP_Owner\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\HP_Owner\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Program Files\ISM
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\qdrloader.exe
C:\Program Files\QdrModule
C:\Program Files\QdrModule\QdrModule11 .exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\000080.exe
C:\WINDOWS\system32\bwucqwgw.ini
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\cwyobnnu.ini
C:\WINDOWS\system32\eosaymos.ini
C:\WINDOWS\system32\jjkmp.ini
C:\WINDOWS\system32\jjkmp.ini2
C:\WINDOWS\system32\kmtqypdu.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mjodajlj.ini
C:\WINDOWS\system32\sjewygtw.ini
C:\WINDOWS\system32\somyasoe.dll
C:\WINDOWS\system32\syvgolok.ini
C:\WINDOWS\system32\wgwqcuwb.dll
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-02-12 to 2008-03-12 )))))))))))))))))))))))))))))))
.

2008-03-11 14:56 . 2008-03-11 14:56 61,224 –a—— C:\Documents and Settings\HP_Owner\GoToAssistDownloadHelper.exe
2008-03-11 14:32 . 2008-03-11 14:32 d——– C:\Documents and Settings\HP_Owner\Application Data\McAfee
2008-03-11 09:57 . 2008-03-11 09:57 d——– C:\ComboFix[1]
2008-03-10 18:33 . 2008-03-10 18:33 d——– C:\Program Files\Trend Micro
2008-03-10 17:00 . 2008-03-10 17:00 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-03-10 16:12 . 2008-03-10 16:12 d——– C:\VundoFix Backups
2008-03-09 17:50 . 2008-03-09 17:50 d——– C:\Program Files\Enigma Software Group
2008-03-08 00:25 . 2008-03-08 00:25 d——– C:\Program Files\Lavasoft
2008-03-08 00:25 . 2008-03-10 17:01 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-07 23:46 . 2008-03-07 23:46 d—s—- C:\Documents and Settings\Administrator\UserData
2008-03-07 22:56 . 2004-08-07 17:22 d——– C:\Documents and Settings\Administrator\WINDOWS
2008-03-07 22:56 . 2004-08-07 17:59 d——– C:\Documents and Settings\Administrator\Application Data\SampleView
2008-03-07 22:56 . 2004-08-07 17:20 d——– C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-03-04 19:46 . 2008-03-04 19:49 d——– C:\Program Files\Shutterfly
2008-02-17 13:14 . 2008-02-17 13:14 145 –a—— C:\WINDOWS\wininit.ini
2008-02-17 11:39 . 2008-03-10 09:41 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-13 22:17 . 2008-03-11 22:25 5,380 –a—— C:\WINDOWS\system32\Config.MPF
2008-02-13 21:57 . 2006-03-03 12:07 143,360 –a—— C:\WINDOWS\system32\dunzip32.dll
2008-02-13 21:51 . 2008-02-06 10:51 171,400 –a—— C:\WINDOWS\system32\drivers\mfehidk.sys
2008-02-13 21:51 . 2007-03-02 15:16 109,608 –a—— C:\WINDOWS\system32\drivers\Mpfp.sys
2008-02-13 21:51 . 2007-06-25 15:54 71,496 –a—— C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-02-13 21:51 . 2007-06-25 11:57 37,480 –a—— C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-02-13 21:51 . 2007-06-25 11:57 34,184 –a—— C:\WINDOWS\system32\drivers\mfebopk.sys
2008-02-13 21:51 . 2007-06-25 11:57 32,008 –a—— C:\WINDOWS\system32\drivers\mferkdk.sys
2008-02-13 21:50 . 2008-02-13 21:50 d——– C:\Program Files\McAfee.com
2008-02-13 21:49 . 2008-03-07 22:18 d——– C:\Program Files\McAfee
2008-02-13 21:49 . 2008-02-13 21:55 d——– C:\Program Files\Common Files\McAfee
2008-02-13 21:45 . 2008-03-11 14:36 d——– C:\Documents and Settings\All Users\Application Data\McAfee

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-11 18:19 81,920 —-a-w C:\WINDOWS\system32\ps2.exe
2008-03-11 18:19 659,456 —-a-w C:\WINDOWS\system32\hphmon06.exe
2008-03-11 18:19 155,648 —-a-w C:\WINDOWS\system32\igfxtray.exe
2008-03-11 18:19 15,360 —-a-w C:\WINDOWS\system32\ctfmon .exe
2008-03-11 18:19 118,784 —-a-w C:\WINDOWS\system32\hkcmd.exe
2008-03-11 18:18 ——— d—–w C:\Program Files\QuickTime
2008-03-11 18:18 ——— d—–w C:\Program Files\iTunes
2008-03-11 18:16 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-10 22:16 81,920 —-a-w C:\WINDOWS\system32\ps2 .exe
2008-03-10 22:16 659,456 —-a-w C:\WINDOWS\system32\hphmon06 .exe
2008-03-10 22:16 155,648 —-a-w C:\WINDOWS\system32\igfxtray .exe
2008-03-10 22:16 118,784 —-a-w C:\WINDOWS\system32\hkcmd .exe
2008-02-14 01:37 ——— d—–w C:\Program Files\support.com
2008-02-06 01:11 1,194,436 –sha-w C:\WINDOWS\system32\xdvatfue.tmp
2008-02-06 01:11 ——— d—–w C:\Program Files\Picasa2
2008-02-04 03:10 ——— d—–w C:\Program Files\Netscape Online
2008-01-30 22:21 ——— d—–w C:\Program Files\Google
2008-01-28 15:49 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-28 15:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-28 15:44 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-28 15:43 ——— d—–w C:\Program Files\AIM Toolbar
2008-01-13 11:35 ——— d—–w C:\Documents and Settings\HP_Owner\Application Data\AdobeUM
2007-12-23 23:19 4,008 —-a-w C:\WINDOWS\viassary-hp.reg
2007-12-14 15:32 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
.
—-a-w			61,440 2008-01-20 16:40:11  C:\hp\KBD\KBD .EXE
—-a-w		   180,272 2008-03-10 22:16:38  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w			70,776 2008-02-01 01:36:37  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w			49,152 2008-03-10 22:16:32  C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06 .exe
—-a-w		   286,720 2008-03-10 22:16:38  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w			36,976 2008-03-10 22:16:30  C:\Program Files\Java\jre1.5.0_03\bin\jusched .exe
—-a-w		 1,694,208 2008-01-11 22:21:53  C:\Program Files\Messenger\msmsgs .exe
—-a-w			53,248 2008-03-10 22:16:52  C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask .exe
—-a-w		   135,168 2008-03-10 22:16:38  C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray .exe
—-a-w		   443,968 2008-02-06 01:08:57  C:\Program Files\Picasa2\PicasaMediaDetector .exe
—-a-w			98,304 2008-03-11 18:19:16  C:\Program Files\QuickTime\qttask																							.exe
—-a-w			98,304 2008-03-12 01:21:34  C:\Program Files\QuickTime\qttask																						   .exe
—-a-w			98,304 2008-03-10 21:31:13  C:\Program Files\QuickTime\qttask																						  .exe
—-a-w			98,304 2008-03-10 13:15:07  C:\Program Files\QuickTime\qttask																						 .exe
—-a-w			98,304 2008-03-09 21:52:25  C:\Program Files\QuickTime\qttask																						.exe
—-a-w			98,304 2008-03-09 20:20:09  C:\Program Files\QuickTime\qttask																					   .exe
—-a-w			98,304 2008-03-09 20:20:09  C:\Program Files\QuickTime\qttask																					  .exe
—-a-w			98,304 2008-03-09 20:20:10  C:\Program Files\QuickTime\qttask																					 .exe
—-a-w			98,304 2008-03-09 20:20:10  C:\Program Files\QuickTime\qttask																					.exe
—-a-w			98,304 2008-03-07 22:32:31  C:\Program Files\QuickTime\qttask																				   .exe
—-a-w			98,304 2008-03-04 23:01:57  C:\Program Files\QuickTime\qttask																				  .exe
—-a-w			98,304 2008-03-05 02:32:44  C:\Program Files\QuickTime\qttask																				 .exe
—-a-w			98,304 2008-02-17 15:47:43  C:\Program Files\QuickTime\qttask																				.exe
—-a-w			98,304 2008-03-05 02:32:53  C:\Program Files\QuickTime\qttask																			   .exe
—-a-w			98,304 2008-02-15 21:16:20  C:\Program Files\QuickTime\qttask																			  .exe
—-a-w			98,304 2008-02-15 23:06:25  C:\Program Files\QuickTime\qttask																			 .exe
—-a-w			98,304 2008-02-15 23:06:25  C:\Program Files\QuickTime\qttask																			.exe
—-a-w			98,304 2008-02-15 23:06:25  C:\Program Files\QuickTime\qttask																		   .exe
—-a-w			98,304 2008-02-15 23:06:28  C:\Program Files\QuickTime\qttask																		  .exe
—-a-w			98,304 2008-02-15 23:06:29  C:\Program Files\QuickTime\qttask																		 .exe
—-a-w			98,304 2008-02-14 04:48:26  C:\Program Files\QuickTime\qttask																		.exe
—-a-w			98,304 2008-02-14 01:49:28  C:\Program Files\QuickTime\qttask																	   .exe
—-a-w			98,304 2008-02-14 04:48:30  C:\Program Files\QuickTime\qttask																	  .exe
—-a-w			98,304 2008-02-14 04:48:37  C:\Program Files\QuickTime\qttask																	 .exe
—-a-w			98,304 2008-02-14 04:48:38  C:\Program Files\QuickTime\qttask																	.exe
—-a-w			98,304 2008-02-14 04:48:39  C:\Program Files\QuickTime\qttask																   .exe
—-a-w			98,304 2008-02-14 04:48:40  C:\Program Files\QuickTime\qttask																  .exe
—-a-w			98,304 2008-02-14 04:48:41  C:\Program Files\QuickTime\qttask																 .exe
—-a-w			98,304 2008-02-14 04:48:41  C:\Program Files\QuickTime\qttask																.exe
—-a-w			98,304 2008-02-14 04:48:42  C:\Program Files\QuickTime\qttask															   .exe
—-a-w			98,304 2008-02-14 04:48:44  C:\Program Files\QuickTime\qttask															  .exe
—-a-w			98,304 2008-02-14 04:48:44  C:\Program Files\QuickTime\qttask															 .exe
—-a-w			98,304 2008-02-14 04:48:45  C:\Program Files\QuickTime\qttask															.exe
—-a-w			98,304 2008-02-14 04:48:45  C:\Program Files\QuickTime\qttask														   .exe
—-a-w			98,304 2008-02-14 04:48:45  C:\Program Files\QuickTime\qttask														  .exe
—-a-w			98,304 2008-02-14 04:48:50  C:\Program Files\QuickTime\qttask														 .exe
—-a-w			98,304 2008-02-14 04:48:54  C:\Program Files\QuickTime\qttask														.exe
—-a-w			98,304 2008-02-14 04:48:54  C:\Program Files\QuickTime\qttask													   .exe
—-a-w			98,304 2008-02-14 04:48:55  C:\Program Files\QuickTime\qttask													  .exe
—-a-w			98,304 2008-02-14 04:48:55  C:\Program Files\QuickTime\qttask													 .exe
—-a-w			98,304 2008-02-14 04:48:56  C:\Program Files\QuickTime\qttask													.exe
—-a-w			98,304 2008-02-14 04:48:57  C:\Program Files\QuickTime\qttask												   .exe
—-a-w			98,304 2008-02-14 04:48:57  C:\Program Files\QuickTime\qttask												  .exe
—-a-w			98,304 2008-02-14 04:48:57  C:\Program Files\QuickTime\qttask												 .exe
—-a-w			98,304 2008-02-14 04:48:57  C:\Program Files\QuickTime\qttask												.exe
—-a-w			98,304 2008-02-14 04:48:58  C:\Program Files\QuickTime\qttask											   .exe
—-a-w			98,304 2008-02-14 04:48:58  C:\Program Files\QuickTime\qttask											  .exe
—-a-w			98,304 2008-02-14 04:48:58  C:\Program Files\QuickTime\qttask											 .exe
—-a-w			98,304 2008-02-14 04:48:59  C:\Program Files\QuickTime\qttask											.exe
—-a-w			98,304 2008-02-14 04:48:59  C:\Program Files\QuickTime\qttask										   .exe
—-a-w			98,304 2008-02-14 04:48:59  C:\Program Files\QuickTime\qttask										  .exe
—-a-w			98,304 2008-02-14 04:49:07  C:\Program Files\QuickTime\qttask										 .exe
—-a-w			98,304 2008-02-14 04:49:10  C:\Program Files\QuickTime\qttask										.exe
—-a-w			98,304 2008-02-14 04:49:11  C:\Program Files\QuickTime\qttask									   .exe
—-a-w			98,304 2008-02-14 04:49:11  C:\Program Files\QuickTime\qttask									  .exe
—-a-w			98,304 2008-02-14 04:49:11  C:\Program Files\QuickTime\qttask									 .exe
—-a-w			98,304 2008-02-14 04:49:11  C:\Program Files\QuickTime\qttask									.exe
—-a-w			98,304 2008-02-14 04:49:11  C:\Program Files\QuickTime\qttask								   .exe
—-a-w			98,304 2008-02-14 04:49:12  C:\Program Files\QuickTime\qttask								  .exe
—-a-w			98,304 2008-02-14 04:49:12  C:\Program Files\QuickTime\qttask								 .exe
—-a-w			98,304 2008-02-14 04:49:12  C:\Program Files\QuickTime\qttask								.exe
—-a-w			98,304 2008-02-14 04:49:13  C:\Program Files\QuickTime\qttask							   .exe
—-a-w			98,304 2008-02-14 04:49:13  C:\Program Files\QuickTime\qttask							  .exe
—-a-w			98,304 2008-02-14 04:49:13  C:\Program Files\QuickTime\qttask							 .exe
—-a-w			98,304 2008-02-14 04:49:13  C:\Program Files\QuickTime\qttask							.exe
—-a-w			98,304 2008-02-14 04:49:14  C:\Program Files\QuickTime\qttask						   .exe
—-a-w			98,304 2008-02-14 04:49:14  C:\Program Files\QuickTime\qttask						  .exe
—-a-w			98,304 2008-02-14 04:49:14  C:\Program Files\QuickTime\qttask						 .exe
—-a-w			98,304 2008-02-14 04:49:14  C:\Program Files\QuickTime\qttask						.exe
—-a-w			98,304 2008-02-14 04:49:17  C:\Program Files\QuickTime\qttask					   .exe
—-a-w			98,304 2008-02-14 04:49:24  C:\Program Files\QuickTime\qttask					  .exe
—-a-w			98,304 2008-02-14 04:49:26  C:\Program Files\QuickTime\qttask					 .exe
—-a-w			98,304 2008-02-14 04:49:28  C:\Program Files\QuickTime\qttask					.exe
—-a-w			98,304 2008-02-14 04:49:32  C:\Program Files\QuickTime\qttask				   .exe
—-a-w			98,304 2008-02-14 04:49:38  C:\Program Files\QuickTime\qttask				  .exe
—-a-w			98,304 2008-02-14 04:49:39  C:\Program Files\QuickTime\qttask				 .exe
—-a-w			98,304 2008-02-14 04:49:39  C:\Program Files\QuickTime\qttask				.exe
—-a-w			98,304 2008-02-14 04:49:40  C:\Program Files\QuickTime\qttask			   .exe
—-a-w			98,304 2008-02-14 04:49:40  C:\Program Files\QuickTime\qttask			  .exe
—-a-w			98,304 2008-02-14 04:49:40  C:\Program Files\QuickTime\qttask			 .exe
—-a-w			98,304 2008-02-14 04:49:41  C:\Program Files\QuickTime\qttask			.exe
—-a-w			98,304 2008-02-14 04:49:41  C:\Program Files\QuickTime\qttask		   .exe
—-a-w			98,304 2008-02-14 04:49:41  C:\Program Files\QuickTime\qttask		  .exe
—-a-w			98,304 2008-02-14 04:49:41  C:\Program Files\QuickTime\qttask		 .exe
—-a-w			98,304 2008-02-14 04:49:41  C:\Program Files\QuickTime\qttask		.exe
—-a-w			98,304 2008-02-14 04:49:42  C:\Program Files\QuickTime\qttask	   .exe
—-a-w			98,304 2008-02-14 04:49:42  C:\Program Files\QuickTime\qttask	  .exe
—-a-w			98,304 2008-02-14 04:49:42  C:\Program Files\QuickTime\qttask	 .exe
—-a-w			98,304 2008-02-14 04:49:42  C:\Program Files\QuickTime\qttask	.exe
—-a-w			98,304 2008-02-14 04:49:42  C:\Program Files\QuickTime\qttask   .exe
—-a-w			98,304 2008-02-14 04:49:43  C:\Program Files\QuickTime\qttask  .exe
—-a-w			98,304 2008-02-14 04:49:46  C:\Program Files\QuickTime\qttask .exe
—-a-w		25,365,032 2008-01-07 23:13:01  C:\Program Files\Skype\Phone\Skype .exe
—-a-w		 1,773,568 2008-02-14 02:24:10  C:\Program Files\support.com\bin\tgcmd .exe
—-a-w		   233,472 2008-03-10 22:16:39  C:\WINDOWS\SMINST\RECGUARD .EXE
—-a-w			52,736 2008-03-10 22:16:30  C:\WINDOWS\system\hpsysdrv .exe
—-a-w			15,360 2008-03-11 18:19:02  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   118,784 2008-03-10 22:16:30  C:\WINDOWS\system32\hkcmd .exe
—-a-w		   659,456 2008-03-10 22:16:40  C:\WINDOWS\system32\hphmon06 .exe
—-a-w		   155,648 2008-03-10 22:16:36  C:\WINDOWS\system32\igfxtray .exe
—-a-w			81,920 2008-03-10 22:16:35  C:\WINDOWS\system32\ps2 .exe


– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5F09B9B3-B7C3-4D7E-92F6-D6BEA0605BBD}]
C:\WINDOWS\system32\pmkjj.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:00 15360]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [ ]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe" [ ]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [ ]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"CheckNetworkConnection"="C:\Program Files\Support.com\providerComcast\desktopdoctor.exe" [2006-06-02 16:13 1286144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2008-03-11 14:19 36976]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [2008-03-11 14:19 52736]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2008-03-11 14:19 118784]
"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2008-03-11 14:19 49152]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2008-03-11 14:19 659456]
"KBD"="C:\HP\KBD\KBD.EXE" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-11 14:19 180272]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-11 14:19 286720]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2008-03-11 14:19 233472]
"VTTimer"="VTTimer.exe" []
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 12:01 88209 C:\WINDOWS\AGRSMMSG.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2008-03-11 14:19 81920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [2008-03-11 14:19 98304]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2008-03-11 14:19 155648]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [2005-04-06 18:57 90112 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-04-06 18:53 2805248 C:\WINDOWS\ALCWZRD.EXE]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2008-03-11 14:19 135168]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2008-03-11 14:19 53248]
"tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [ ]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-04 15:00 143360]

C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\
Netscape Online Setup Wizard.lnk - C:\Program Files\Netscape Online\SetupWd.exe [2008-02-03 23:09:41 675840]
TrueAssistant.lnk - C:\Program Files\TrueAssistant\TrueAssistant.exe [2005-04-02 10:08:48 372224]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-29 08:31:38 241664]
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1997-08-19 01:00:00 111376]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1997-08-19 01:00:00 51984]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2004-01-29 00:36:18 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hggedec]
hggedec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"C:\\Program Files\\Soulseek\\slsk.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype .exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-14 01:50:49 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-02-14 01:50:48 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-11 22:26:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\system32\wdfmgr.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2008-03-11 22:27:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-12 02:27:45
.
2008-02-14 08:16:51 — E O F —
hello jim

P2P Warning!

IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

LimeWire 4.12.11

Please note that as long as you are using any form of Peer-to-Peer networking and downloading files from non-documented sources, you can expect infestations of malware to occur
Once upon a time, P2P file sharing was fairly safe. That is no longer true. You may continue to use P2P sharing at your own risk; however, please keep in mind that this practice may be the source of your current malware infestation

I'd like you to read the Guidelines for P2P Programs where we explain why it's not a good idea to have them.

References for the risk of these programs can be found in these links: http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm
See Clean/Infected P2P Programs here

I would recommend that you uninstall LimeWire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

:Run CFScript:

Open Notepad and copy/paste the text in the box into the window:

File::
C:\WINDOWS\system32\pmkjj.dll
hggedec.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5F09B9B3-B7C3-4D7E-92F6-D6BEA0605BBD}]

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hggedec]

RenV::
—-a-w			61,440 2008-01-20 16:40:11  C:\hp\KBD\KBD .EXE
—-a-w		   180,272 2008-03-10 22:16:38  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w			70,776 2008-02-01 01:36:37  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w			49,152 2008-03-10 22:16:32  C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06 .exe
—-a-w		   286,720 2008-03-10 22:16:38  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w			36,976 2008-03-10 22:16:30  C:\Program Files\Java\jre1.5.0_03\bin\jusched .exe
—-a-w		 1,694,208 2008-01-11 22:21:53  C:\Program Files\Messenger\msmsgs .exe
—-a-w			53,248 2008-03-10 22:16:52  C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask .exe
—-a-w		   135,168 2008-03-10 22:16:38  C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray .exe
—-a-w		   443,968 2008-02-06 01:08:57  C:\Program Files\Picasa2\PicasaMediaDetector .exe
—-a-w			98,304 2008-03-11 18:19:16  C:\Program Files\QuickTime\qttask																							.exe
—-a-w			98,304 2008-03-12 01:21:34  C:\Program Files\QuickTime\qttask																						   .exe
—-a-w			98,304 2008-03-10 21:31:13  C:\Program Files\QuickTime\qttask																						  .exe
—-a-w			98,304 2008-03-10 13:15:07  C:\Program Files\QuickTime\qttask																						 .exe
—-a-w			98,304 2008-03-09 21:52:25  C:\Program Files\QuickTime\qttask																						.exe
—-a-w			98,304 2008-03-09 20:20:09  C:\Program Files\QuickTime\qttask																					   .exe
—-a-w			98,304 2008-03-09 20:20:09  C:\Program Files\QuickTime\qttask																					  .exe
—-a-w			98,304 2008-03-09 20:20:10  C:\Program Files\QuickTime\qttask																					 .exe
—-a-w			98,304 2008-03-09 20:20:10  C:\Program Files\QuickTime\qttask																					.exe
—-a-w			98,304 2008-03-07 22:32:31  C:\Program Files\QuickTime\qttask																				   .exe
—-a-w			98,304 2008-03-04 23:01:57  C:\Program Files\QuickTime\qttask																				  .exe
—-a-w			98,304 2008-03-05 02:32:44  C:\Program Files\QuickTime\qttask																				 .exe
—-a-w			98,304 2008-02-17 15:47:43  C:\Program Files\QuickTime\qttask																				.exe
—-a-w			98,304 2008-03-05 02:32:53  C:\Program Files\QuickTime\qttask																			   .exe
—-a-w			98,304 2008-02-15 21:16:20  C:\Program Files\QuickTime\qttask																			  .exe
—-a-w			98,304 2008-02-15 23:06:25  C:\Program Files\QuickTime\qttask																			 .exe
—-a-w			98,304 2008-02-15 23:06:25  C:\Program Files\QuickTime\qttask																			.exe
—-a-w			98,304 2008-02-15 23:06:25  C:\Program Files\QuickTime\qttask																		   .exe
—-a-w			98,304 2008-02-15 23:06:28  C:\Program Files\QuickTime\qttask																		  .exe
—-a-w			98,304 2008-02-15 23:06:29  C:\Program Files\QuickTime\qttask																		 .exe
—-a-w			98,304 2008-02-14 04:48:26  C:\Program Files\QuickTime\qttask																		.exe
—-a-w			98,304 2008-02-14 01:49:28  C:\Program Files\QuickTime\qttask																	   .exe
—-a-w			98,304 2008-02-14 04:48:30  C:\Program Files\QuickTime\qttask																	  .exe
—-a-w			98,304 2008-02-14 04:48:37  C:\Program Files\QuickTime\qttask																	 .exe
—-a-w			98,304 2008-02-14 04:48:38  C:\Program Files\QuickTime\qttask																	.exe
—-a-w			98,304 2008-02-14 04:48:39  C:\Program Files\QuickTime\qttask																   .exe
—-a-w			98,304 2008-02-14 04:48:40  C:\Program Files\QuickTime\qttask																  .exe
—-a-w			98,304 2008-02-14 04:48:41  C:\Program Files\QuickTime\qttask																 .exe
—-a-w			98,304 2008-02-14 04:48:41  C:\Program Files\QuickTime\qttask																.exe
—-a-w			98,304 2008-02-14 04:48:42  C:\Program Files\QuickTime\qttask															   .exe
—-a-w			98,304 2008-02-14 04:48:44  C:\Program Files\QuickTime\qttask															  .exe
—-a-w			98,304 2008-02-14 04:48:44  C:\Program Files\QuickTime\qttask															 .exe
—-a-w			98,304 2008-02-14 04:48:45  C:\Program Files\QuickTime\qttask															.exe
—-a-w			98,304 2008-02-14 04:48:45  C:\Program Files\QuickTime\qttask														   .exe
—-a-w			98,304 2008-02-14 04:48:45  C:\Program Files\QuickTime\qttask														  .exe
—-a-w			98,304 2008-02-14 04:48:50  C:\Program Files\QuickTime\qttask														 .exe
—-a-w			98,304 2008-02-14 04:48:54  C:\Program Files\QuickTime\qttask														.exe
—-a-w			98,304 2008-02-14 04:48:54  C:\Program Files\QuickTime\qttask													   .exe
—-a-w			98,304 2008-02-14 04:48:55  C:\Program Files\QuickTime\qttask													  .exe
—-a-w			98,304 2008-02-14 04:48:55  C:\Program Files\QuickTime\qttask													 .exe
—-a-w			98,304 2008-02-14 04:48:56  C:\Program Files\QuickTime\qttask													.exe
—-a-w			98,304 2008-02-14 04:48:57  C:\Program Files\QuickTime\qttask												   .exe
—-a-w			98,304 2008-02-14 04:48:57  C:\Program Files\QuickTime\qttask												  .exe
—-a-w			98,304 2008-02-14 04:48:57  C:\Program Files\QuickTime\qttask												 .exe
—-a-w			98,304 2008-02-14 04:48:57  C:\Program Files\QuickTime\qttask												.exe
—-a-w			98,304 2008-02-14 04:48:58  C:\Program Files\QuickTime\qttask											   .exe
—-a-w			98,304 2008-02-14 04:48:58  C:\Program Files\QuickTime\qttask											  .exe
—-a-w			98,304 2008-02-14 04:48:58  C:\Program Files\QuickTime\qttask											 .exe
—-a-w			98,304 2008-02-14 04:48:59  C:\Program Files\QuickTime\qttask											.exe
—-a-w			98,304 2008-02-14 04:48:59  C:\Program Files\QuickTime\qttask										   .exe
—-a-w			98,304 2008-02-14 04:48:59  C:\Program Files\QuickTime\qttask										  .exe
—-a-w			98,304 2008-02-14 04:49:07  C:\Program Files\QuickTime\qttask										 .exe
—-a-w			98,304 2008-02-14 04:49:10  C:\Program Files\QuickTime\qttask										.exe
—-a-w			98,304 2008-02-14 04:49:11  C:\Program Files\QuickTime\qttask									   .exe
—-a-w			98,304 2008-02-14 04:49:11  C:\Program Files\QuickTime\qttask									  .exe
—-a-w			98,304 2008-02-14 04:49:11  C:\Program Files\QuickTime\qttask									 .exe
—-a-w			98,304 2008-02-14 04:49:11  C:\Program Files\QuickTime\qttask									.exe
—-a-w			98,304 2008-02-14 04:49:11  C:\Program Files\QuickTime\qttask								   .exe
—-a-w			98,304 2008-02-14 04:49:12  C:\Program Files\QuickTime\qttask								  .exe
—-a-w			98,304 2008-02-14 04:49:12  C:\Program Files\QuickTime\qttask								 .exe
—-a-w			98,304 2008-02-14 04:49:12  C:\Program Files\QuickTime\qttask								.exe
—-a-w			98,304 2008-02-14 04:49:13  C:\Program Files\QuickTime\qttask							   .exe
—-a-w			98,304 2008-02-14 04:49:13  C:\Program Files\QuickTime\qttask							  .exe
—-a-w			98,304 2008-02-14 04:49:13  C:\Program Files\QuickTime\qttask							 .exe
—-a-w			98,304 2008-02-14 04:49:13  C:\Program Files\QuickTime\qttask							.exe
—-a-w			98,304 2008-02-14 04:49:14  C:\Program Files\QuickTime\qttask						   .exe
—-a-w			98,304 2008-02-14 04:49:14  C:\Program Files\QuickTime\qttask						  .exe
—-a-w			98,304 2008-02-14 04:49:14  C:\Program Files\QuickTime\qttask						 .exe
—-a-w			98,304 2008-02-14 04:49:14  C:\Program Files\QuickTime\qttask						.exe
—-a-w			98,304 2008-02-14 04:49:17  C:\Program Files\QuickTime\qttask					   .exe
—-a-w			98,304 2008-02-14 04:49:24  C:\Program Files\QuickTime\qttask					  .exe
—-a-w			98,304 2008-02-14 04:49:26  C:\Program Files\QuickTime\qttask					 .exe
—-a-w			98,304 2008-02-14 04:49:28  C:\Program Files\QuickTime\qttask					.exe
—-a-w			98,304 2008-02-14 04:49:32  C:\Program Files\QuickTime\qttask				   .exe
—-a-w			98,304 2008-02-14 04:49:38  C:\Program Files\QuickTime\qttask				  .exe
—-a-w			98,304 2008-02-14 04:49:39  C:\Program Files\QuickTime\qttask				 .exe
—-a-w			98,304 2008-02-14 04:49:39  C:\Program Files\QuickTime\qttask				.exe
—-a-w			98,304 2008-02-14 04:49:40  C:\Program Files\QuickTime\qttask			   .exe
—-a-w			98,304 2008-02-14 04:49:40  C:\Program Files\QuickTime\qttask			  .exe
—-a-w			98,304 2008-02-14 04:49:40  C:\Program Files\QuickTime\qttask			 .exe
—-a-w			98,304 2008-02-14 04:49:41  C:\Program Files\QuickTime\qttask			.exe
—-a-w			98,304 2008-02-14 04:49:41  C:\Program Files\QuickTime\qttask		   .exe
—-a-w			98,304 2008-02-14 04:49:41  C:\Program Files\QuickTime\qttask		  .exe
—-a-w			98,304 2008-02-14 04:49:41  C:\Program Files\QuickTime\qttask		 .exe
—-a-w			98,304 2008-02-14 04:49:41  C:\Program Files\QuickTime\qttask		.exe
—-a-w			98,304 2008-02-14 04:49:42  C:\Program Files\QuickTime\qttask	   .exe
—-a-w			98,304 2008-02-14 04:49:42  C:\Program Files\QuickTime\qttask	  .exe
—-a-w			98,304 2008-02-14 04:49:42  C:\Program Files\QuickTime\qttask	 .exe
—-a-w			98,304 2008-02-14 04:49:42  C:\Program Files\QuickTime\qttask	.exe
—-a-w			98,304 2008-02-14 04:49:42  C:\Program Files\QuickTime\qttask   .exe
—-a-w			98,304 2008-02-14 04:49:43  C:\Program Files\QuickTime\qttask  .exe
—-a-w			98,304 2008-02-14 04:49:46  C:\Program Files\QuickTime\qttask .exe
—-a-w		25,365,032 2008-01-07 23:13:01  C:\Program Files\Skype\Phone\Skype .exe
—-a-w		 1,773,568 2008-02-14 02:24:10  C:\Program Files\support.com\bin\tgcmd .exe
—-a-w		   233,472 2008-03-10 22:16:39  C:\WINDOWS\SMINST\RECGUARD .EXE
—-a-w			52,736 2008-03-10 22:16:30  C:\WINDOWS\system\hpsysdrv .exe
—-a-w			15,360 2008-03-11 18:19:02  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   118,784 2008-03-10 22:16:30  C:\WINDOWS\system32\hkcmd .exe
—-a-w		   659,456 2008-03-10 22:16:40  C:\WINDOWS\system32\hphmon06 .exe
—-a-w		   155,648 2008-03-10 22:16:36  C:\WINDOWS\system32\igfxtray .exe
—-a-w			81,920 2008-03-10 22:16:35  C:\WINDOWS\system32\ps2 .exe


Save it to your desktop as CFScript.txt

Refering to the picture above, drag CFScript.txt into ComboFix.exe
[external image: Posted Image]
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

: Malwarebytes' Anti-Malware :

  • Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
    • Update Malwarebytes' Anti-Malware
    • and Launch Malwarebytes' Anti-Malware
  • then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply
    • If you accidently close it, the log file is saved here and will be named like this:
    • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt



: uninstall list

I know you gave me one but I would like to see a new one

Make an uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.

:information and logs:

In your next post I need the following

1.the cobofix log
2.log from MBAM
3.the new uninstall list
4.new log from hijackthis
5.let me know how the computer is doing


Gringo
Gringo_PR, It's great to hear from you.

The information and logs you requested follow.
1.the cobofix log
2.log from MBAM
3.the new uninstall list
4.new log from hijackthis
5.let me know how the computer is doing

Let me start by saying I'll take your warnings about "P2P file sharing programs" under advisement.
I will not use "Limeware" while we work on my issue. The Vundo Trojan we're trying to kill is on the
PC of a family member and I'm sure they'll ok "Limeware" removal when I advise them.

How is our problem computer doing? Yesterday it started behaving LIKE NEW. All of a sudden
the serial VUNDO Trojan warnings from McAfee stopped. The unbelieveably bogged down performance stopped too.
I can't think of any direct action I took to cause this positve change. (I only performed std maint such as Defrag cleanup, etc.)

1. ComboFix log
ComboFix 08-03-10.1 - HP_Owner 2008-03-13 9:35:30.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.172 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Owner\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\system32\pmkjj.dll
.

((((((((((((((((((((((((( Files Created from 2008-02-13 to 2008-03-13 )))))))))))))))))))))))))))))))
.

2008-03-12 21:38 . 2007-06-05 10:56 44,928 –a—— C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-03-12 21:37 . 2007-06-08 09:44 8,576 –a—— C:\WINDOWS\system32\drivers\ltkghxxqxphp.sys
2008-03-12 21:24 . 2008-03-12 21:24 2,550 –a—— C:\WINDOWS\system32\Uninstall.ico
2008-03-12 21:24 . 2008-03-12 21:24 1,406 –a—— C:\WINDOWS\system32\Help.ico
2008-03-12 10:35 . 2008-03-12 11:14 d——– C:\Program Files\Windows Live Safety Center
2008-03-11 14:56 . 2008-03-11 14:56 61,224 –a—— C:\Documents and Settings\HP_Owner\GoToAssistDownloadHelper.exe
2008-03-11 14:32 . 2008-03-11 14:32 d——– C:\Documents and Settings\HP_Owner\Application Data\McAfee
2008-03-11 09:57 . 2008-03-11 09:57 d——– C:\ComboFix[1]
2008-03-10 18:33 . 2008-03-10 18:33 d——– C:\Program Files\Trend Micro
2008-03-10 17:00 . 2008-03-10 17:00 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-03-10 16:12 . 2008-03-10 16:12 d——– C:\VundoFix Backups
2008-03-09 17:50 . 2008-03-09 17:50 d——– C:\Program Files\Enigma Software Group
2008-03-08 00:25 . 2008-03-08 00:25 d——– C:\Program Files\Lavasoft
2008-03-08 00:25 . 2008-03-10 17:01 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-07 23:46 . 2008-03-07 23:46 d—s—- C:\Documents and Settings\Administrator\UserData
2008-03-07 22:56 . 2004-08-07 17:22 d——– C:\Documents and Settings\Administrator\WINDOWS
2008-03-07 22:56 . 2004-08-07 17:59 d——– C:\Documents and Settings\Administrator\Application Data\SampleView
2008-03-07 22:56 . 2004-08-07 17:20 d——– C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-03-04 19:46 . 2008-03-04 19:49 d——– C:\Program Files\Shutterfly
2008-02-17 13:14 . 2008-02-17 13:14 145 –a—— C:\WINDOWS\wininit.ini
2008-02-17 11:39 . 2008-03-10 09:41 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-13 22:17 . 2008-03-13 09:39 5,816 –a—— C:\WINDOWS\system32\Config.MPF
2008-02-13 21:57 . 2006-03-03 12:07 143,360 –a—— C:\WINDOWS\system32\dunzip32.dll
2008-02-13 21:51 . 2008-02-06 10:51 171,400 –a—— C:\WINDOWS\system32\drivers\mfehidk.sys
2008-02-13 21:51 . 2007-03-02 15:16 109,608 –a—— C:\WINDOWS\system32\drivers\Mpfp.sys
2008-02-13 21:51 . 2007-06-25 15:54 71,496 –a—— C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-02-13 21:51 . 2007-06-25 11:57 37,480 –a—— C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-02-13 21:51 . 2007-06-25 11:57 34,184 –a—— C:\WINDOWS\system32\drivers\mfebopk.sys
2008-02-13 21:51 . 2007-06-25 11:57 32,008 –a—— C:\WINDOWS\system32\drivers\mferkdk.sys
2008-02-13 21:50 . 2008-02-13 21:50 d——– C:\Program Files\McAfee.com
2008-02-13 21:49 . 2008-03-07 22:18 d——– C:\Program Files\McAfee
2008-02-13 21:49 . 2008-02-13 21:55 d——– C:\Program Files\Common Files\McAfee
2008-02-13 21:45 . 2008-03-11 14:36 d——– C:\Documents and Settings\All Users\Application Data\McAfee

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-13 13:39 ——— d—–w C:\Documents and Settings\HP_Owner\Application Data\Skype
2008-03-13 13:38 ——— d—–w C:\Program Files\QuickTime
2008-03-13 13:38 ——— d—–w C:\Program Files\iTunes
2008-03-13 13:34 ——— d—–w C:\Program Files\Picasa2
2008-03-13 13:34 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-13 02:05 ——— d—–w C:\Program Files\TrueAssistant
2008-03-13 01:53 ——— d—–w C:\Program Files\ComcastToolbar
2008-03-12 23:10 ——— d—–w C:\Program Files\Viewpoint
2008-03-12 23:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-12 23:09 ——— d—–w C:\Documents and Settings\HP_Owner\Application Data\Viewpoint
2008-02-14 01:37 ——— d—–w C:\Program Files\support.com
2008-02-04 03:10 ——— d—–w C:\Program Files\Netscape Online
2008-01-30 22:21 ——— d—–w C:\Program Files\Google
2008-01-28 15:49 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-28 15:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-28 15:44 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-28 15:43 ——— d—–w C:\Program Files\AIM Toolbar
2008-01-13 11:35 ——— d—–w C:\Documents and Settings\HP_Owner\Application Data\AdobeUM
2007-12-23 23:19 4,008 —-a-w C:\WINDOWS\viassary-hp.reg
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:00 15360]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-01-07 19:13 25365032]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-01-11 18:21 1694208]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe" [ ]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-05 21:08 443968]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"CheckNetworkConnection"="C:\Program Files\Support.com\providerComcast\desktopdoctor.exe" [2006-06-02 16:13 1286144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2008-03-10 18:16 36976]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [2008-03-10 18:16 52736]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2008-03-10 18:16 118784]
"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2008-03-10 18:16 49152]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2008-03-10 18:16 659456]
"KBD"="C:\HP\KBD\KBD.EXE" [2008-01-20 12:40 61440]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-10 18:16 180272]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-10 18:16 286720]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2008-03-10 18:16 233472]
"VTTimer"="VTTimer.exe" []
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 12:01 88209 C:\WINDOWS\AGRSMMSG.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2008-03-10 18:16 81920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2008-03-10 18:16 155648]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [2005-04-06 18:57 90112 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-04-06 18:53 2805248 C:\WINDOWS\ALCWZRD.EXE]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2008-03-10 18:16 135168]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2008-03-10 18:16 53248]
"tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [2008-02-13 22:24 1773568]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-04 15:00 143360]

C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\
Netscape Online Setup Wizard.lnk - C:\Program Files\Netscape Online\SetupWd.exe [2008-02-03 23:09:41 675840]
TrueAssistant.lnk - C:\Program Files\TrueAssistant\TrueAssistant.exe [2005-04-02 10:08:48 372224]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-29 08:31:38 241664]
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1997-08-19 01:00:00 111376]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1997-08-19 01:00:00 51984]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2004-01-29 00:36:18 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"C:\\Program Files\\Soulseek\\slsk.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=


.
Contents of the 'Scheduled Tasks' folder
"2008-02-14 01:50:49 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-02-14 01:50:48 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-13 09:39:38
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-03-13 9:42:26 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-13 13:42:22
ComboFix2.txt 2008-03-12 02:27:51
.
2008-03-12 13:07:57 — E O F —

2. MBAM Log:
Malwarebytes' Anti-Malware 1.08
Database version: 483

Scan type: Full Scan (C:\|D:\|G:\|H:\|I:\|J:\|)
Objects scanned: 99963
Time elapsed: 30 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 18
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\bndblock4.band (Adware.ISM) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bndblock4.band.1 (Adware.ISM) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{1fe2ebe5-42ff-4586-a144-ca420c84ff6a} (Adware.ISM) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bndblock4.bho (Adware.ISM) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bndblock4.bho.1 (Adware.ISM) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d4a714f6-af40-4425-b708-ff03cbbc0a84} (Adware.ISM) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\568267acfc5644dab06f058006ddbae3 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BndBlock4.DLL (Adware.ISM) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BndBlock4.Band (Adware.ISM) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BndBlock4.Band.1 (Adware.ISM) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BndBlock4.BHO (Adware.ISM) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BndBlock4.BHO.1 (Adware.ISM) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\Zango 10.0.314.0 (Adware.Zango) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\QooBox\Quarantine\C\Program Files\QdrDrive\qdrloader.exe.vir (Trojan.Agent) -> Quarantined and deleted successfully.

3.- Uninstall List:

Ad-Aware 2007
Adobe Flash Player ActiveX
Adobe Reader 7.0
Agere Systems PCI Soft Modem
Comcast High-Speed Internet Install Wizard
Comcast Toolbar
Desktop Doctor
DivX Web Player
Easy Internet Sign-up
EasyChange Powered by TrueSwitch
FirstClass® Client
Google Earth
Help and Support Additions
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Windows XP (KB935448)
HP Deskjet Preloaded Printer Drivers
HP Image Zone 4.2
HP Image Zone Plus 4.2
HP Organize
HP Photo & Imaging 3.5 - HP Devices
HP PSC & OfficeJet 4.0
HP Software Update
HPIZ402
Intel® Graphics Media Accelerator Driver
IntelliMover Data Transfer Demo
InterVideo WinDVD Creator 2
InterVideo WinDVD Player
iTunes
J2SE Runtime Environment 5.0 Update 3
Java 2 Runtime Environment, SE v1.4.2_03
KBD
Learn2 Player (Uninstall Only)
LimeWire 4.12.11
Macromedia Shockwave Player
Malwarebytes' Anti-Malware
McAfee SecurityCenter
Medieval Total War
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Excel 97
Microsoft Office 2003 Web Components
Microsoft Office Standard Edition 2003
Microsoft Office XP Web Components
Microsoft Plus! Dancer LE
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Word 97
Microsoft Works 7.0
Mozilla Firefox (2.0.0.12)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
Musicmatch® Jukebox
muvee autoProducer 3.5 magicMoments - HPD
Netscape Online
NVIDIA GART Driver
PC-Doctor for Windows
PCFriendly
Photosmart 320,370,7400,8100,8400 Series
Picasa 2
PS2
Quicken 2004
QuickTime
RealPlayer
SecondLife (remove only)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB946026)
Shutterfly Plugin
Skype 3.0
Skype Plugin Manager
Software Jukebox 2.0 NA-01D
Sonic RecordNow!
SoulSeek Client 156
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Updates from HP
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Live OneCare safety scanner
Windows Media Format Runtime
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Yahoo! Toolbar

4.- hijackthis Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:40:41 AM, on 3/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\TrueAssistant\TrueAssistant.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe AcRdB7_0_0
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\RunOnce: [CheckNetworkConnection] "C:\Program Files\Support.com\providerComcast\desktopdoctor.exe" /flow /flow=diagnosenetwork /trayclick=true /haveconfirmedwiring=true /haverenewed=true /haverestartedmodem=true /onrestart=true /havehealed=true /issuenumber=625c2af8-00f4-4c0d-830a-7b8be1e00372
O4 - Startup: Netscape Online Setup Wizard.lnk = C:\Program Files\Netscape Online\SetupWd.exe
O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Add To HP Organize… - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…wlscbase370.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Software Jukebox v2.0 Service - Unknown owner - C:\Program Files\Common Files\MSJB NA01D Shared\Service\Software Jukebox v2.0 Service File.exe

–
End of file - 9755 bytes

Talk to you soon. Thank you….Jim
Hi Gringo, I decided to do a run of "MS LIVE OneCare Safety Scanner". The Computer seems fine now but The Scan tells me different. I'm hoping this might help us move things along. Here's the Scan Report: 📎LiveCare.doc
Hello jim

I decided to do a run of "MS LIVE OneCare Safety Scanner". The Computer seems fine now but
The Scan tells me different. I'm hoping this might help us move things along. Here's the Scan Report:


those files are the Quarantine folders from the tools that I had you run



:upload files to jotti:

  • Please upload a file for scanning:
  • Open virusscan.jotti
  • Copy/paste this file and path into the white box at the top:

C:\WINDOWS\system32\drivers\ltkghxxqxphp.sys

Press Submit - this will submit the file for testing.
Please wait for all the scanners to finish then copy and paste the results in your next response.

please do this with each of these files one at a time

C:\WINDOWS\system32\drivers\ltkghxxqxphp.sys


save the reports and send with your next reply
Note: If Jotti is busy, you can use VirusTotal instead.

:uninstall some programs:

1. click on start
2. then go to settings
3. after that you need control panel
4. look for the icon add remove programs
click on the following programs

J2SE Runtime Environment 5.0 Update 3
Java 2 Runtime Environment, SE v1.4.2_03


and click on remove

note:: please restart the computer

: Update Java :

Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to update.
  • Download the latest version of Java™ SE Runtime Environment 6u5.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Then from your desktop double-click on the download to install the newest version.

:Run Kaspersky Online AV Scanner:

Order to use it you have to use Internet Explorer.
Go to Kaspersky and click the Accept button at the end of the page.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
  • Read the Requirements and limitations before you click Accept.
  • Allow the ActiveX download if necessary.
  • Once the database has downloaded, click Next.
  • Click Scan Settings and change the "Scan using the following antivirus database" from standard to extended and then click OK.
  • Click on "My Computer"
  • When the scan has completed, click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.

    Copy and paste the report into your next reply

:information and logs:

In your next post I need the following

1.log from jotti
2.log from kaspersky
3.new log from hijackthis
4.how is the computer doing

Gringo
Hi Gringo,
The Java upgrade went ok. Plus you asked for and I sent:
1.log from jotti
2.log from kaspersky
3.new log from hijackthis
4.how is the computer doing

Sorry, I found the Jotti log instruction ambiguous:
Am I supposed to scan the "ltkghxxqxphp.sys" 2x or maybe some other file?
I scanned ltkghxxqxphp.sys 1x and fwd to you.





:upload files to jotti:

  • Please upload a file for scanning:
    • Open virusscan.jotti
    • Copy/paste this file and path into the white box at the top:

    C:\WINDOWS\system32\drivers\ltkghxxqxphp.sys

    Press Submit - this will submit the file for testing.
    Please wait for all the scanners to finish then copy and paste the results in your next response.

    please do this with each of these files one at a time

    C:\WINDOWS\system32\drivers\ltkghxxqxphp.sys


    save the reports and send with your next reply



    1. Log from jotti:
    Service load: 0% 100%

    File: ltkghxxqxphp.sys
    Status: OK(Note: file has been scanned before. Therefore, this file's scan results will not be stored in the database)
    MD5: d7dbfbc453b645111e6d21142305e80b
    Packers detected: -
    Bit9 reports: File not found

    Scanner results
    Scan taken on 17 Mar 2008 22:24:39 (GMT)
    A-Squared Found nothing
    AntiVir Found nothing
    ArcaVir Found nothing
    Avast Found nothing
    AVG Antivirus Found nothing
    BitDefender Found nothing
    ClamAV Found nothing
    CPsecure Found nothing
    Dr.Web Found nothing
    F-Prot Antivirus Found nothing
    F-Secure Anti-Virus Found nothing
    Fortinet Found nothing
    Ikarus Found nothing
    Kaspersky Anti-Virus Found nothing
    NOD32 Found nothing
    Norman Virus Control Found nothing
    Panda Antivirus Found nothing
    Rising Antivirus Found nothing
    Sophos Antivirus Found nothing
    VirusBuster Found nothing
    VBA32 Found nothing

    2. Log from Kaspersky:
    KASPERSKY ONLINE SCANNER REPORT
    Monday, March 17, 2008 9:13:57 PM
    Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 17/03/2008
    Kaspersky Anti-Virus database records: 636268


    Scan Settings
    Scan using the following antivirus database extended
    Scan Archives true
    Scan Mail Bases true

    Scan Target My Computer
    C:\
    D:\
    E:\
    F:\
    G:\
    H:\
    I:\
    J:\

    Scan Statistics
    Total number of scanned objects 73437
    Number of viruses found 3
    Number of infected objects 5
    Number of suspicious objects 0
    Duration of the scan process 01:43:57

    Infected Object Name Virus Name Last Action
    C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{45AD67F0-9F7E-4D00-BE23-15C5D70769E5}.log Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR1.tmp Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Support.com\profiles\HP_Owner\triggers.log Object is locked skipped

    C:\Documents and Settings\HP_Owner\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\HP_Owner\Local Settings\Temp\hpodvd09.log Object is locked skipped

    C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\HP_Owner\My Documents\My Music\iTunes\iTunes Music\07 Track 7.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped

    C:\Documents and Settings\HP_Owner\My Documents\My Music\iTunes\iTunes Music\Rare Recording.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped

    C:\Documents and Settings\HP_Owner\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\HP_Owner\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

    C:\Program Files\muvee Technologies\muvee autoProducer 3.5 magicMoments - HPD\Samples\CandyLand-dm.exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\chandir.dat Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\chandir.idx Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\chn.dat Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\chn.idx Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\D0000000.FCS Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\inuse.txt Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\L0000001.FCS Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\main.log Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\prs.dat Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\prs.idx Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_die.dat Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_die.idx Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_dnd.dat Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_dnd.idx Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_ext.dat Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_ext.idx Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_rcv.dat Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_rcv.idx Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\storydb.dat Object is locked skipped

    C:\Program Files\Updates from HP\309731\Users\Default\Data\storydb.idx Object is locked skipped

    C:\QooBox\Quarantine\C\WINDOWS\system32\somyasoe.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

    C:\QooBox\Quarantine\C\WINDOWS\system32\wgwqcuwb.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    C:\System Volume Information\_restore{E7B21304-9105-4D9D-AFAC-E7088FDCC6A0}\RP7\change.log Object is locked skipped

    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

    C:\WINDOWS\SchedLgU.Txt Object is locked skipped

    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

    C:\WINDOWS\Sti_Trace.log Object is locked skipped

    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\default Object is locked skipped

    C:\WINDOWS\system32\config\default.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SAM Object is locked skipped

    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

    C:\WINDOWS\system32\config\software Object is locked skipped

    C:\WINDOWS\system32\config\software.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\system Object is locked skipped

    C:\WINDOWS\system32\config\system.LOG Object is locked skipped

    C:\WINDOWS\system32\h323log.txt Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

    C:\WINDOWS\Temp\mcafee_FO1TyktOTqrjSvr Object is locked skipped

    C:\WINDOWS\Temp\mcafee_ueuG8GuSMhTYx4W Object is locked skipped

    C:\WINDOWS\Temp\mcmsc_BK4gteGuZAST7nx Object is locked skipped

    C:\WINDOWS\Temp\mcmsc_iaLOAdPygQdQNkM Object is locked skipped

    C:\WINDOWS\Temp\mcmsc_JFcg4TaE2U5gYRw Object is locked skipped

    C:\WINDOWS\Temp\mcmsc_jFu0o8013TaNdAp Object is locked skipped

    C:\WINDOWS\wiadebug.log Object is locked skipped

    C:\WINDOWS\wiaservc.log Object is locked skipped

    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    3.New log from hijackthis:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:17:25 PM, on 3/17/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\PROGRA~1\McAfee\MPS\mps.exe
    C:\WINDOWS\system32\svchost.exe
    C:\windows\system\hpsysdrv.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\hphmon06.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\ALCWZRD.EXE
    C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
    C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    C:\Program Files\Microsoft Office\Office\OSA.EXE
    C:\Program Files\McAfee\MPS\mpsevh.exe
    C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    C:\Program Files\TrueAssistant\TrueAssistant.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Support.com\bin\tgcmd.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
    O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
    O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
    O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
    O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
    O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
    O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe AcRdB7_0_0
    O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    O4 - HKCU\..\RunOnce: [CheckNetworkConnection] "C:\Program Files\Support.com\providerComcast\desktopdoctor.exe" /flow /flow=diagnosenetwork /trayclick=true /haveconfirmedwiring=true /haverenewed=true /haverestartedmodem=true /onrestart=true /havehealed=true /issuenumber=625c2af8-00f4-4c0d-830a-7b8be1e00372
    O4 - Startup: Netscape Online Setup Wizard.lnk = C:\Program Files\Netscape Online\SetupWd.exe
    O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: Add To HP Organize… - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O15 - Trusted Zone: http://*.mcafee.com
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…wlscbase370.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
    O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Software Jukebox v2.0 Service - Unknown owner - C:\Program Files\Common Files\MSJB NA01D Shared\Service\Software Jukebox v2.0 Service File.exe

    –
    End of file - 10356 bytes
    Scan process completed.



    4.How is the computer doing?
    The computer seems normal. No constant McAfee reminders about presence of VUNDO Trojan. Nor are there the fake Windows warning msg boxes about computer errors, adware stuff & click for free scan" etc, etc.
If Gringo hasn't replied before you need to return the PC, be sure to do this before you do.

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI