This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] crazy amounts of popups and redirects

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 2:03:11 PM, on 3/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\sv3978\svchost.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Program Files\Tzzdskr\Ncqp.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\NoAds\NoAds.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\PROGRA~1\SLIMSE~1\server\Bin\MSWIN3~1\mysqld.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\FSScrCtl.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=localhost:8081;http=localhost:8081
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F3 - REG:win.ini: load=C:\WINDOWS\sv3978\svchost.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O4 - HKLM\..\Run: [BlockTracker] c:\hp\bin\BlockTracker.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Lwseipw] C:\Program Files\Tzzdskr\Ncqp.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [NoAds] "C:\Program Files\NoAds\NoAds.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpyClean] C:\Program Files\Netcom3 Cleaner\SpyClean.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Screen Saver Control.lnk = C:\WINDOWS\FSScrCtl.exe
O4 - Global Startup: updater.lnk = C:\Program Files\Common Files\updater\wupdater.exe
O8 - Extra context menu item: &Search - ?p=ZUxdm300LDUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/WebsiteA…e/bridge-c9.cab
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by117fd.bay117.hotmail.msn.com/activex/HMAtchmt.ocx
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe
O23 - Service: NetCom3 Service (Netcom3) - Unknown owner - C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SlimServerMySQL - Unknown owner - C:\PROGRA~1\SLIMSE~1\server\Bin\MSWIN3~1\mysqld.exe
O23 - Service: SlimServer (slimsvc) - Unknown owner - C:\Program Files\SlimServer\server\slim.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)

Hope i did this right…………….
Hello shdoweaver and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.


Please provide a list of uninstallable programs.

To Provide a List of Installed Programs
  • Run HijackThis.
  • Click Config>>Miscellaneous Tools>>Open Uninstall Manager>>Save List
  • Save list to Desktop
  • Copy the Notepad list and Paste it into this thread.
Ad-Aware SE Personal Adobe Acrobat 5.0 Adobe Flash Player 9 ActiveX Adobe Flash Player ActiveX Adobe Reader 8.1.2 Adobe® Photoshop® Album Starter Edition 3.2 Charter High-Speed™ Self-Installation Clifford Thinking Adventures CloneDVD Full [removed] CompuServe CoreVorbis Audio Decoder (remove only) Coupon Printer for Windows Creative System Information Detto IntelliMover Demo DTCLookup DVD Decrypter (Remove Only) Google Earth Google Toolbar for Internet Explorer HDView for Internet Explorer Hijackthis 1.99.1 HijackThis 1.99.1 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) HP Imaging Device Functions 7.0 hp instant support HP Memories Disc HP Photo and Imaging 2.0 - Photosmart Cameras HP Photosmart and Deskjet 7.0.A HP Photosmart Essential HP Solution Center 7.0 HP Update Indeo® Software Intel® 82845G Graphics Driver Software J2SE Runtime Environment 5.0 Update 10 J2SE Runtime Environment 5.0 Update 11 J2SE Runtime Environment 5.0 Update 8 J2SE Runtime Environment 5.0 Update 9 Java 2 Runtime Environment Standard Edition v1.3.1_02 Java 2 Runtime Environment, SE v1.4.0_01 Java Web Start Java™ 6 Update 2 Java™ 6 Update 3 Java™ 6 Update 5 LimeWire 4.14.12 Microsoft .NET Framework (English) Microsoft .NET Framework (English) v1.0.3705 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Data Access Components KB870669 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Works 7.0 MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 6.0 Parser (KB933579) Netscape (7.0) NoAds NVIDIA Drivers OCR Software by I.R.I.S 7.0 Paint Shop Pro 7 PartyPokerNet PC-Doctor for Windows PowerQuest Drive Image 5.0 PowerQuest PartitionMagic Pro 7.0 PS2 Python 2.2 combined Win32 extensions Python 2.2.1 QuickTime RealPlayer S3Display S3Gamma2 S3Info2 S3Overlay Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901190) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB946026) Shockwave Simple Installer - Multilanguage Version SlimServer 6.5.4 Softsqueeze 2.0b9 Softsqueeze 3.5 Sound Blaster Live! 24-bit Spybot - Search & Destroy System Requirements Lab Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Ventrilo Client WeatherBug WebSearch Tools Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 WinRAR archiver World of Warcraft Yahoo! Essentials THx for the help…….
A. Using the Add/Remove Program module in your Control Panel, please UNNSTALL the following program:

PartyPokerNet

Justification for the removal can be found here: http://www.bleepingcomputer.com/uninstall/Cat-P.html


B. I do not see the presence of any Antivirus program or software Firewall in your log. Please tell me what products you are using to protect your system.


C. Are you currently running any Symantec products as I notice an entry which appears to be a remnant from a prior installation:

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe



D. First we must disable some of your security programs so that they do not interfere with the running of our tools:

SPYBOT TEATIMER
  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Uncheck the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done.
  • (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]


E. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • ComboFix will automatically start. Any monitoring programs will be shut down like your antivirus, antispyware programs for example.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
here's the new hijackthis log file…..



Logfile of HijackThis v1.99.1
Scan saved at 13:32, on 2008-03-16
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\SLIMSE~1\server\Bin\MSWIN3~1\mysqld.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Program Files\SlimServer\server\slim.exe
C:\Program Files\Tzzdskr\Ncqp.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\NoAds\NoAds.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\FSScrCtl.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=localhost:8081;http=localhost:8081
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O4 - HKLM\..\Run: [BlockTracker] c:\hp\bin\BlockTracker.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Lwseipw] C:\Program Files\Tzzdskr\Ncqp.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [NoAds] "C:\Program Files\NoAds\NoAds.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpyClean] C:\Program Files\Netcom3 Cleaner\SpyClean.exe
O4 - Startup: Screen Saver Control.lnk = C:\WINDOWS\FSScrCtl.exe
O4 - Global Startup: updater.lnk = C:\Program Files\Common Files\updater\wupdater.exe
O8 - Extra context menu item: &Search - ?p=ZUxdm300LDUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/WebsiteA…e/bridge-c9.cab
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by117fd.bay117.hotmail.msn.com/activex/HMAtchmt.ocx
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe
O23 - Service: NetCom3 Service (Netcom3) - Unknown owner - C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SlimServerMySQL - Unknown owner - C:\PROGRA~1\SLIMSE~1\server\Bin\MSWIN3~1\mysqld.exe
O23 - Service: SlimServer (slimsvc) - Unknown owner - C:\Program Files\SlimServer\server\slim.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

and here's the combofix log…….


ComboFix 08-03-14.4 - Owner 2008-03-16 13:19:33.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.650 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\Z5Y3CTBY\www.broadcaster.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\Z5Y3CTBY\www.broadcaster.com\played_list.sol
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\Z5Y3CTBY\www.broadcaster.com\video_queue.sol
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\WINDOWS\system32\a.exe

.
((((((((((((((((((((((((( Files Created from 2008-02-16 to 2008-03-16 )))))))))))))))))))))))))))))))
.

2008-03-14 12:42 . 2008-03-14 12:42 d——– C:\Program Files\Spybot - Search & Destroy
2008-03-14 12:42 . 2008-03-14 13:20 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-14 11:25 . 2008-03-14 12:17 0 –a—— C:\WINDOWS\system32\pqtmp.fil
2008-03-13 21:19 . 2008-03-14 14:02 d——– C:\Program Files\Netcom3 Cleaner
2008-03-13 16:12 . 2008-03-13 16:13 d——– C:\Documents and Settings\Owner\Application Data\Ventrilo
2008-03-13 15:56 . 2008-03-13 15:56 d——– C:\Program Files\Ventrilo
2008-03-13 15:53 . 2008-03-13 15:53 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-24 18:09 . 2008-02-24 18:09 d——– C:\WINDOWS\sv3978

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-16 17:14 ——— d—–w C:\Program Files\NoAds
2008-03-16 17:12 ——— d—–w C:\Program Files\PartyGaming.Net
2008-03-14 20:09 ——— d—–w C:\Documents and Settings\Owner\Application Data\Image Zone Express
2008-03-14 16:28 ——— d—–w C:\Program Files\Java
2008-03-13 03:34 ——— d—–w C:\Documents and Settings\Owner\Application Data\WeatherBug
2008-02-26 03:54 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-08 22:40 ——— d—–w C:\Program Files\Microsoft Research
2008-01-26 07:31 ——— d—–w C:\Program Files\World of Warcraft
2007-09-07 15:24 486,449 -c–a-w C:\Program Files\Fixwareout.exe
2003-02-16 00:28 0 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NoAds"="C:\Program Files\NoAds\NoAds.exe" [2003-06-30 23:50 122880]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2005-06-07 14:58 1339392]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
"SpyClean"="C:\Program Files\Netcom3 Cleaner\SpyClean.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BlockTracker"="c:\hp\bin\BlockTracker.exe" [ ]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 20:04 52736]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2002-09-09 11:05 114688]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 01:42 212992]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-08-01 00:28 81920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2003-07-02 11:48 77824]
"S3TRAY2"="S3tray2.exe" [2003-02-25 04:33 69632 C:\WINDOWS\system32\S3tray2.exe]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-06-20 16:30 69632]
"CamMonitor"="C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 01:23 90112]
"CTSysVol"="C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 11:43 57344]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 02:00 90112]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"Lwseipw"="C:\Program Files\Tzzdskr\Ncqp.exe" [2005-05-17 01:00 37512]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" []
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2005-03-15 05:46 196608]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 19:26 217088]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-02-19 03:41 49152]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"RegistryMechanic"="" []

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
Screen Saver Control.lnk - C:\WINDOWS\FSScrCtl.exe [2005-02-20 10:07:43 249344]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"= 0 (0x0)
"Btn_Search"= 0 (0x0)

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SlimServer Tray Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SlimServer Tray Tool.lnk
backup=C:\WINDOWS\pss\SlimServer Tray Tool.lnkCommon Startup

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9000:TCP"= 9000:TCP:SlimServer 9000 tcp
"3483:UDP"= 3483:UDP:SlimServer 3483 udp
"3483:TCP"= 3483:TCP:SlimServer 3483 tcp
"3724:TCP"= 3724:TCP:WoW
"3724:UDP"= 3724:UDP:WoW

R2 SlimServerMySQL;SlimServerMySQL;C:\PROGRA~1\SLIMSE~1\server\Bin\MSWIN3~1\mysqld.exe [2007-08-15 19:23]
S3 msCMTSrvc;Content Monitoring Tool;C:\WINDOWS\system32\msCMTSrvc.exe [2002-03-27 07:42]
S3 Netcom3;NetCom3 Service;C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe []
S3 PCDRDRV;Pcdr Helper Driver;C:\PROGRA~1\PC-DOC~1\DIAGNO~1\PCDRDRV.sys []

.
Contents of the 'Scheduled Tasks' folder
"2008-03-14 10:27:00 C:\WINDOWS\Tasks\Disk Cleanup.job"
- C:\WINDOWS\system32\cleanmgr.exe
"2008-03-04 14:00:00 C:\WINDOWS\Tasks\rpc.job"
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe
"2008-03-16 04:03:36 C:\WINDOWS\Tasks\User_Feed_Synchronization-{92101280-83C4-41AA-BB16-2DD11AC1374A}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-16 13:23:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\NoAds\NoAds.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\SlimServer\server\slim.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-03-16 13:29:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-16 17:29:06
.
2008-03-12 06:10:29 — E O F —

B. I do not see the presence of any Antivirus program or software Firewall in your log. Please tell me what products you are using to protect your system.


C. Are you currently running any Symantec products as I notice an entry which appears to be a remnant from a prior installation:

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe



Please provide me with the answer to these two questions as requested at the beginning of my last post.

Thanks,

Trevuren
try not to laugh to hard but in my 13 years of owning a pc i haven't ever had the security software you are requesting info on, i will however say that this is my first time having an issue like this, and you do seem to have resolved the issue, i will also be looking into some serious safety software insurance.
I am sorry to be a pest but I must confirm that you do not require this Symantec service to run?

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
i would also like to add that everything you have had me do has helped tremendously, the issues are gone and it seems to be much better, i thank you greatly.
A. Please ensure that TeaTimer remains disabled as per previous instructions:


B. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
    O4 - HKLM\..\Run: [Lwseipw] C:\Program Files\Tzzdskr\Ncqp.exe
    O4 - HKCU\..\Run: [SpyClean] C:\Program Files\Netcom3 Cleaner\SpyClean.exe
    O8 - Extra context menu item: &Search - ?p=ZUxdm300LDUS
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
    O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/WebsiteA…e/bridge-c9.cab
    O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe


  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.


C. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\system32\pqtmp.fil
C:\Program Files\Fixwareout.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\install.cab

Folder::
C:\Program Files\Netcom3 Cleaner
C:\Program Files\PartyGaming.Net
C:\Program Files\Tzzdskr
C:\Program Files\Common Files\Symantec Shared

DirLook::
C:\WINDOWS\sv3978

Driver::
Netcom3
PCDRDRV
SNDSrvc

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BlockTracker"=-
"RegistryMechanic"=-
"Logitech Hardware Abstraction Layer"=-
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


D. Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
dayam, i think my computer hates me…….



ComboFix 08-03-14.4 - Owner 2008-03-18 11:24:35.2 - NTFSx86

Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.text
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\install.cab
C:\Program Files\Fixwareout.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\pqtmp.fil
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Common Files\Symantec Shared
C:\Program Files\Common Files\Symantec Shared\Default.rul
C:\Program Files\Common Files\Symantec Shared\IDS\DefUtDcd.dll
C:\Program Files\Common Files\Symantec Shared\IDS\IDSaux.dll
C:\Program Files\Common Files\Symantec Shared\IDS\IdsInst.exe
C:\Program Files\Common Files\Symantec Shared\IDS\Patch25.dll
C:\Program Files\Common Files\Symantec Shared\IDS\SymIDSLU.dll
C:\Program Files\Common Files\Symantec Shared\Sevinst.exe
C:\Program Files\Common Files\Symantec Shared\SNDInst.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDunin.dll
C:\Program Files\Common Files\Symantec Shared\SPManifests\CIDS.GRD
C:\Program Files\Common Files\Symantec Shared\SPManifests\CIDS.SIG
C:\Program Files\Common Files\Symantec Shared\SPManifests\CIDS.SPM
C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.grd
C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.sig
C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.spm
C:\Program Files\Common Files\Symantec Shared\SPManifests\SYMEVNT.GRD
C:\Program Files\Common Files\Symantec Shared\SPManifests\SYMEVNT.SIG
C:\Program Files\Common Files\Symantec Shared\SPManifests\SYMEVNT.SPM
C:\Program Files\Common Files\Symantec Shared\Validate.dat
C:\Program Files\Fixwareout.exe
C:\Program Files\Netcom3 Cleaner
C:\Program Files\Netcom3 Cleaner\Logs\2008_03_13.log
C:\Program Files\Netcom3 Cleaner\Logs\2008_03_14.log
C:\Program Files\PartyGaming.Net
C:\Program Files\PartyGaming.Net\DID.dll
C:\Program Files\PartyGaming.Net\images\habeas_webseal.gif
C:\Program Files\PartyGaming.Net\images\Thumbs.db
C:\Program Files\PartyGaming.Net\INSTALL.LOG
C:\Program Files\PartyGaming.Net\Language\en_US\lang_pack_en_US.txt
C:\Program Files\PartyGaming.Net\MFC42LU.DLL
C:\Program Files\PartyGaming.Net\MSLUP60.dll
C:\Program Files\PartyGaming.Net\MSLURT.dll
C:\Program Files\PartyGaming.Net\PartyGamingNet.RPT
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\155.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\1593.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\1595.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\1739.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\1741.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\1921.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\1983.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\2551.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\293.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\295.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\363.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\373.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\383.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\4317.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\4333.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\4355.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\4363.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\447.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\449.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\545.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\579.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\581.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\7.html
C:\Program Files\PartyGaming.Net\PartyPokerNet\Articles\9.html
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\468x60_DefaultBanner.gif
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\728x90_DefaultBanner.gif
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\btnQuickRedepositBuyin.gif
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\btnQuickRedepositTable.gif
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\but_joinlist_number.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\but_unjoinlist_number.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\buyin_popup_okbg.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\ChatOffIndicator_Deaf.gif
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\ChatOffIndicator_Mute.gif
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\ChatOffIndicator_MuteDeaf.gif
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\close_EM_button.gif
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\ezleavetable.bmp
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\fold_to_off.JPG
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\fold_to_on.JPG
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\help_background_SB.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\lhn_ani_refresh.gif
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\lhn_bar_prize.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\popup_logo_monster_net.gif
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\popup_logo_monster_net.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\pp_logo_small.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\prize_numbers.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\strip.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\table_waitlist_bg.gif
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\Thumbs.db
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\timer.gif
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\titlebar_chip.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\tree_listing_background_SB.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Images\tree_main_background_SB.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\10253.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\10259.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\10313.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\10315.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\10397.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\10515.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\10517.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\10765.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\10767.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\16993.html
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\17055.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\17057.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\17103.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\17105.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\20925.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\22887.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\22911.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\62753.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\6421.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\6425.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\64749.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\64823.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\66721.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\66743.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\66745.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\66747.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\66905.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\66939.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\67047.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\67246.html
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\67248.html
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\67250.html
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\69221.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\69259.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\69627.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\69629.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\7.html
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\8317.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\8319.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\8445.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\8447.atc
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\articles\9.html
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\images\bulletin_background.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\images\bulletin_box_background.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\images\bulletin_nav_background.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\images\bulletin_nav_buttons.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\images\client_gradient.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\images\express_request_popup.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\images\JP_Other_Popup_BG.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\images\lhn_account_divider.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\images\lhn_but_deposit_large.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\images\lhn_but_options.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\images\lhn_but_refresh.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\images\lhn_but_reload_play.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\images\lhn_link_arrow.gif
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\images\pp_tourney_banner_default.jpg
C:\Program Files\PartyGaming.Net\PartyPokerNet\Language\en_US\lang_pack_en_US.txt
C:\Program Files\PartyGaming.Net\PartyPokerNet\Notes.txt
C:\Program Files\PartyGaming.Net\PartyPokerNet\pf_pocketpikkin_c-o-i.txt
C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\Sys.ini
C:\Program Files\PartyGaming.Net\PartyPokerNet\tmpUpgrade\upgradepf104-105man.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\tmpUpgrade\upgradepf105-106man.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\tmpUpgrade\upgradepf106-107man.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\tmpUpgrade\upgradepf107-108man.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\tmpUpgrade\upgradepf109-110man.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\tmpUpgrade\upgradepf110-111man.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\tmpUpgrade\upgradepf112-113man.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\tmpUpgrade\upgradepf113-114man.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\tmpUpgrade\upgradepf115-116man.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\tmpUpgrade\upgradepf116-117man.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\tmpUpgrade\upgradepf118-119man.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\tmpUpgrade\upgradepf92-94sim.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\tmpUpgrade\upgradepf94-95man.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\tmpUpgrade\upgradepf96-97man.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\tmpUpgrade\upgradepf97-98man.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\TourneyDescription.html
C:\Program Files\PartyGaming.Net\PartyPokerNet\Uninstall.exe
C:\Program Files\PartyGaming.Net\PartyPokerNet\usertab.txt
C:\Program Files\PartyGaming.Net\tmpUpgrade\INSTALL.LOG
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet104-105man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet105-106man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet106-107man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet107-108man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet109-110man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet110-111man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet111-112man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet112-113man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet113-114man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet114-115man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet115-116man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet116-117man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet117-118man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet119-120man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet92-93sim.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet93-94man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet94-95man.exe
C:\Program Files\PartyGaming.Net\tmpUpgrade\upgradePGNet95-96man.exe
C:\Program Files\PartyGaming.Net\UNICOWS.DLL
C:\Program Files\Tzzdskr
C:\Program Files\Tzzdskr\Ncqp.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\pqtmp.fil

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Netcom3
——-\PCDRDRV
——-\SNDSrvc


((((((((((((((((((((((((( Files Created from 2008-02-18 to 2008-03-18 )))))))))))))))))))))))))))))))
.

2008-03-14 12:42 . 2008-03-14 12:42 d——– C:\Program Files\Spybot - Search & Destroy
2008-03-14 12:42 . 2008-03-14 13:20 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-13 16:12 . 2008-03-13 16:13 d——– C:\Documents and Settings\Owner\Application Data\Ventrilo
2008-03-13 15:56 . 2008-03-13 15:56 d——– C:\Program Files\Ventrilo
2008-03-13 15:53 . 2008-03-13 15:53 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-24 18:09 . 2008-02-24 18:09 d——– C:\WINDOWS\sv3978

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-18 14:25 ——— d—–w C:\Documents and Settings\Owner\Application Data\WeatherBug
2008-03-16 17:14 ——— d—–w C:\Program Files\NoAds
2008-03-14 20:09 ——— d—–w C:\Documents and Settings\Owner\Application Data\Image Zone Express
2008-03-14 16:28 ——— d—–w C:\Program Files\Java
2008-02-26 03:54 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-08 22:40 ——— d—–w C:\Program Files\Microsoft Research
2008-01-26 07:31 ——— d—–w C:\Program Files\World of Warcraft
2003-02-16 00:28 0 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\WINDOWS\sv3978 —-

2008-02-24 18:09 522240 –a—— C:\WINDOWS\sv3978\svchost.exe


((((((((((((((((((((((((((((( snapshot@2008-03-16_13.28.51.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2000-08-31 12:00:00 163,328 —-a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2008-03-16 17:23:10 82,042 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\0fdf6651ec58af7738a5f192a16308f3.dll
+ 2008-03-18 15:28:17 82,042 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\0fdf6651ec58af7738a5f192a16308f3.dll
- 2008-03-16 17:23:04 32,870 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\1c4c331123ae5269fbd179de68e18722.dll
+ 2008-03-18 15:28:11 32,870 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\1c4c331123ae5269fbd179de68e18722.dll
- 2008-03-16 17:22:59 41,080 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\33dea2ee1515e1c0eedfcd55d2d0540f.dll
+ 2008-03-18 15:28:04 41,080 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\33dea2ee1515e1c0eedfcd55d2d0540f.dll
- 2008-03-16 17:22:55 41,060 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\37dbb36b1afb4153f311e1937d13beb9.dll
+ 2008-03-18 15:27:57 41,060 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\37dbb36b1afb4153f311e1937d13beb9.dll
- 2008-03-16 17:22:56 90,213 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\3dab63509796d9defe82e7c8f292cdc2.dll
+ 2008-03-18 15:27:58 90,213 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\3dab63509796d9defe82e7c8f292cdc2.dll
- 2008-03-16 17:22:56 24,681 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\426234b03a6207e763a72e588f8ed8de.dll
+ 2008-03-18 15:27:58 24,681 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\426234b03a6207e763a72e588f8ed8de.dll
- 2008-03-16 17:22:55 20,576 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\463172d63e5c347ebd2a2c9f3e30a769.dll
+ 2008-03-18 15:27:56 20,576 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\463172d63e5c347ebd2a2c9f3e30a769.dll
- 2008-03-16 17:23:07 20,594 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\480ac5427cb6705921c199c825f6feda.dll
+ 2008-03-18 15:28:16 20,594 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\480ac5427cb6705921c199c825f6feda.dll
- 2008-03-16 17:23:11 41,057 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\563d7ead40b59c49009856a0b10f2014.dll
+ 2008-03-18 15:28:18 41,057 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\563d7ead40b59c49009856a0b10f2014.dll
- 2008-03-16 17:23:16 36,965 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\5665e9d91ffd5329b4b069811edd98e1.dll
+ 2008-03-18 15:28:44 36,965 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\5665e9d91ffd5329b4b069811edd98e1.dll
- 2008-03-16 17:22:52 802,902 —-a-w C:\WINDOWS\Temp\pdk-SYSTEM\5f4010392d26de2972604a5df777f946\perl58.dll
+ 2008-03-18 15:27:50 802,902 —-a-w C:\WINDOWS\Temp\pdk-SYSTEM\5f4010392d26de2972604a5df777f946\perl58.dll
- 2008-03-16 17:22:57 32,871 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\619eb23c53abde1a9d9d6b8d81ccd746.dll
+ 2008-03-18 15:27:59 32,871 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\619eb23c53abde1a9d9d6b8d81ccd746.dll
- 2008-03-16 17:23:06 110,697 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\6b58dab08175faa9470d9b8f08345f77.dll
+ 2008-03-18 15:28:14 110,697 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\6b58dab08175faa9470d9b8f08345f77.dll
- 2008-03-16 17:23:02 819,261 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\7718c08cc46695fc3fef36d1131eac8d.dll
+ 2008-03-18 15:28:08 819,261 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\7718c08cc46695fc3fef36d1131eac8d.dll
- 2008-03-16 17:23:05 24,687 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\804a82b53759189a7786eee16508a628.dll
+ 2008-03-18 15:28:12 24,687 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\804a82b53759189a7786eee16508a628.dll
- 2008-03-16 17:23:12 28,794 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\8715287e64467664fda73ee36a680ad6.dll
+ 2008-03-18 15:28:19 28,794 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\8715287e64467664fda73ee36a680ad6.dll
- 2008-03-16 17:23:08 65,642 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\8d9ba91df5b696882e70aa59f4766acb.dll
+ 2008-03-18 15:28:17 65,642 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\8d9ba91df5b696882e70aa59f4766acb.dll
- 2008-03-16 17:22:59 24,670 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\93e8018418e0dd3aeabcea5210c424d9.dll
+ 2008-03-18 15:28:05 24,670 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\93e8018418e0dd3aeabcea5210c424d9.dll
- 2008-03-16 17:23:11 41,082 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\95e9a2327e375c6b6f41bca6adf49352.dll
+ 2008-03-18 15:28:18 41,082 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\95e9a2327e375c6b6f41bca6adf49352.dll
- 2008-03-16 17:23:07 20,590 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\9e11e8cf40c66b8d30f95ce783f2ac0b.dll
+ 2008-03-18 15:28:15 20,590 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\9e11e8cf40c66b8d30f95ce783f2ac0b.dll
- 2008-03-16 17:22:57 1,040,497 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\a507fccf2be25b878761a66bf411c201.dll
+ 2008-03-18 15:27:59 1,040,497 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\a507fccf2be25b878761a66bf411c201.dll
- 2008-03-16 17:22:58 143,483 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\abaa64637ebb3715a020574efc3032f8.dll
+ 2008-03-18 15:28:03 143,483 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\abaa64637ebb3715a020574efc3032f8.dll
- 2008-03-16 17:23:07 32,879 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\ad76515ff4d1de346e3888790190a3c0.dll
+ 2008-03-18 15:28:16 32,879 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\ad76515ff4d1de346e3888790190a3c0.dll
- 2008-03-16 17:23:11 24,680 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\b2a041897a5d2e9486f60c2f6017af23.dll
+ 2008-03-18 15:28:18 24,680 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\b2a041897a5d2e9486f60c2f6017af23.dll
- 2008-03-16 17:23:08 28,794 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\b44b56de153a5879c1b84993c5cdadfa.dll
+ 2008-03-18 15:28:17 28,794 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\b44b56de153a5879c1b84993c5cdadfa.dll
- 2008-03-16 17:22:56 24,706 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\baf7b671cd22e344218d4404c5715954.dll
+ 2008-03-18 15:27:58 24,706 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\baf7b671cd22e344218d4404c5715954.dll
- 2008-03-16 17:23:01 94,300 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\bbd2dcfa51103025d57caa776bc1047b.dll
+ 2008-03-18 15:28:07 94,300 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\bbd2dcfa51103025d57caa776bc1047b.dll
- 2008-03-16 17:23:08 24,696 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\bd9a153164799d8be71e6a02e5c8cc4b.dll
+ 2008-03-18 15:28:17 24,696 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\bd9a153164799d8be71e6a02e5c8cc4b.dll
- 2008-03-16 17:23:07 24,679 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\c0bb48510a66e6fdcb5936be6801222d.dll
+ 2008-03-18 15:28:15 24,679 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\c0bb48510a66e6fdcb5936be6801222d.dll
- 2008-03-16 17:23:11 24,683 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\c537490a8d5597db7ef38c63a14dd378.dll
+ 2008-03-18 15:28:18 24,683 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\c537490a8d5597db7ef38c63a14dd378.dll
- 2008-03-16 17:23:00 131,149 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\c92f1c7d4396f53f4c5d352e2bd8c9a9.dll
+ 2008-03-18 15:28:06 131,149 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\c92f1c7d4396f53f4c5d352e2bd8c9a9.dll
- 2008-03-16 17:23:00 28,790 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\cd36294c81a9e8872c0bc2638facfd15.dll
+ 2008-03-18 15:28:06 28,790 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\cd36294c81a9e8872c0bc2638facfd15.dll
- 2008-03-16 17:23:05 94,320 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\cd6be9554293967a36ad1075b097a79b.dll
+ 2008-03-18 15:28:12 94,320 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\cd6be9554293967a36ad1075b097a79b.dll
- 2008-03-16 17:23:00 86,138 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\df3d88a56622b79eb806b7ec6d5febc2.dll
+ 2008-03-18 15:28:05 86,138 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\df3d88a56622b79eb806b7ec6d5febc2.dll
- 2008-03-16 17:23:05 36,966 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\e247dd11d21a2bfdb97ad0cdd295b32d.dll
+ 2008-03-18 15:28:12 36,966 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\e247dd11d21a2bfdb97ad0cdd295b32d.dll
- 2008-03-16 17:23:07 32,888 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\e51718032942dd5fb4b1590be1ec8d83.dll
+ 2008-03-18 15:28:16 32,888 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\e51718032942dd5fb4b1590be1ec8d83.dll
- 2008-03-16 17:23:02 24,676 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\ea8f9cce13d067ab0d898ca399b403ed.dll
+ 2008-03-18 15:28:07 24,676 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\ea8f9cce13d067ab0d898ca399b403ed.dll
- 2008-03-16 17:23:04 20,567 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\fa142febd5dc53f93f911452e1a99387.dll
+ 2008-03-18 15:28:11 20,567 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\fa142febd5dc53f93f911452e1a99387.dll
- 2008-03-16 17:22:55 82,020 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\fb2e449d6244301907de33f5adebdb35.dll
+ 2008-03-18 15:27:57 82,020 —-a-r C:\WINDOWS\Temp\pdk-SYSTEM\fb2e449d6244301907de33f5adebdb35.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NoAds"="C:\Program Files\NoAds\NoAds.exe" [2003-06-30 23:50 122880]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2005-06-07 14:58 1339392]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 20:04 52736]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2002-09-09 11:05 114688]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 01:42 212992]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-08-01 00:28 81920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2003-07-02 11:48 77824]
"S3TRAY2"="S3tray2.exe" [2003-02-25 04:33 69632 C:\WINDOWS\system32\S3tray2.exe]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-06-20 16:30 69632]
"CamMonitor"="C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 01:23 90112]
"CTSysVol"="C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 11:43 57344]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 02:00 90112]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2005-03-15 05:46 196608]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 19:26 217088]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-02-19 03:41 49152]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
Screen Saver Control.lnk - C:\WINDOWS\FSScrCtl.exe [2005-02-20 10:07:43 249344]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"= 0 (0x0)
"Btn_Search"= 0 (0x0)

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SlimServer Tray Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SlimServer Tray Tool.lnk
backup=C:\WINDOWS\pss\SlimServer Tray Tool.lnkCommon Startup

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9000:TCP"= 9000:TCP:SlimServer 9000 tcp
"3483:UDP"= 3483:UDP:SlimServer 3483 udp
"3483:TCP"= 3483:TCP:SlimServer 3483 tcp
"3724:TCP"= 3724:TCP:WoW
"3724:UDP"= 3724:UDP:WoW

R2 SlimServerMySQL;SlimServerMySQL;C:\PROGRA~1\SLIMSE~1\server\Bin\MSWIN3~1\mysqld.exe [2007-08-15 19:23]
S3 msCMTSrvc;Content Monitoring Tool;C:\WINDOWS\system32\msCMTSrvc.exe [2002-03-27 07:42]

.
Contents of the 'Scheduled Tasks' folder
"2008-03-18 10:27:00 C:\WINDOWS\Tasks\Disk Cleanup.job"
- C:\WINDOWS\system32\cleanmgr.exe
"2008-03-18 13:00:00 C:\WINDOWS\Tasks\rpc.job"
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe
"2008-03-18 05:55:05 C:\WINDOWS\Tasks\User_Feed_Synchronization-{92101280-83C4-41AA-BB16-2DD11AC1374A}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-18 11:28:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\NoAds\NoAds.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\SlimServer\server\slim.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-03-18 11:33:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-18 15:33:27
ComboFix2.txt 2008-03-16 17:29:17
.
2008-03-12 06:10:29 — E O F —







Logfile of HijackThis v1.99.1
Scan saved at 11:37, on 2008-03-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\PROGRA~1\SLIMSE~1\server\Bin\MSWIN3~1\mysqld.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\NoAds\NoAds.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SlimServer\server\slim.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\FSScrCtl.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=localhost:8081;http=localhost:8081
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [NoAds] "C:\Program Files\NoAds\NoAds.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Screen Saver Control.lnk = C:\WINDOWS\FSScrCtl.exe
O4 - Global Startup: updater.lnk = C:\Program Files\Common Files\updater\wupdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by117fd.bay117.hotmail.msn.com/activex/HMAtchmt.ocx
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\system32\nvsvc32.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SlimServerMySQL - Unknown owner - C:\PROGRA~1\SLIMSE~1\server\Bin\MSWIN3~1\mysqld.exe
O23 - Service: SlimServer (slimsvc) - Unknown owner - C:\Program Files\SlimServer\server\slim.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe








——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
2008-03-18 14:10
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 18/03/2008
Kaspersky Anti-Virus database records: 637233
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\

Scan Statistics:
Total number of scanned objects: 72285
Number of viruses found: 28
Number of infected objects: 67
Number of suspicious objects: 0
Duration of the scan process: 01:20:44

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Application Data\rdrante\31775.del Infected: Packed.Win32.PolyCrypt.d skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\16\1415d0-5fbbc94b/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\16\1415d0-5fbbc94b/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\16\1415d0-5fbbc94b/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\16\1415d0-5fbbc94b ZIP: infected - 3 skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\24\3e021ed8-553808e4/Counter.class Infected: Trojan.Java.ClassLoader.i skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\24\3e021ed8-553808e4/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\24\3e021ed8-553808e4/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\24\3e021ed8-553808e4 ZIP: infected - 3 skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\37\3e36ace5-71452e94/MagicApplet.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\37\3e36ace5-71452e94/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\37\3e36ace5-71452e94 ZIP: infected - 2 skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\42\307e0b6a-3712e868/GetAccess.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\42\307e0b6a-3712e868/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\42\307e0b6a-3712e868/NewSecurityClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\42\307e0b6a-3712e868/NewURLClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\42\307e0b6a-3712e868 ZIP: infected - 4 skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\47\3661afaf-7f00b6fb/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\47\3661afaf-7f00b6fb/Counter.class Infected: Trojan.Java.ClassLoader.h skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\47\3661afaf-7f00b6fb/Parser.class Infected: Trojan.Java.ClassLoader.d skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\47\3661afaf-7f00b6fb ZIP: infected - 3 skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\47\5224156f-1988d034/MagicApplet.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\47\5224156f-1988d034/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\47\5224156f-1988d034 ZIP: infected - 2 skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-44f46a27-5ba4ecf6.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-44f46a27-5ba4ecf6.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-44f46a27-5ba4ecf6.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-44f46a27-5ba4ecf6.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-96c4fc7-79c18753.zip/GetAccess.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-96c4fc7-79c18753.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-96c4fc7-79c18753.zip/NewSecurityClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-96c4fc7-79c18753.zip/NewURLClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-96c4fc7-79c18753.zip ZIP: infected - 4 skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv557.jar-500f74fc-6cf0500a.zip/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv557.jar-500f74fc-6cf0500a.zip/Counter.class Infected: Trojan.Java.ClassLoader.h skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv557.jar-500f74fc-6cf0500a.zip/Parser.class Infected: Trojan.Java.ClassLoader.d skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv557.jar-500f74fc-6cf0500a.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
C:\hp\region\EN_US-ie.reg Infected: Trojan.WinREG.StartPage skipped
C:\Program Files\Common Files\csshare\plugins0942\npzango.dll Infected: not-a-virus:AdWare.Win32.WinAD.aw skipped
C:\Program Files\SlimServer\server\Cache\MySQL\ibdata1 Object is locked skipped
C:\Program Files\SlimServer\server\Cache\MySQL\ib_logfile0 Object is locked skipped
C:\Program Files\SlimServer\server\Cache\MySQL\ib_logfile1 Object is locked skipped
C:\Program Files\SlimServer\server\Cache\mysql-error-log.txt Object is locked skipped
C:\QooBox\Quarantine\C\Program Files\Tzzdskr\Ncqp.exe.vir Infected: Trojan.Win32.Small.cy skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\a.exe.vir Infected: Trojan-Downloader.Win32.Agent.kst skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP1282\A0319106.DLL Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP1282\A0319107.EXE Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP1282\A0319111.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ao skipped
C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP1282\A0319112.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped
C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP1282\A0319113.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP1282\A0319164.exe Infected: not-a-virus:AdWare.Win32.Agent.agw skipped
C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP1284\A0319530.exe Infected: Trojan-Downloader.Win32.Agent.kst skipped
C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP1286\A0319709.exe Infected: Trojan.Win32.Small.cy skipped
C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP1286\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\eSearchBar\eu_Filesubmit_p1.exe/data0002/data0002 Infected: Trojan-Downloader.Win32.Keenval skipped
C:\WINDOWS\eSearchBar\eu_Filesubmit_p1.exe/data0002/data0004 Infected: Trojan-Downloader.Win32.Keenval skipped
C:\WINDOWS\eSearchBar\eu_Filesubmit_p1.exe/data0002/data0005 Infected: Trojan-Downloader.Win32.Keenval skipped
C:\WINDOWS\eSearchBar\eu_Filesubmit_p1.exe/data0002 Infected: Trojan-Downloader.Win32.Keenval skipped
C:\WINDOWS\eSearchBar\eu_Filesubmit_p1.exe/data0003 Infected: Trojan-Downloader.Win32.Keenval.e skipped
C:\WINDOWS\eSearchBar\eu_Filesubmit_p1.exe/data0004 Infected: Trojan-Downloader.Win32.Keenval.b skipped
C:\WINDOWS\eSearchBar\eu_Filesubmit_p1.exe NSIS: infected - 6 skipped
C:\WINDOWS\Lycos\ss_IGN1_setup.exe/data0002 Infected: not-a-virus:AdWare.Win32.Sidesearch.d skipped
C:\WINDOWS\Lycos\ss_IGN1_setup.exe NSIS: infected - 1 skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\70tovmto.ini Infected: not-a-virus:AdWare.Win32.Sahat.ao skipped
C:\WINDOWS\system32\bho32.exe Infected: Trojan-Downloader.Win32.Zlob.hbk skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\hqjob089.ini Infected: not-a-virus:AdWare.Win32.Sahat.ao skipped
C:\WINDOWS\system32\msCMTsrvc.exe Infected: Trojan-Downloader.Win32.Presario skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ib2 Object is locked skipped
C:\WINDOWS\Temp\ib3 Object is locked skipped
C:\WINDOWS\Temp\ib4 Object is locked skipped
C:\WINDOWS\Temp\ib5 Object is locked skipped
C:\WINDOWS\Temp\ib6 Object is locked skipped
C:\WINDOWS\Temp\ONE24.tmp\upgrade.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.OneStep.d skipped
C:\WINDOWS\Temp\ONE24.tmp\upgrade.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.OneStep.c skipped
C:\WINDOWS\Temp\ONE24.tmp\upgrade.exe/stream/data0003 Infected: not-a-virus:AdWare.Win32.OneStep.c skipped
C:\WINDOWS\Temp\ONE24.tmp\upgrade.exe/stream Infected: not-a-virus:AdWare.Win32.OneStep.c skipped
C:\WINDOWS\Temp\ONE24.tmp\upgrade.exe NSIS: infected - 4 skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP1286\change.log Object is locked skipped
H:\c_021503.002 Object is locked skipped
H:\c_021503.003 Object is locked skipped
H:\c_021503.004 Object is locked skipped
H:\c_021503.005 Object is locked skipped
H:\c_021503.PQI Object is locked skipped
H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
H:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP1286\change.log Object is locked skipped

Scan process completed.
A.

dayam, i think my computer hates me…….


Why are you saying that?


B. Your Java cache is infected we need to clean it out:

Clearing Java Cache

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)[external image: Posted Image]
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


C. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:
File::
C:\Documents and Settings\Owner\Application Data\rdrante\31775.del
C:\hp\region\EN_US-ie.reg
C:\WINDOWS\system32\70tovmto.ini
C:\WINDOWS\system32\bho32.exe
C:\WINDOWS\system32\hqjob089.ini
C:\WINDOWS\system32\msCMTsrvc.exe
C:\WINDOWS\Temp\ONE24.tmp
C:\Program Files\Common Files\updater

Folder::
C:\Program Files\Common Files\csshare\plugins0942
C:\WINDOWS\eSearchBar
C:\WINDOWS\Lycos

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply after you re-enable all the programs that were disabled during the running of ComboFix:
  • Combofix.txt
  • A new HijackThis log.
Please take note:

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
here ya go boss………..






Logfile of HijackThis v1.99.1
Scan saved at 15:14, on 2008-03-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\PROGRA~1\SLIMSE~1\server\Bin\MSWIN3~1\mysqld.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SlimServer\server\slim.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\FSScrCtl.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=localhost:8081;http=localhost:8081
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [NoAds] "C:\Program Files\NoAds\NoAds.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Screen Saver Control.lnk = C:\WINDOWS\FSScrCtl.exe
O4 - Global Startup: updater.lnk = C:\Program Files\Common Files\updater\wupdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by117fd.bay117.hotmail.msn.com/activex/HMAtchmt.ocx
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\system32\nvsvc32.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SlimServerMySQL - Unknown owner - C:\PROGRA~1\SLIMSE~1\server\Bin\MSWIN3~1\mysqld.exe
O23 - Service: SlimServer (slimsvc) - Unknown owner - C:\Program Files\SlimServer\server\slim.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe







Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Documents and Settings\Owner\Application Data\rdrante\31775.del
C:\hp\region\EN_US-ie.reg
C:\Program Files\Common Files\updater
C:\WINDOWS\system32\70tovmto.ini
C:\WINDOWS\system32\bho32.exe
C:\WINDOWS\system32\hqjob089.ini
C:\WINDOWS\system32\msCMTsrvc.exe
C:\WINDOWS\Temp\ONE24.tmp
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Owner\Application Data\rdrante\31775.del
C:\hp\region\EN_US-ie.reg
C:\Program Files\Common Files\csshare\plugins0942
C:\Program Files\Common Files\csshare\plugins0942\npclntax.dll
C:\Program Files\Common Files\csshare\plugins0942\NPJava11.dll
C:\Program Files\Common Files\csshare\plugins0942\NPJava12.dll
C:\Program Files\Common Files\csshare\plugins0942\NPJava13.dll
C:\Program Files\Common Files\csshare\plugins0942\NPJava32.dll
C:\Program Files\Common Files\csshare\plugins0942\NPJPI140_01.dll
C:\Program Files\Common Files\csshare\plugins0942\NPOJI610.dll
C:\Program Files\Common Files\csshare\plugins0942\nppdf32.dll
C:\Program Files\Common Files\csshare\plugins0942\nppl3260.dll
C:\Program Files\Common Files\csshare\plugins0942\nppl3260.xpt
C:\Program Files\Common Files\csshare\plugins0942\npqtplugin.dll
C:\Program Files\Common Files\csshare\plugins0942\npqtplugin2.dll
C:\Program Files\Common Files\csshare\plugins0942\npqtplugin3.dll
C:\Program Files\Common Files\csshare\plugins0942\npqtplugin4.dll
C:\Program Files\Common Files\csshare\plugins0942\nprjplug.dll
C:\Program Files\Common Files\csshare\plugins0942\nprpjplug.dll
C:\Program Files\Common Files\csshare\plugins0942\NPSWF32.dll
C:\Program Files\Common Files\csshare\plugins0942\npzango.dll
C:\Program Files\Common Files\csshare\plugins0942\nsIQTScriptablePlugin.xpt
C:\Program Files\Common Files\csshare\plugins0942\nsJSRealPlayerPlugin.xpt
C:\Program Files\Common Files\csshare\plugins0942\QuickTimePlugin.class
C:\WINDOWS\eSearchBar
C:\WINDOWS\eSearchBar\eu_Filesubmit_p1.exe
C:\WINDOWS\Lycos
C:\WINDOWS\Lycos\ss_IGN1_setup.exe
C:\WINDOWS\system32\70tovmto.ini
C:\WINDOWS\system32\bho32.exe
C:\WINDOWS\system32\hqjob089.ini
C:\WINDOWS\system32\msCMTsrvc.exe

.
((((((((((((((((((((((((( Files Created from 2008-02-18 to 2008-03-18 )))))))))))))))))))))))))))))))
.

2008-03-18 11:48 . 2008-03-18 11:48 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-03-18 11:48 . 2008-03-18 11:48 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-18 11:45 . 2008-03-18 11:45 d——– C:\WINDOWS\LastGood
2008-03-14 12:42 . 2008-03-14 12:42 d——– C:\Program Files\Spybot - Search & Destroy
2008-03-14 12:42 . 2008-03-14 13:20 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-13 16:12 . 2008-03-13 16:13 d——– C:\Documents and Settings\Owner\Application Data\Ventrilo
2008-03-13 15:56 . 2008-03-13 15:56 d——– C:\Program Files\Ventrilo
2008-03-13 15:53 . 2008-03-13 15:53 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-24 18:09 . 2008-02-24 18:09 d——– C:\WINDOWS\sv3978

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-18 19:08 ——— d—–w C:\Program Files\Common Files\csshare
2008-03-18 19:08 ——— d—–w C:\Documents and Settings\Owner\Application Data\rdrante
2008-03-18 14:25 ——— d—–w C:\Documents and Settings\Owner\Application Data\WeatherBug
2008-03-16 17:14 ——— d—–w C:\Program Files\NoAds
2008-03-14 20:09 ——— d—–w C:\Documents and Settings\Owner\Application Data\Image Zone Express
2008-03-14 16:28 ——— d—–w C:\Program Files\Java
2008-02-26 03:54 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-08 22:40 ——— d—–w C:\Program Files\Microsoft Research
2008-01-26 07:31 ——— d—–w C:\Program Files\World of Warcraft
2003-02-16 00:28 0 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((( snapshot_2008-03-18_11.33.08.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-05-24 16:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NoAds"="C:\Program Files\NoAds\NoAds.exe" [2003-06-30 23:50 122880]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2005-06-07 14:58 1339392]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 20:04 52736]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2002-09-09 11:05 114688]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 01:42 212992]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-08-01 00:28 81920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2003-07-02 11:48 77824]
"S3TRAY2"="S3tray2.exe" [2003-02-25 04:33 69632 C:\WINDOWS\system32\S3tray2.exe]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-06-20 16:30 69632]
"CamMonitor"="C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 01:23 90112]
"CTSysVol"="C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 11:43 57344]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 02:00 90112]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2005-03-15 05:46 196608]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 19:26 217088]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-02-19 03:41 49152]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
Screen Saver Control.lnk - C:\WINDOWS\FSScrCtl.exe [2005-02-20 10:07:43 249344]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"= 0 (0x0)
"Btn_Search"= 0 (0x0)

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SlimServer Tray Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SlimServer Tray Tool.lnk
backup=C:\WINDOWS\pss\SlimServer Tray Tool.lnkCommon Startup

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9000:TCP"= 9000:TCP:SlimServer 9000 tcp
"3483:UDP"= 3483:UDP:SlimServer 3483 udp
"3483:TCP"= 3483:TCP:SlimServer 3483 tcp
"3724:TCP"= 3724:TCP:WoW
"3724:UDP"= 3724:UDP:WoW

R2 SlimServerMySQL;SlimServerMySQL;C:\PROGRA~1\SLIMSE~1\server\Bin\MSWIN3~1\mysqld.exe [2007-08-15 19:23]
S3 msCMTSrvc;Content Monitoring Tool;C:\WINDOWS\system32\msCMTSrvc.exe []

.
Contents of the 'Scheduled Tasks' folder
"2008-03-18 10:27:00 C:\WINDOWS\Tasks\Disk Cleanup.job"
- C:\WINDOWS\system32\cleanmgr.exe
"2008-03-18 13:00:00 C:\WINDOWS\Tasks\rpc.job"
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe
"2008-03-18 05:55:05 C:\WINDOWS\Tasks\User_Feed_Synchronization-{92101280-83C4-41AA-BB16-2DD11AC1374A}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-18 15:10:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-18 15:12:06
ComboFix-quarantined-files.txt 2008-03-18 19:11:27
ComboFix2.txt 2008-03-18 15:33:31
ComboFix3.txt 2008-03-16 17:29:17
.
2008-03-12 06:10:29 — E O F —
Please go to: Virus Total
  • [external image: Posted Image]
  • Click the Browse button and search for the following file: C:\WINDOWS\sv3978\svchost.exe
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI