This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] trojan\winbo32\enhance & RUNDLL ERROR

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi , thank you for your anticipated help.
A couple of days ago my daughter downloaded LIMEWIRE 16.14, and ever since then I have had the following problems, at startup I get a message "ERROR loading c:\windows\uxmbohch.dll the specified module cannot be found." and another error REGSVR32 Load Library ("C:\Documentsand Settings\All Users\Application Data\pozsralk.dll") Failed-The specific Module could not be found.
I also have found the Trojan\winbo32\enhance virus on my scans with SUPERANTISPYWARE (which I remove ,but the next time I check the virus comes back).
Another problem I am having is with the search engines GOOGLE and YAHOO, when searching in Google the screen comes up with the search results in the middle and it is surrounded by SPONSERED LINKS on both sides (if I refresh the screen it displays correctly until I do another search. With the YAHOO search the screen keeps blink very very fast the word YAHOO and the text blinks repeatedly. I have turned off all my SYSTEM RESTORE POINTS .I have since ran SPYBOT 1.5 and this is what my error log read:
Search result list —
Rabio.SearchEnhancer: [SBI $E3AEF3D2] Program directory (Directory, nothing done)
C:\Documents and Settings\All Users\Application Data\Rabio\Search Enhancer\

TagASaurus: [SBI $0F18797C] Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\System

TagASaurus: [SBI $A5527063] Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\System\sysold


— Spybot - Search & Destroy version: 1.5.2 (build: 20080128) —
After running spybot , I then ran SUPERANTISPYWARE and this is the error log I received:

Memory items scanned : 485
Memory threats detected : 0
Registry items scanned : 5739
Registry threats detected : 2
File items scanned : 49356
File threats detected : 5

Adware.Tracking Cookie
C:\Documents and Settings\Owner\Cookies\[removed][1].txt
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[1].txt
C:\Documents and Settings\Owner\Cookies\owner@2o7[2].txt
C:\Documents and Settings\Owner\Cookies\owner@indextools[2].txt
C:\Documents and Settings\Owner\Cookies\owner@atdmt[2].txt

Trojan.WinBo32/Enhance
HKU\S-1-5-21-1429147517-2468864202-290325556-1003\Software\System\sysuid

Adware.AdSponsor/ISM
HKU\S-1-5-21-1429147517-2468864202-290325556-1003\Software\QdrModule


After fixing those errors I closed the program and rebooted at which time I ran HIJACKTHIS, Here is my log for Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:48:41 PM, on 3/11/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\ss245sd.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINDOWS\System32\winlugan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\Program Files\Bat\X_Bat.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SPAMfighter\sfus.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UTSCSI.EXE
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Owner\Application Data\mjusbsp\magicJack.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_clipbook.exe
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\AR41S7U1\HiJackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://therx.com/
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: BatBHO - {63F7460B-C831-4142-A4AA-5EC303EC4343} - C:\Program Files\Bat\Bat.dll
O2 - BHO: DiginkBHO Class - {73fc67a7-bdd3-48d0-b358-3a11bab21720} - C:\WINDOWS\TinyBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: BndFibu7 IE Helper - {8041E642-8CFC-4720-BC9D-D2DB8904286F} - C:\Program Files\QdrDrive\QdrDrive12.dll (file missing)
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\PROGRA~1\mcafee\mps\mcpopup.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [TorontoMail] sysconf16.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1161439287\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [ppmate] C:\Program Files\PPMate\PPMate\ppmate.exe -autoplay
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ss245sd] C:\WINDOWS\ss245sd.exe
O4 - HKLM\..\Run: [pozsralk] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\pozsralk.dll"
O4 - HKLM\..\RunOnce: [MRUBlaster] C:\Program Files\MRU-Blaster\indexcleaner.exe -CACHE
O4 - HKCU\..\Run: [sound64] barint.exe
O4 - HKCU\..\Run: [media64] TForm1.exe
O4 - HKCU\..\Run: [MsNetHelper] init32.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [QdrModule13] "C:\Program Files\QdrModule\QdrModule13.exe"
O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe"
O4 - HKLM\..\Policies\Explorer\Run: [xaJzMIov4W] C:\WINDOWS\tazerofg.exe
O4 - HKLM\..\Policies\Explorer\Run: [3BEmKIov4W] rundll32.exe "C:\WINDOWS\uxmbohch.dll",DllCleanServer
O4 - HKCU\..\Policies\Explorer\Run: [{34D37E51-07CE-1033-0704-031113020001}] "C:\Program Files\Common Files\{34D37E51-07CE-1033-0704-031113020001}\Update.exe" te-110-12-0000213
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [sound64] barint.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [media64] TForm1.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [MsNetHelper] init32.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [cdloader] "C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [QdrModule13] "C:\Program Files\QdrModule\QdrModule13.exe" (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe" (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Policies\Explorer\Run: [{34D37E51-07CE-1033-0704-031113020001}] "C:\Program Files\Common Files\{34D37E51-07CE-1033-0704-031113020001}\Update.exe" te-110-12-0000213 (User '?')
O4 - S-1-5-21-1429147517-2468864202-290325556-1003 Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe (User '?')
O4 - S-1-5-21-1429147517-2468864202-290325556-1003 Startup: Magnifier.lnk = C:\WINDOWS\system32\magnify.exe (User '?')
O4 - S-1-5-21-1429147517-2468864202-290325556-1003 Startup: MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe (User '?')
O4 - S-1-5-21-1429147517-2468864202-290325556-1003 Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe (User '?')
O4 - Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe
O4 - Startup: Magnifier.lnk = C:\WINDOWS\system32\magnify.exe
O4 - Startup: MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Owner\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Owner\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00000005-0000-0000-0000-100009000004} - http://code.trasferimento.biz/l/2acc042149…1f7c301f_35.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - http://aolsvc.aol.com/onlinegames/sonybewitched/main.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/…ash/swflash.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: iifdbby - iifdbby.dll (file missing)
O20 - Winlogon Notify: wineil32 - wineil32.dll (file missing)
O23 - Service: 1Google Online Search Service - Unknown owner - C:\WINDOWS\System32\winlugan.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe (file missing)
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\System32\UTSCSI.EXE

–
End of file - 14863 bytes
Hello and welcome to the forum.

Important: Do this before any fix.

Please put your HijackThis in it's own folder, (I create a new folder in C:\ named HJT).
You can do a Right Click on any open area on the desktop, New> Folder, then rename the folder HJT.

Go to where your HijackThis is and Right Click on HijackThis.exe, select Cut, then open the new folder you just created (HJT) Right Click in the folder and select paste.

The reason we do this is Hijackthis creates backup files just in case you'd need to restore one and we'll be cleaning out the temp files.
Hi LD and thank you for taking the time to help me out. just an updateI do not have a problem with the yahoo and googles seaqrches any longer , however I am still getting the trojan\winbo32\enhance.
here is my latest Superantispyware log and my latest HJT log (which I have move the exe file to its own folder)

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 03/15/2008 at 02:14 AM

Application Version : 3.9.1008

Core Rules Database Version : 3420
Trace Rules Database Version: 1412

Scan type : Complete Scan
Total Scan Time : 01:12:54

Memory items scanned : 479
Memory threats detected : 0
Registry items scanned : 5708
Registry threats detected : 1
File items scanned : 50124
File threats detected : 10

Adware.Tracking Cookie
C:\Documents and Settings\Owner\Cookies\owner@revenue[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adserver[1].txt
C:\Documents and Settings\Owner\Cookies\owner@statcounter[1].txt
C:\Documents and Settings\Owner\Cookies\owner@2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@apmebf[1].txt
C:\Documents and Settings\Owner\Cookies\owner@fastclick[1].txt
C:\Documents and Settings\Owner\Cookies\[removed][2].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[1].txt
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[2].txt
C:\Documents and Settings\Owner\Cookies\[removed][2].txt

Trojan.WinBo32/Enhance
HKU\S-1-5-21-1429147517-2468864202-290325556-1003\Software\System\sysuid


Here is my latest HJT LOG:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:05:57 PM, on 3/15/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\S3tray2.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\Program Files\Bat\X_Bat.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SPAMfighter\sfus.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UTSCSI.EXE
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Owner\Application Data\mjusbsp\magicJack.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\Hijackthis\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [TorontoMail] sysconf16.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1161439287\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [ppmate] C:\Program Files\PPMate\PPMate\ppmate.exe -autoplay
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [sound64] barint.exe
O4 - HKCU\..\Run: [media64] TForm1.exe
O4 - HKCU\..\Run: [MsNetHelper] init32.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [QdrModule13] "C:\Program Files\QdrModule\QdrModule13.exe"
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [sound64] barint.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [media64] TForm1.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [MsNetHelper] init32.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [Aim6] (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [cdloader] "C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [QdrModule13] "C:\Program Files\QdrModule\QdrModule13.exe" (User '?')
O4 - S-1-5-21-1429147517-2468864202-290325556-1003 Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe (User '?')
O4 - S-1-5-21-1429147517-2468864202-290325556-1003 Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe (User '?')
O4 - Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Owner\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Owner\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00000005-0000-0000-0000-100009000004} - http://code.trasferimento.biz/l/2acc042149…1f7c301f_35.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - http://aolsvc.aol.com/onlinegames/sonybewitched/main.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/…ash/swflash.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: iifdbby - iifdbby.dll (file missing)
O20 - Winlogon Notify: wineil32 - wineil32.dll (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe (file missing)
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\System32\UTSCSI.EXE

–
End of file - 10836 bytes
Any reason you're still using Platform: Windows XP SP1 (WinNT 5.01.2600) and not SP2?

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Give it atleast 20-30 minutes to finish
Hi LD , sorry I did not respond quicker as I had to run some errands for my mom.
Here is my combofix log:

ComboFix 08-03-14.4 - Owner 2008-03-16 14:11:04.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Local Settings\Temporary Internet Files\Content.IE5\G5WZ854Z\ComboFix[1].exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\X6DVZTVU\www.broadcaster.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Program Files\Common Files\{34D37~1
C:\Program Files\Common Files\dobe~1
C:\WINDOWS\ms047566588622008.exe
C:\WINDOWS\saiemod.dll
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\components
C:\WINDOWS\system32\lsp.dll
C:\WINDOWS\voiceip.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\LEGACY_NPF


((((((((((((((((((((((((( Files Created from 2008-02-16 to 2008-03-16 )))))))))))))))))))))))))))))))
.

2008-03-14 22:33 . 2008-03-14 22:33 23,392 –a—— C:\WINDOWS\system32\nscompat.tlb
2008-03-14 22:33 . 2008-03-14 22:33 16,832 –a—— C:\WINDOWS\system32\amcompat.tlb
2008-03-14 22:23 . 2008-03-14 22:23 d——– C:\Program Files\Common Files\Knowledge Adventure
2008-03-14 22:21 . 2008-03-14 22:21 d——– C:\Documents and Settings\All Users\Application Data\Knowledge Adventure
2008-03-14 02:54 . 2008-03-14 02:54 69,632 –a—— C:\WINDOWS\system32\s3tray2.exe
2008-03-14 01:48 . 2008-03-14 01:48 59,904 –a—— C:\syswkpe.exe
2008-03-13 17:44 . 2008-03-13 17:44 d——– C:\Program Files\Trend Micro
2008-03-13 00:59 . 2008-03-13 00:59 d——– C:\WINDOWS\ERUNT
2008-03-13 00:46 . 2008-03-13 01:31 d——– C:\SDFix
2008-03-10 21:09 . 2008-03-10 21:09 d——– C:\Program Files\Spybot - Search & Destroy
2008-03-10 21:09 . 2008-03-11 01:05 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-10 20:16 . 2008-03-10 20:16 d——– C:\Program Files\MRU-Blaster
2008-03-10 14:17 . 2008-03-10 14:17 d——– C:\Documents and Settings\Owner\.magicfix
2008-03-10 14:17 . 2008-03-10 14:17 45,056 –a—— C:\WINDOWS\system32\UTSCSI.EXE
2008-03-10 02:11 . 2008-03-10 02:11 d——– C:\VundoFix Backups
2008-03-10 01:24 . 2008-03-10 01:24 d——– C:\Program Files\Enigma Software Group
2008-03-08 16:58 . 2008-03-08 16:58 3,805,830 –a—— C:\WINDOWS\3BEmKIov4W.exe
2008-03-08 16:56 . 2008-03-13 01:06 d——– C:\WINDOWS\cswthdtr
2008-03-08 16:56 . 2008-03-08 16:56 44,544 –a—— C:\WINDOWS\elmtirat.exe
2008-03-08 13:40 . 2008-03-11 21:05 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-08 13:26 . 2008-03-08 13:26 d——– C:\Program Files\stc
2008-03-08 13:26 . 2008-03-08 13:26 d——– C:\Program Files\180search assistant
2008-03-08 13:26 . 2008-03-08 13:26 30,976 –a—— C:\WINDOWS\msa64chk.dll
2008-03-08 13:26 . 2008-03-08 13:26 22,272 –a—— C:\WINDOWS\system32\MSNSA32.dll
2008-03-08 13:26 . 2008-03-08 13:26 16,640 –a—— C:\WINDOWS\msapasrc.dll
2008-03-08 13:25 . 2008-03-08 13:25 d——– C:\Program Files\Sysmnt
2008-03-08 13:14 . 2008-03-08 16:49 6,868 –ahs—- C:\WINDOWS\system32\ijkmp.ini
2008-03-08 13:11 . 2008-03-08 13:22 d——– C:\Program Files\Bat
2008-03-08 13:09 . 2008-03-08 13:09 295,819 –a—— C:\WINDOWS\system32\L154.tmp
2008-03-08 13:08 . 2008-03-08 13:08 229,532 –a—— C:\WINDOWS\system32\LE456.tmp
2008-03-02 02:03 . 2002-12-29 01:14 81,920 –a—— C:\WINDOWS\system32\Startup.cpl
2008-02-29 17:19 . 2008-02-29 17:19 d——– C:\Program Files\Common Files\xing shared
2008-02-25 20:57 . 2008-02-25 20:59 d——– C:\Documents and Settings\Owner\Application Data\U3
2008-02-24 14:02 . 2008-02-24 14:02 287 –a—— C:\Shortcut to PRESARIO ©.lnk
2008-02-20 14:50 . 2002-08-29 02:01 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2008-02-20 14:50 . 2002-08-29 02:01 134,272 –a–c— C:\WINDOWS\system32\dllcache\portcls.sys
2008-02-20 14:50 . 2002-08-29 01:32 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2008-02-20 14:50 . 2002-08-29 01:32 57,856 –a–c— C:\WINDOWS\system32\dllcache\drmk.sys
2008-02-20 14:50 . 2002-08-29 01:32 56,832 –a—— C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-02-20 14:50 . 2002-08-29 01:32 56,832 –a–c— C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-02-20 14:48 . 2008-03-15 00:50 d——– C:\Documents and Settings\Owner\Application Data\mjusbsp
2008-02-18 17:21 . 2008-02-18 17:21 204,800 –a—— C:\WINDOWS\TinyBHO.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-16 19:24 ——— d—–w C:\Program Files\SPAMfighter
2008-03-15 06:00 ——— d—–w C:\Program Files\SUPERAntiSpyware
2008-03-14 21:27 ——— d—–w C:\Program Files\AIM
2008-03-14 21:27 ——— d—–w C:\Documents and Settings\Owner\Application Data\Aim
2008-03-14 18:40 ——— d—–w C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-03-14 07:34 ——— d—–w C:\Program Files\QuickTime
2008-03-14 07:34 ——— d—–w C:\Program Files\Microsoft IntelliType Pro
2008-03-14 07:34 ——— d—–w C:\Program Files\Microsoft IntelliPoint
2008-03-14 07:34 ——— d—–w C:\Program Files\iTunes
2008-03-12 03:16 ——— d—–w C:\Program Files\Viewpoint
2008-03-11 01:07 ——— d—–w C:\Documents and Settings\Owner\Application Data\ppStream
2008-03-10 00:08 ——— d—–w C:\Program Files\Google
2008-03-09 23:42 4,342 —-a-w C:\WINDOWS\system32\tmp.reg
2008-03-09 04:52 ——— d—–w C:\Program Files\Absolute Poker
2008-03-03 04:58 ——— d—–w C:\Program Files\AIM6
2008-03-02 06:55 ——— d—–w C:\Documents and Settings\Owner\Application Data\Move Networks
2008-02-29 22:18 ——— d—–w C:\Program Files\Common Files\Real
2008-02-29 22:17 499,712 —-a-w C:\WINDOWS\system32\msvcp71.dll
2008-02-29 22:17 348,160 —-a-w C:\WINDOWS\system32\msvcr71.dll
2008-02-29 05:42 ——— d—–w C:\Program Files\AOL Games
2008-02-29 05:41 ——— d—–w C:\Program Files\Common Files\AOL
2008-02-28 03:29 ——— d—–w C:\Program Files\Poker World
2008-02-26 16:40 ——— d—–w C:\Program Files\McAfee
2008-02-16 17:17 ——— d—–w C:\Program Files\AOD
2008-02-16 17:14 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-14 03:02 ——— d—–w C:\Documents and Settings\Owner\Application Data\Leadertech
2008-02-10 05:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-02-08 22:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-02-06 14:51 171,400 —-a-w C:\WINDOWS\system32\drivers\mfehidk.sys
2008-01-24 06:24 ——— d—–w C:\Program Files\Canon
2008-01-22 23:49 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-22 23:48 ——— d—–w C:\Program Files\Quicken
2008-01-22 23:46 ——— d—–w C:\Program Files\PokerStars
2008-01-08 16:55 208,896 —-a-w C:\WINDOWS\ss245sd.exe
2007-04-12 04:43 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2007-03-17 07:12 374 —-a-w C:\Documents and Settings\Owner\Application Data\internaldb6334.dat
2007-03-17 07:02 18,432 —-a-w C:\Documents and Settings\Owner\Application Data\internaldb41.dat
2007-03-17 06:02 538 —-a-w C:\Documents and Settings\Owner\Application Data\internaldb8467.dat
.
Files Infected - Win32.Agent.zb
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"sound64"="barint.exe" []
"media64"="TForm1.exe" []
"MsNetHelper"="init32.exe" []
"PopUpStopperFreeEdition"="C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" [2008-03-14 02:22 536576]
"Aim6"="" []
"cdloader"="C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" [2007-12-21 09:39 50520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [ ]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [ ]
"KBD"="C:\HP\KBD\KBD.EXE" [ ]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [ ]
"PS2"="C:\WINDOWS\system32\ps2.exe" [ ]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [ ]
"TorontoMail"="sysconf16.exe" []
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe" [2008-03-14 02:22 188416]
"HostManager"="C:\Program Files\Common Files\AOL\1161439287\ee\AOLSoftware.exe" [ ]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [ ]
"ppmate"="C:\Program Files\PPMate\PPMate\ppmate.exe" [ ]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2008-03-14 02:22 576320]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2008-03-14 02:22 600896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-14 02:22 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-14 02:22 270648]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" [ ]
"S3TRAY2"="S3tray2.exe" [2008-03-14 02:54 69632 C:\WINDOWS\system32\s3tray2.exe]
"SPAMfighter Agent"="C:\Program Files\SPAMfighter\SFAgent.exe" [2008-03-14 02:22 308880]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2008-03-14 02:22 49152]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-14 02:22 185896]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
Bat - Auto Update.lnk - C:\Program Files\Bat\Bat.exe [2008-03-08 13:10:56 178419]
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe [2003-04-10 05:53:45 552960]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2003-04-10 06:08:26 16384]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-02 20:56:10 40960]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifdbby]
iifdbby.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wineil32]
wineil32.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-16 14:23:48
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\SPAMfighter\sfus.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\UTSCSI.EXE
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Bat\X_Bat.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Owner\Application Data\mjusbsp\magicJack.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
.
**************************************************************************
.
Completion time: 2008-03-16 14:41:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-16 19:41:41
.
2008-03-15 08:01:48 — E O F —

Here is my new Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:59:29 PM, on 3/16/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S3tray2.exe
C:\Program Files\SPAMfighter\sfus.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UTSCSI.EXE
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\Program Files\Bat\X_Bat.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Owner\Application Data\mjusbsp\magicJack.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\internet explorer\iexplore.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\Documents and Settings\Owner\Desktop\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [TorontoMail] sysconf16.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1161439287\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [ppmate] C:\Program Files\PPMate\PPMate\ppmate.exe -autoplay
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [sound64] barint.exe
O4 - HKCU\..\Run: [media64] TForm1.exe
O4 - HKCU\..\Run: [MsNetHelper] init32.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [sound64] barint.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [media64] TForm1.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [MsNetHelper] init32.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [Aim6] (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [cdloader] "C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK (User '?')
O4 - S-1-5-21-1429147517-2468864202-290325556-1003 Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe (User '?')
O4 - S-1-5-21-1429147517-2468864202-290325556-1003 Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe (User '?')
O4 - Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Owner\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Owner\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00000005-0000-0000-0000-100009000004} - http://code.trasferimento.biz/l/2acc042149…1f7c301f_35.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - http://aolsvc.aol.com/onlinegames/sonybewitched/main.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/…ash/swflash.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: iifdbby - iifdbby.dll (file missing)
O20 - Winlogon Notify: wineil32 - wineil32.dll (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe (file missing)
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\System32\UTSCSI.EXE

–
End of file - 10831 bytes
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\G5WZ854Z\ComboFix[1].exe

NOTE: Combofix has to be on your desktop before it will work.
Please move it there before doing the fix.



Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\syswkpe.exe
C:\WINDOWS\3BEmKIov4W.exe
C:\WINDOWS\elmtirat.exe
C:\WINDOWS\msa64chk.dll
C:\WINDOWS\system32\MSNSA32.dll
C:\WINDOWS\msapasrc.dll
C:\WINDOWS\system32\ijkmp.ini
C:\WINDOWS\system32\L154.tmp
C:\WINDOWS\system32\LE456.tmp
C:\WINDOWS\TinyBHO.dll
C:\WINDOWS\ss245sd.exe
C:\Program Files\Bat\X_Bat.exe

Folder::
C:\Program Files\180search assistant
C:\Program Files\Viewpoint
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\Program Files\Bat

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifdbby]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wineil32]

Save this as Save this as "CFScript"


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
LD , i put combofix in Desktop and copied the information in the qoutebox to natepad , however when i try to drag it into combofix.exe i get a message saying "were you trying to run cfscript, the name cfscript appears to be spelt incorrectly". LD sorry for my being so inexperienced.
LD I have trojan\winbo32\enhance,my computer seems slow, and also everytime I shut my computer off I have to put my password in various sites that I have "SAVED MY PASSWORD" in , I should not have to load my password each time I go into a site.

Here is my Combofix Log which I ran from the Desktop:

ComboFix 08-03-14.4 - Owner 2008-03-16 16:42:34.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2008-02-16 to 2008-03-16 )))))))))))))))))))))))))))))))
.

2008-03-14 22:33 . 2008-03-14 22:33 23,392 –a—— C:\WINDOWS\system32\nscompat.tlb
2008-03-14 22:33 . 2008-03-14 22:33 16,832 –a—— C:\WINDOWS\system32\amcompat.tlb
2008-03-14 22:23 . 2008-03-14 22:23 d——– C:\Program Files\Common Files\Knowledge Adventure
2008-03-14 22:21 . 2008-03-14 22:21 d——– C:\Documents and Settings\All Users\Application Data\Knowledge Adventure
2008-03-14 02:54 . 2008-03-14 02:54 69,632 –a—— C:\WINDOWS\system32\s3tray2.exe
2008-03-13 17:44 . 2008-03-13 17:44 d——– C:\Program Files\Trend Micro
2008-03-13 00:59 . 2008-03-13 00:59 d——– C:\WINDOWS\ERUNT
2008-03-13 00:46 . 2008-03-16 16:07 d——– C:\SDFix
2008-03-10 21:09 . 2008-03-10 21:09 d——– C:\Program Files\Spybot - Search & Destroy
2008-03-10 21:09 . 2008-03-11 01:05 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-10 20:16 . 2008-03-10 20:16 d——– C:\Program Files\MRU-Blaster
2008-03-10 14:17 . 2008-03-10 14:17 d——– C:\Documents and Settings\Owner\.magicfix
2008-03-10 14:17 . 2008-03-10 14:17 45,056 –a—— C:\WINDOWS\system32\UTSCSI.EXE
2008-03-10 02:11 . 2008-03-10 02:11 d——– C:\VundoFix Backups
2008-03-10 01:24 . 2008-03-10 01:24 d——– C:\Program Files\Enigma Software Group
2008-03-08 16:56 . 2008-03-13 01:06 d——– C:\WINDOWS\cswthdtr
2008-03-08 13:40 . 2008-03-11 21:05 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-08 13:26 . 2008-03-08 13:26 d——– C:\Program Files\stc
2008-03-08 13:25 . 2008-03-08 13:25 d——– C:\Program Files\Sysmnt
2008-03-02 02:03 . 2002-12-29 01:14 81,920 –a—— C:\WINDOWS\system32\Startup.cpl
2008-02-29 17:19 . 2008-02-29 17:19 d——– C:\Program Files\Common Files\xing shared
2008-02-25 20:57 . 2008-02-25 20:59 d——– C:\Documents and Settings\Owner\Application Data\U3
2008-02-24 14:02 . 2008-02-24 14:02 287 –a—— C:\Shortcut to PRESARIO ©.lnk
2008-02-20 14:50 . 2002-08-29 02:01 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2008-02-20 14:50 . 2002-08-29 02:01 134,272 –a–c— C:\WINDOWS\system32\dllcache\portcls.sys
2008-02-20 14:50 . 2002-08-29 01:32 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2008-02-20 14:50 . 2002-08-29 01:32 57,856 –a–c— C:\WINDOWS\system32\dllcache\drmk.sys
2008-02-20 14:50 . 2002-08-29 01:32 56,832 –a—— C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-02-20 14:50 . 2002-08-29 01:32 56,832 –a–c— C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-02-20 14:48 . 2008-03-16 16:31 d——– C:\Documents and Settings\Owner\Application Data\mjusbsp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-16 21:32 ——— d—–w C:\Program Files\SPAMfighter
2008-03-15 06:00 ——— d—–w C:\Program Files\SUPERAntiSpyware
2008-03-14 21:27 ——— d—–w C:\Program Files\AIM
2008-03-14 21:27 ——— d—–w C:\Documents and Settings\Owner\Application Data\Aim
2008-03-14 18:40 ——— d—–w C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-03-14 07:34 ——— d—–w C:\Program Files\QuickTime
2008-03-14 07:34 ——— d—–w C:\Program Files\Microsoft IntelliType Pro
2008-03-14 07:34 ——— d—–w C:\Program Files\Microsoft IntelliPoint
2008-03-14 07:34 ——— d—–w C:\Program Files\iTunes
2008-03-11 01:07 ——— d—–w C:\Documents and Settings\Owner\Application Data\ppStream
2008-03-10 00:08 ——— d—–w C:\Program Files\Google
2008-03-09 23:42 4,342 —-a-w C:\WINDOWS\system32\tmp.reg
2008-03-09 04:52 ——— d—–w C:\Program Files\Absolute Poker
2008-03-03 04:58 ——— d—–w C:\Program Files\AIM6
2008-03-02 06:55 ——— d—–w C:\Documents and Settings\Owner\Application Data\Move Networks
2008-02-29 22:18 ——— d—–w C:\Program Files\Common Files\Real
2008-02-29 22:17 499,712 —-a-w C:\WINDOWS\system32\msvcp71.dll
2008-02-29 22:17 348,160 —-a-w C:\WINDOWS\system32\msvcr71.dll
2008-02-29 05:42 ——— d—–w C:\Program Files\AOL Games
2008-02-29 05:41 ——— d—–w C:\Program Files\Common Files\AOL
2008-02-28 03:29 ——— d—–w C:\Program Files\Poker World
2008-02-26 16:40 ——— d—–w C:\Program Files\McAfee
2008-02-16 17:17 ——— d—–w C:\Program Files\AOD
2008-02-14 03:02 ——— d—–w C:\Documents and Settings\Owner\Application Data\Leadertech
2008-02-10 05:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-02-08 22:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-02-06 14:51 171,400 —-a-w C:\WINDOWS\system32\drivers\mfehidk.sys
2008-01-24 06:24 ——— d—–w C:\Program Files\Canon
2008-01-22 23:49 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-22 23:48 ——— d—–w C:\Program Files\Quicken
2008-01-22 23:46 ——— d—–w C:\Program Files\PokerStars
2007-04-12 04:43 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2007-03-17 07:12 374 —-a-w C:\Documents and Settings\Owner\Application Data\internaldb6334.dat
2007-03-17 07:02 18,432 —-a-w C:\Documents and Settings\Owner\Application Data\internaldb41.dat
2007-03-17 06:02 538 —-a-w C:\Documents and Settings\Owner\Application Data\internaldb8467.dat
.
Files Infected - Win32.Agent.zb
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"sound64"="barint.exe" []
"media64"="TForm1.exe" []
"MsNetHelper"="init32.exe" []
"PopUpStopperFreeEdition"="C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" [2008-03-14 02:22 536576]
"Aim6"="" []
"cdloader"="C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" [2007-12-21 09:39 50520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [ ]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [ ]
"KBD"="C:\HP\KBD\KBD.EXE" [ ]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [ ]
"PS2"="C:\WINDOWS\system32\ps2.exe" [ ]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [ ]
"TorontoMail"="sysconf16.exe" []
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe" [2008-03-14 02:22 188416]
"HostManager"="C:\Program Files\Common Files\AOL\1161439287\ee\AOLSoftware.exe" [ ]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [ ]
"ppmate"="C:\Program Files\PPMate\PPMate\ppmate.exe" [ ]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2008-03-14 02:22 576320]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2008-03-14 02:22 600896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-14 02:22 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-14 02:22 270648]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" [ ]
"S3TRAY2"="S3tray2.exe" [2008-03-14 02:54 69632 C:\WINDOWS\system32\s3tray2.exe]
"SPAMfighter Agent"="C:\Program Files\SPAMfighter\SFAgent.exe" [2008-03-14 02:22 308880]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2008-03-14 02:22 49152]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-14 02:22 185896]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2003-04-10 06:08:26 16384]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-02 20:56:10 40960]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-16 16:54:11
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-16 17:02:50
ComboFix-quarantined-files.txt 2008-03-16 22:02:44
ComboFix2.txt 2008-03-16 21:23:44
ComboFix3.txt 2008-03-16 19:41:52
.
2008-03-15 08:01:48 — E O F —


Here is my Hijackthis log which I reran:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:13:15 PM, on 3/16/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\System32\S3tray2.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SPAMfighter\sfus.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UTSCSI.EXE
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Owner\Application Data\mjusbsp\magicJack.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\Documents and Settings\Owner\Desktop\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [TorontoMail] sysconf16.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1161439287\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [ppmate] C:\Program Files\PPMate\PPMate\ppmate.exe -autoplay
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [sound64] barint.exe
O4 - HKCU\..\Run: [media64] TForm1.exe
O4 - HKCU\..\Run: [MsNetHelper] init32.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [sound64] barint.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [media64] TForm1.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [MsNetHelper] init32.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [Aim6] (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [cdloader] "C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK (User '?')
O4 - S-1-5-21-1429147517-2468864202-290325556-1003 Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe (User '?')
O4 - S-1-5-21-1429147517-2468864202-290325556-1003 Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe (User '?')
O4 - Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Owner\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Owner\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00000005-0000-0000-0000-100009000004} - http://code.trasferimento.biz/l/2acc042149…1f7c301f_35.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - http://aolsvc.aol.com/onlinegames/sonybewitched/main.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/…ash/swflash.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe (file missing)
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\System32\UTSCSI.EXE

–
End of file - 10632 bytes
Lets run an F-Secure online scan it will scan for Viruses, Spyware and RootKits:
  • Click HERE
  • Scroll to the bottom of the page and click the Start scanning button. A window will pop up.
  • Allow the Active X control to be installed on your computer, then click the Accept button
  • Click Full System Scan and allow the components to download and the scan to complete.
  • If malware is found, check Submit samples to F-Secure then select Automatic cleaning
  • When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post
If Automatic cleaning with Submit samples hangs, click Cancel, then New Scan
  • When the cleaning option is presented, Uncheck Submit samples to F-Secure
  • Click Automatic cleaning
  • When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post

Note: This scan will only work with Internet Explorer.
You must be logged on a administrator rights to run this scan.
The scan may take a few hours.

Also let me know how the computer is running now.
Scanning Report Sunday, March 16, 2008 21:37:48 - 00:08:44 Computer name: YOUR-SZ6X6SEFXO Scanning type: Scan system for malware, rootkits Target: C:\ D:\ ——————————————————————————– Result: 18 malware found RiskTool.Win32.Reboot (spyware) System Tracking Cookie (spyware) System Trojan.Win32.Puper.bx (virus) C:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\01CB0AC1.EXE (Renamed & Submitted) C:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\06703DA5.EXE (Renamed & Submitted) C:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\0B157089.EXE (Renamed & Submitted) C:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\0FB9236D.EXE (Renamed & Submitted) C:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\1461004D.EXE (Renamed & Submitted) C:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\193728FB.EXE (Renamed & Submitted) C:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\1DDF05DB.EXE (Renamed & Submitted) C:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\6AA1343F.EXE (Renamed & Submitted) C:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\6F393F31.EXE (Renamed & Submitted) C:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\73DD7215.EXE (Renamed & Submitted) C:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\78854EF5.EXE (Renamed & Submitted) C:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\7C1528C0.EXE (Renamed & Submitted) C:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\7D2757DD.EXE (Renamed & Submitted) W32/Agent.AMZU (virus) C:\PROGRAM FILES\WILDTANGENT\WEBDRIVERFULLINSTALL.EXE (Submitted) W32/Smalltroj.CRCL (virus) C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZTSB07.EXE (Submitted) W32/Smalltroj.CRLY (virus) C:\PROGRAM FILES\MICROSOFT INTELLIPOINT\IPOINT.EXE (Submitted) ——————————————————————————– Statistics Scanned: Files: 45770 System: 4021 Not scanned: 14 Actions: Disinfected: 0 Renamed: 13 Deleted: 0 None: 5 Submitted: 16 Files not scanned: C:\HIBERFIL.SYS C:\PAGEFILE.SYS C:\WINDOWS\TEMP\MCAFEE_7XCHOMGPMTGO3AC C:\WINDOWS\TEMP\MCMSC_3TQBBPJEBMSBRZY C:\WINDOWS\TEMP\MCMSC_9CMNAGINVB8XKWA C:\WINDOWS\TEMP\MCMSC_FPSV5EGGRLRCQE6 C:\WINDOWS\TEMP\MCMSC_PKWYG44DI8RTF8F C:\WINDOWS\TEMP\MCMSC_UD3C1VESHYINHAO C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT C:\WINDOWS\SYSTEM32\CONFIG\SAM C:\WINDOWS\SYSTEM32\CONFIG\SECURITY C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM C:\WINDOWS\SOFTWAREDISTRIBUTION\EVENTCACHE\{065065D3-740A-426E-8D02-7CBDADEE9201}.BIN ——————————————————————————– Options Scanning engines: F-Secure USS: 2.30.0 F-Secure Hydra: 2.6.7470, 2008-03-16 F-Secure AVP: 7.0.171, 2008-03-16 F-Secure Pegasus: 1.20.0, 2008-02-07 F-Secure Blacklight: 1.0.64 Scanning options: Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JPG LSP MAP MHT MIF PHP POT SWF WMF NWS TAR Use Advanced heuristics ——————————————————————————– Copyright © 1998-2007 Product support |Send virus sample to F-Secure F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.
Open NORTON's anti-virus and remove all the files in QUARANTINE.


Delete these files if still listed:
C:\PROGRAM FILES\WILDTANGENT\WEBDRIVERFULLINSTALL.EXE
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZTSB07.EXE
C:\PROGRAM FILES\MICROSOFT INTELLIPOINT\IPOINT.EXE

Empty Recycle Bin
Reboot

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Hi LD , I was not able to delete C:\PROGRAM FILES\MICROSOFT INTELLIPOINT\IPOINT.EXE , the message was"cannot deleteIpoint:access denied"

Here is my new Combofix log:

ComboFix 08-03-14.4 - Owner 2008-03-17 16:26:24.4 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2008-02-17 to 2008-03-17 )))))))))))))))))))))))))))))))
.

2008-03-16 17:25 . 2008-03-16 17:25 d——– C:\fsaua.data
2008-03-14 22:33 . 2008-03-14 22:33 23,392 –a—— C:\WINDOWS\system32\nscompat.tlb
2008-03-14 22:33 . 2008-03-14 22:33 16,832 –a—— C:\WINDOWS\system32\amcompat.tlb
2008-03-14 22:23 . 2008-03-14 22:23 d——– C:\Program Files\Common Files\Knowledge Adventure
2008-03-14 22:21 . 2008-03-14 22:21 d——– C:\Documents and Settings\All Users\Application Data\Knowledge Adventure
2008-03-14 02:54 . 2008-03-14 02:54 69,632 –a—— C:\WINDOWS\system32\s3tray2.exe
2008-03-13 17:44 . 2008-03-13 17:44 d——– C:\Program Files\Trend Micro
2008-03-13 00:59 . 2008-03-13 00:59 d——– C:\WINDOWS\ERUNT
2008-03-13 00:46 . 2008-03-17 00:13 d——– C:\SDFix
2008-03-10 21:09 . 2008-03-10 21:09 d——– C:\Program Files\Spybot - Search & Destroy
2008-03-10 21:09 . 2008-03-11 01:05 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-10 20:16 . 2008-03-10 20:16 d——– C:\Program Files\MRU-Blaster
2008-03-10 14:17 . 2008-03-10 14:17 d——– C:\Documents and Settings\Owner\.magicfix
2008-03-10 14:17 . 2008-03-10 14:17 45,056 –a—— C:\WINDOWS\system32\UTSCSI.EXE
2008-03-10 02:11 . 2008-03-10 02:11 d——– C:\VundoFix Backups
2008-03-10 01:24 . 2008-03-10 01:24 d——– C:\Program Files\Enigma Software Group
2008-03-08 16:56 . 2008-03-13 01:06 d——– C:\WINDOWS\cswthdtr
2008-03-08 13:40 . 2008-03-11 21:05 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-08 13:26 . 2008-03-08 13:26 d——– C:\Program Files\stc
2008-03-08 13:25 . 2008-03-08 13:25 d——– C:\Program Files\Sysmnt
2008-03-02 02:03 . 2002-12-29 01:14 81,920 –a—— C:\WINDOWS\system32\Startup.cpl
2008-02-29 17:19 . 2008-02-29 17:19 d——– C:\Program Files\Common Files\xing shared
2008-02-25 20:57 . 2008-02-25 20:59 d——– C:\Documents and Settings\Owner\Application Data\U3
2008-02-24 14:02 . 2008-02-24 14:02 287 –a—— C:\Shortcut to PRESARIO ©.lnk
2008-02-20 14:50 . 2002-08-29 02:01 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2008-02-20 14:50 . 2002-08-29 02:01 134,272 –a–c— C:\WINDOWS\system32\dllcache\portcls.sys
2008-02-20 14:50 . 2002-08-29 01:32 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2008-02-20 14:50 . 2002-08-29 01:32 57,856 –a–c— C:\WINDOWS\system32\dllcache\drmk.sys
2008-02-20 14:50 . 2002-08-29 01:32 56,832 –a—— C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-02-20 14:50 . 2002-08-29 01:32 56,832 –a–c— C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-02-20 14:48 . 2008-03-17 16:20 d——– C:\Documents and Settings\Owner\Application Data\mjusbsp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-17 21:21 ——— d—–w C:\Program Files\SPAMfighter
2008-03-17 21:06 ——— d—–w C:\Program Files\WildTangent
2008-03-17 07:44 ——— d—–w C:\Program Files\SUPERAntiSpyware
2008-03-17 05:08 ——— d—–w C:\Program Files\Microsoft IntelliPoint
2008-03-14 21:27 ——— d—–w C:\Program Files\AIM
2008-03-14 21:27 ——— d—–w C:\Documents and Settings\Owner\Application Data\Aim
2008-03-14 18:40 ——— d—–w C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-03-14 07:34 ——— d—–w C:\Program Files\QuickTime
2008-03-14 07:34 ——— d—–w C:\Program Files\Microsoft IntelliType Pro
2008-03-14 07:34 ——— d—–w C:\Program Files\iTunes
2008-03-11 01:07 ——— d—–w C:\Documents and Settings\Owner\Application Data\ppStream
2008-03-10 00:08 ——— d—–w C:\Program Files\Google
2008-03-09 23:42 4,342 —-a-w C:\WINDOWS\system32\tmp.reg
2008-03-09 04:52 ——— d—–w C:\Program Files\Absolute Poker
2008-03-03 04:58 ——— d—–w C:\Program Files\AIM6
2008-03-02 06:55 ——— d—–w C:\Documents and Settings\Owner\Application Data\Move Networks
2008-02-29 22:18 ——— d—–w C:\Program Files\Common Files\Real
2008-02-29 22:17 499,712 —-a-w C:\WINDOWS\system32\msvcp71.dll
2008-02-29 22:17 348,160 —-a-w C:\WINDOWS\system32\msvcr71.dll
2008-02-29 05:42 ——— d—–w C:\Program Files\AOL Games
2008-02-29 05:41 ——— d—–w C:\Program Files\Common Files\AOL
2008-02-28 03:29 ——— d—–w C:\Program Files\Poker World
2008-02-26 16:40 ——— d—–w C:\Program Files\McAfee
2008-02-16 17:17 ——— d—–w C:\Program Files\AOD
2008-02-14 03:02 ——— d—–w C:\Documents and Settings\Owner\Application Data\Leadertech
2008-02-10 05:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-02-08 22:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-02-06 14:51 171,400 —-a-w C:\WINDOWS\system32\drivers\mfehidk.sys
2008-01-24 06:24 ——— d—–w C:\Program Files\Canon
2008-01-22 23:49 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-22 23:48 ——— d—–w C:\Program Files\Quicken
2008-01-22 23:46 ——— d—–w C:\Program Files\PokerStars
2007-04-12 04:43 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2007-03-17 07:12 374 —-a-w C:\Documents and Settings\Owner\Application Data\internaldb6334.dat
2007-03-17 07:02 18,432 —-a-w C:\Documents and Settings\Owner\Application Data\internaldb41.dat
2007-03-17 06:02 538 —-a-w C:\Documents and Settings\Owner\Application Data\internaldb8467.dat
.
Files Infected - Win32.Agent.zb
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
.

((((((((((((((((((((((((((((( snapshot@2008-03-16_14.41.05.96 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-02-27 20:59:28 290,816 —-a-w C:\WINDOWS\Downloaded Program Files\auc_lib.dll
+ 2008-02-27 20:59:28 495,616 —-a-w C:\WINDOWS\Downloaded Program Files\daas_s.dll
+ 2008-02-27 21:00:12 262,144 —-a-w C:\WINDOWS\Downloaded Program Files\fscax.dll
+ 2008-02-27 20:59:16 588,392 —-a-w C:\WINDOWS\Downloaded Program Files\gatelauncher.exe
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"sound64"="barint.exe" []
"media64"="TForm1.exe" []
"MsNetHelper"="init32.exe" []
"PopUpStopperFreeEdition"="C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" [2008-03-14 02:22 536576]
"Aim6"="" []
"cdloader"="C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" [2007-12-21 09:39 50520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [ ]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [ ]
"KBD"="C:\HP\KBD\KBD.EXE" [ ]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [ ]
"PS2"="C:\WINDOWS\system32\ps2.exe" [ ]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [ ]
"TorontoMail"="sysconf16.exe" []
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe" [ ]
"HostManager"="C:\Program Files\Common Files\AOL\1161439287\ee\AOLSoftware.exe" [ ]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [ ]
"ppmate"="C:\Program Files\PPMate\PPMate\ppmate.exe" [ ]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2008-03-14 02:22 576320]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2008-03-14 02:22 600896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-14 02:22 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-14 02:22 270648]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" [ ]
"S3TRAY2"="S3tray2.exe" [2008-03-14 02:54 69632 C:\WINDOWS\system32\s3tray2.exe]
"SPAMfighter Agent"="C:\Program Files\SPAMfighter\SFAgent.exe" [2008-03-14 02:22 308880]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2008-03-14 02:22 49152]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-14 02:22 185896]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2003-04-10 06:08:26 16384]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-02 20:56:10 40960]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-17 16:36:11
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-17 16:42:48
ComboFix-quarantined-files.txt 2008-03-17 21:42:43
ComboFix2.txt 2008-03-16 22:02:51
ComboFix3.txt 2008-03-16 21:23:44
ComboFix4.txt 2008-03-16 19:41:52
.
2008-03-15 08:01:48 — E O F —

Here is my new HiJackthis Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:49:03 PM, on 3/17/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
C:\WINDOWS\System32\S3tray2.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SPAMfighter\sfus.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UTSCSI.EXE
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Owner\Application Data\mjusbsp\magicJack.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [TorontoMail] sysconf16.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1161439287\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [ppmate] C:\Program Files\PPMate\PPMate\ppmate.exe -autoplay
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [sound64] barint.exe
O4 - HKCU\..\Run: [media64] TForm1.exe
O4 - HKCU\..\Run: [MsNetHelper] init32.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [sound64] barint.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [media64] TForm1.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [MsNetHelper] init32.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [Aim6] (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [cdloader] "C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK (User '?')
O4 - S-1-5-21-1429147517-2468864202-290325556-1003 Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe (User '?')
O4 - S-1-5-21-1429147517-2468864202-290325556-1003 Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe (User '?')
O4 - Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Owner\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Owner\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00000005-0000-0000-0000-100009000004} - http://code.trasferimento.biz/l/2acc042149…1f7c301f_35.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - http://aolsvc.aol.com/onlinegames/sonybewitched/main.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/…ash/swflash.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe (file missing)
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\System32\UTSCSI.EXE

–
End of file - 10708 bytes
If I'm seeing this correctly, it's showing the below files are infected.
You'll need to reinstall these programs.

Microsoft IntelliType
QuickTime
iTunes
SPAMfighter
PANICW~1

Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe

Folder::
C:\Program Files\WildTangent

Save this as Save this as "CFScript"


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Here is the new Combofix Log:


ComboFix 08-03-14.4 - Owner 2008-03-17 17:15:43.5 - NTFSx86

Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\SDFix\CFScript.txt

FILE ::
C:\PROGRA~1\PANICW~1\POP-UP~1\psfree.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\hpwuschd2.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iTunes\ituneshelper.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\Program Files\SPAMfighter\sfagent.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\PROGRA~1\PANICW~1\POP-UP~1\psfree.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\ituneshelper.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SPAMfighter\sfagent.exe
C:\Program Files\WildTangent
C:\Program Files\WildTangent\Apps\GameChannel\Games\27565B66-EC6D-48A9-A1C3-8886A849995F\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Games\2B4B4104-7AC7-4950-8BF2-6BB5E3E61CA7\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Games\31403AA7-7357-43E1-9B46-4B45847C37D5\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Games\33A16A26-1533-4016-AE2D-89D6398D7EB2\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Games\350CC34B-2B8E-4EE5-AE4D-F04FDF37DC39\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Games\67D9A48A-81E9-4863-8B55-744BAEA180E2\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Games\80E21EE8-007B-4C28-ADB2-5110B4401E2E\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Games\865917D2-33F4-4223-BDCD-C7DA958C216C\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Games\9A8CE71F-71D5-4555-B355-85481DC99B80\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Games\AD0E57E8-ABB1-4BF6-9AFF-0C7DDA1710CD\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Games\c058d3ba-df2a-493d-9a60-9f725cc6502c\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Games\EEDAA297-DFDF-436A-B977-D95EA63C907D\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\{4bdc3f86-5f2f-4527-89e8-dbaaeb417821}\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\{4bdc3f86-5f2f-4527-89e8-dbaaeb417821}\images\dl_off.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\{4bdc3f86-5f2f-4527-89e8-dbaaeb417821}\images\dl_on.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\{4bdc3f86-5f2f-4527-89e8-dbaaeb417821}\images\main_hp.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\{4bdc3f86-5f2f-4527-89e8-dbaaeb417821}\images\main_wg.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\{4bdc3f86-5f2f-4527-89e8-dbaaeb417821}\images\spacer.gif
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\{4bdc3f86-5f2f-4527-89e8-dbaaeb417821}\index.html
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\{5f1ce890-6d3e-4056-85ee-350f66e2c81d}\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\{9BAC992E-77E6-4ad3-8C8A-2C2EB76C6702}\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\{f388931a-fa43-4a56-baa1-8a6cd1d17a77}\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\{f388931a-fa43-4a56-baa1-8a6cd1d17a77}\images\background.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\{f388931a-fa43-4a56-baa1-8a6cd1d17a77}\index.html
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\def.dat
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\gamelinks.exe
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\games.html
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\htmlapp.htm
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\htp.ico
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\icon.ico
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_01.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_02.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_03.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_04.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_05.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_06.gif
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_07.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_08.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_09.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_10.gif
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_11.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_12.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_13.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_14.gif
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_15.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_16.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_17.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_18.gif
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_19.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_20.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_21.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_22.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_23.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_24.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_25.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_26.gif
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_27.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_28.gif
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_29.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_30.gif
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_31.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_32.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_33.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_34.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_35.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_36.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_over_08.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_over_12.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_over_16.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_over_25.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_over_27.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\games_over_29.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\images\Thumbs.db
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\rungame.exe
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\tutorial.html
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\welcome_06.jpg
C:\Program Files\WildTangent\Apps\GameChannel\Notifications\hpwelcome\wtproducts.js
C:\Program Files\WildTangent\Apps\wtKernel0100.dll
C:\Program Files\WildTangent\Components\SystemConfig0100.dll
C:\Program Files\WildTangent\LFS\Download\cache.dat
C:\Program Files\WildTangent\LFS\System\LFSRegistry\Cache.lfs
C:\Program Files\WildTangent\LFS\System\LFSRegistry\Download.lfs
C:\Program Files\WildTangent\LFS\System\LFSRegistry\Games.lfs
C:\Program Files\WildTangent\LFS\System\LFSRegistry\Legacy.lfs
C:\Program Files\WildTangent\LFS\System\LFSRegistry\Notifications.lfs
C:\Program Files\WildTangent\LFS\System\LFSRegistry\System.lfs
C:\Program Files\WildTangent\LFS\System\LFSRegistry\Temp.lfs
C:\Program Files\WildTangent\LFS\System\wt.sto

.
((((((((((((((((((((((((( Files Created from 2008-02-17 to 2008-03-17 )))))))))))))))))))))))))))))))
.

2008-03-16 17:25 . 2008-03-16 17:25 d——– C:\fsaua.data
2008-03-14 22:33 . 2008-03-14 22:33 23,392 –a—— C:\WINDOWS\system32\nscompat.tlb
2008-03-14 22:33 . 2008-03-14 22:33 16,832 –a—— C:\WINDOWS\system32\amcompat.tlb
2008-03-14 22:23 . 2008-03-14 22:23 d——– C:\Program Files\Common Files\Knowledge Adventure
2008-03-14 22:21 . 2008-03-14 22:21 d——– C:\Documents and Settings\All Users\Application Data\Knowledge Adventure
2008-03-14 02:54 . 2008-03-14 02:54 69,632 –a—— C:\WINDOWS\system32\s3tray2.exe
2008-03-13 17:44 . 2008-03-13 17:44 d——– C:\Program Files\Trend Micro
2008-03-13 00:59 . 2008-03-13 00:59 d——– C:\WINDOWS\ERUNT
2008-03-13 00:46 . 2008-03-17 17:15 d——– C:\SDFix
2008-03-10 21:09 . 2008-03-10 21:09 d——– C:\Program Files\Spybot - Search & Destroy
2008-03-10 21:09 . 2008-03-11 01:05 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-10 20:16 . 2008-03-10 20:16 d——– C:\Program Files\MRU-Blaster
2008-03-10 14:17 . 2008-03-10 14:17 d——– C:\Documents and Settings\Owner\.magicfix
2008-03-10 14:17 . 2008-03-10 14:17 45,056 –a—— C:\WINDOWS\system32\UTSCSI.EXE
2008-03-10 02:11 . 2008-03-10 02:11 d——– C:\VundoFix Backups
2008-03-10 01:24 . 2008-03-10 01:24 d——– C:\Program Files\Enigma Software Group
2008-03-08 16:56 . 2008-03-13 01:06 d——– C:\WINDOWS\cswthdtr
2008-03-08 13:40 . 2008-03-11 21:05 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-08 13:26 . 2008-03-08 13:26 d——– C:\Program Files\stc
2008-03-08 13:25 . 2008-03-08 13:25 d——– C:\Program Files\Sysmnt
2008-03-02 02:03 . 2002-12-29 01:14 81,920 –a—— C:\WINDOWS\system32\Startup.cpl
2008-02-29 17:19 . 2008-02-29 17:19 d——– C:\Program Files\Common Files\xing shared
2008-02-25 20:57 . 2008-02-25 20:59 d——– C:\Documents and Settings\Owner\Application Data\U3
2008-02-24 14:02 . 2008-02-24 14:02 287 –a—— C:\Shortcut to PRESARIO ©.lnk
2008-02-20 14:50 . 2002-08-29 02:01 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2008-02-20 14:50 . 2002-08-29 02:01 134,272 –a–c— C:\WINDOWS\system32\dllcache\portcls.sys
2008-02-20 14:50 . 2002-08-29 01:32 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2008-02-20 14:50 . 2002-08-29 01:32 57,856 –a–c— C:\WINDOWS\system32\dllcache\drmk.sys
2008-02-20 14:50 . 2002-08-29 01:32 56,832 –a—— C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-02-20 14:50 . 2002-08-29 01:32 56,832 –a–c— C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-02-20 14:48 . 2008-03-17 16:20 d——– C:\Documents and Settings\Owner\Application Data\mjusbsp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-17 22:17 ——— d—–w C:\Program Files\SPAMfighter
2008-03-17 22:17 ——— d—–w C:\Program Files\QuickTime
2008-03-17 22:17 ——— d—–w C:\Program Files\Microsoft IntelliType Pro
2008-03-17 22:17 ——— d—–w C:\Program Files\Microsoft IntelliPoint
2008-03-17 22:17 ——— d—–w C:\Program Files\iTunes
2008-03-17 07:44 ——— d—–w C:\Program Files\SUPERAntiSpyware
2008-03-14 21:27 ——— d—–w C:\Program Files\AIM
2008-03-14 21:27 ——— d—–w C:\Documents and Settings\Owner\Application Data\Aim
2008-03-14 18:40 ——— d—–w C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-03-11 01:07 ——— d—–w C:\Documents and Settings\Owner\Application Data\ppStream
2008-03-10 00:08 ——— d—–w C:\Program Files\Google
2008-03-09 23:42 4,342 —-a-w C:\WINDOWS\system32\tmp.reg
2008-03-09 04:52 ——— d—–w C:\Program Files\Absolute Poker
2008-03-03 04:58 ——— d—–w C:\Program Files\AIM6
2008-03-02 06:55 ——— d—–w C:\Documents and Settings\Owner\Application Data\Move Networks
2008-02-29 22:18 ——— d—–w C:\Program Files\Common Files\Real
2008-02-29 22:17 499,712 —-a-w C:\WINDOWS\system32\msvcp71.dll
2008-02-29 22:17 348,160 —-a-w C:\WINDOWS\system32\msvcr71.dll
2008-02-29 05:42 ——— d—–w C:\Program Files\AOL Games
2008-02-29 05:41 ——— d—–w C:\Program Files\Common Files\AOL
2008-02-28 03:29 ——— d—–w C:\Program Files\Poker World
2008-02-26 16:40 ——— d—–w C:\Program Files\McAfee
2008-02-16 17:17 ——— d—–w C:\Program Files\AOD
2008-02-14 03:02 ——— d—–w C:\Documents and Settings\Owner\Application Data\Leadertech
2008-02-10 05:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-02-08 22:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-02-06 14:51 171,400 —-a-w C:\WINDOWS\system32\drivers\mfehidk.sys
2008-01-24 06:24 ——— d—–w C:\Program Files\Canon
2008-01-22 23:49 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-22 23:48 ——— d—–w C:\Program Files\Quicken
2008-01-22 23:46 ——— d—–w C:\Program Files\PokerStars
2007-04-12 04:43 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2007-03-17 07:12 374 —-a-w C:\Documents and Settings\Owner\Application Data\internaldb6334.dat
2007-03-17 07:02 18,432 —-a-w C:\Documents and Settings\Owner\Application Data\internaldb41.dat
2007-03-17 06:02 538 —-a-w C:\Documents and Settings\Owner\Application Data\internaldb8467.dat
.

((((((((((((((((((((((((((((( snapshot@2008-03-16_14.41.05.96 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-02-27 20:59:28 290,816 —-a-w C:\WINDOWS\Downloaded Program Files\auc_lib.dll
+ 2008-02-27 20:59:28 495,616 —-a-w C:\WINDOWS\Downloaded Program Files\daas_s.dll
+ 2008-02-27 21:00:12 262,144 —-a-w C:\WINDOWS\Downloaded Program Files\fscax.dll
+ 2008-02-27 20:59:16 588,392 —-a-w C:\WINDOWS\Downloaded Program Files\gatelauncher.exe
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"sound64"="barint.exe" []
"media64"="TForm1.exe" []
"MsNetHelper"="init32.exe" []
"PopUpStopperFreeEdition"="C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" [ ]
"Aim6"="" []
"cdloader"="C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" [2007-12-21 09:39 50520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [ ]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [ ]
"KBD"="C:\HP\KBD\KBD.EXE" [ ]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [ ]
"PS2"="C:\WINDOWS\system32\ps2.exe" [ ]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [ ]
"TorontoMail"="sysconf16.exe" []
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe" [ ]
"HostManager"="C:\Program Files\Common Files\AOL\1161439287\ee\AOLSoftware.exe" [ ]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [ ]
"ppmate"="C:\Program Files\PPMate\PPMate\ppmate.exe" [ ]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [ ]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" [ ]
"S3TRAY2"="S3tray2.exe" [2008-03-14 02:54 69632 C:\WINDOWS\system32\s3tray2.exe]
"SPAMfighter Agent"="C:\Program Files\SPAMfighter\SFAgent.exe" [ ]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2003-04-10 06:08:26 16384]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-02 20:56:10 40960]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-17 17:22:11
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-17 17:27:10
ComboFix-quarantined-files.txt 2008-03-17 22:27:00
ComboFix2.txt 2008-03-17 21:42:49
ComboFix3.txt 2008-03-16 22:02:51
ComboFix4.txt 2008-03-16 21:23:44
ComboFix5.txt 2008-03-16 19:41:52
.
2008-03-15 08:01:48 — E O F —


Here is the current Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:57:45 PM, on 3/17/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\S3tray2.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SPAMfighter\sfus.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\System32\UTSCSI.EXE
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Owner\Application Data\mjusbsp\magicJack.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [TorontoMail] sysconf16.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1161439287\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [ppmate] C:\Program Files\PPMate\PPMate\ppmate.exe -autoplay
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [sound64] barint.exe
O4 - HKCU\..\Run: [media64] TForm1.exe
O4 - HKCU\..\Run: [MsNetHelper] init32.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [sound64] barint.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [media64] TForm1.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [MsNetHelper] init32.exe (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [Aim6] (User '?')
O4 - HKUS\S-1-5-21-1429147517-2468864202-290325556-1003\..\Run: [cdloader] "C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK (User '?')
O4 - S-1-5-21-1429147517-2468864202-290325556-1003 Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe (User '?')
O4 - S-1-5-21-1429147517-2468864202-290325556-1003 Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe (User '?')
O4 - Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Owner\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Owner\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00000005-0000-0000-0000-100009000004} - http://code.trasferimento.biz/l/2acc042149…1f7c301f_35.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - http://aolsvc.aol.com/onlinegames/sonybewitched/main.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/…ash/swflash.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe (file missing)
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\System32\UTSCSI.EXE

–
End of file - 10391 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI