This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Ntptdb.sys

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi :)
My computer has recently been crashing on me when it startup and a BSoD appears.
The problem file is highlighted as :

ntptdb.sys

which is actually a virus in chinese, that causes random websites to pop up.
I ran a full system scan and downloaded many programmes for adware,spyware etc removal but
I still couldn't locate the file and hence, couldn't remove it as well.

Here's the HijackThis Log for my Computer:

Logfile of HijackThis v1.99.1
Scan saved at 12:02:59 AM, on 3/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Info cache - {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} - C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: del.icio.us Toolbar Helper - {7AA07AE6-01EF-44EC-93CA-9D7CD41CCDB6} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: Adobe Common Objects - {C86488AF-13D5-4FEF-9DDF-9FB88698CFC1} - C:\Documents and Settings\All Users\Application Data\Microsoft\Office\USERDATA\om 2345.com 5566.net kzdh.com ¿áÕ¾ ÍøÖ· sina baidu.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: del.icio.us - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SDR6_Check] "C:\Program Files\Common Files\DriveCleaner 2006 Free\udcsdr.exe"
O4 - HKLM\..\Run: [PAS_Check] "C:\Program Files\Common Files\DriveCleaner 2006 Free\udcpas.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\RunOnce: [286gf] %systemroot%\system32\Rundll32.exe %systemroot%\system32\286gf.dll,DllUnregisterServer
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-SG/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1149523250647
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149543421608
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/chainz2/sis/mjolauncher.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C5019 - Unknown owner - C:\WINDOWS\system32\C5019.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: System Event loader (sysloader) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\sysloader.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Windows Advanced Manager (wamer) - Unknown owner - C:\Program Files\Microsoft Office\SYSTEM\dodolook_7456.exe

Thanks :)
Hello ApplePears and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem. Those Chinese infections are often very tricky. Bet you you picked it up using MegaUpload!


A. First we must disable some of your security programs so that they do not interfere with the running of our tools:

NORTON ANTIVIRUS
Please navigate to the system tray on the bottom right hand corner and look for a [external image: Posted Image] sign.
  • right-click it -> chose "Disable Auto-Protect."
  • select a duration of 5 hours (this assures no interference with the cleanup of your pc)
  • click "Ok."
  • a popup will warn that protection will now be disabled and the sign will now look like this: [external image: Posted Image]
You succesfully disabled the Norton Antivirus Guard.


SPYWARE DOCTOR
  • Click the Spyware Doctor icon in the System Tray.
  • Click Settings.
  • Click Startup Settings under Pick a Category.
  • Uncheck "Run at Windows startup".
  • Click Apply and Exit Spyware Doctor.
  • From within Spyware Doctor, click the "OnGuard" button on the left side.
  • Uncheck "Activate OnGuard".
  • (When we are done, you can reenable Spyware Doctor)


B. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • ComboFix will automatically start. Any monitoring programs will be shut down like your antivirus, antispyware programs for example.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
hi :)

Here's the Combo Fix and Hijack This Logs

ComboFix 08-03-14.4 - Chris Ow 2008-03-17 20:22:49.3 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.329 [GMT 8:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\Documents and Settings\Administrator\Desktop\MalwareAlarm.lnk
C:\Documents and Settings\Administrator\Start Menu\Programs\MalwareAlarm
C:\Documents and Settings\Administrator\Start Menu\Programs\MalwareAlarm\MalwareAlarm.lnk
C:\Documents and Settings\Administrator\Start Menu\Programs\MalwareAlarm\Uninstall.lnk
C:\Documents and Settings\All Users\Application Data\microsoft\office\system
C:\Documents and Settings\All Users\Application Data\microsoft\office\system\finder.dll
C:\Documents and Settings\All Users\Application Data\microsoft\office\system\ntptdb.sys
C:\Documents and Settings\All Users\Application Data\microsoft\office\userdata
C:\Documents and Settings\All Users\Application Data\microsoft\office\userdata\ ¶¾ ·À»ðǽ ÈðÐÇ ½­Ãñ kv sina so 163 taobao qq yahoo china mop china ali 168 live 51 net sky 126 Íø 123 bt
C:\Documents and Settings\All Users\Application Data\microsoft\office\userdata\_keepfile
C:\Documents and Settings\All Users\Application Data\microsoft\office\userdata\om 2345.com 5566.net kzdh.com ¿áÕ¾ ÍøÖ· sina baidu.dll
C:\Documents and Settings\All Users\Application Data\microsoft\pctools
C:\Documents and Settings\All Users\Application Data\microsoft\pctools\pctools.dll
C:\Documents and Settings\Chris Ow\err.log
C:\WINDOWS\45209.exe
C:\WINDOWS\KB611311.log
C:\WINDOWS\system32\d3d1caps.srg
C:\WINDOWS\system32\drivers\32veqjw7os.sys
C:\WINDOWS\system32\drivers\4yj94j6b3.sys
C:\WINDOWS\system32\mprmsgse.axz
C:\WINDOWS\tempaq

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\LEGACY_PCIHARDDISK
——-\LEGACY_SYSLOADER
——-\LEGACY_WAMER
——-\PciHardDisk
——-\sysloader
——-\wamer


((((((((((((((((((((((((( Files Created from 2008-02-17 to 2008-03-17 )))))))))))))))))))))))))))))))
.

2008-03-16 23:08 . 2008-03-16 23:44 d——– C:\Program Files\Spyware Doctor
2008-03-16 23:08 . 2008-03-17 20:34 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-16 23:08 . 2008-03-16 23:08 d——– C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-03-16 23:08 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-16 23:08 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-16 23:08 . 2008-02-01 12:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-16 23:08 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-03-16 22:13 . 2008-03-16 22:13 d——– C:\Program Files\MalwareAlarm
2008-03-16 22:12 . 2008-03-16 22:14 1,272,856 –a—— C:\Install
2008-03-16 22:03 . 2005-08-27 02:38 1,435,272 –a—— C:\WINDOWS\system32\Flash.ocx
2008-03-16 22:03 . 2003-11-19 13:59 512,688 –a—— C:\WINDOWS\system32\XceedCry.dll
2008-03-16 22:03 . 2004-05-11 09:56 423,784 –a—— C:\WINDOWS\system32\XceedBkp.dll
2008-03-16 22:03 . 2004-02-05 20:53 389,120 –a—— C:\WINDOWS\system32\ACTSKN43.OCX
2008-03-16 22:03 . 2004-01-09 10:54 188,416 –a—— C:\WINDOWS\system32\actsplash.ocx
2008-03-16 22:03 . 2004-03-08 23:00 131,856 –a—— C:\WINDOWS\system32\MSADODC.ocx
2008-03-16 22:03 . 2000-07-15 05:00 101,888 –a—— C:\WINDOWS\system32\VB6STKIT.DLL
2008-03-16 22:03 . 2001-03-28 22:02 89,088 –a—— C:\WINDOWS\system32\ProgressBar4.ocx
2008-03-16 22:03 . 1999-01-26 19:36 11,012 –a—— C:\WINDOWS\system32\threadapi.tlb
2008-03-16 20:55 . 2008-03-16 20:55 d—s—- C:\Documents and Settings\Administrator\UserData

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-16 15:00 94,208 —h–w C:\WINDOWS\system32\DE0AA.exe
2008-03-15 12:53 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-12 10:49 ——— d—–w C:\Documents and Settings\Chris Ow\Application Data\uTorrent
2008-03-10 10:19 13,195 —-a-w C:\Documents and Settings\SoM 3\ZGUICFGW.DAT
2008-02-06 19:47 982,016 —-a-w C:\WINDOWS\Internet Logs\xDB3A.tmp
2008-02-06 18:02 ——— d—–w C:\Program Files\PayPerView Lessons Modulation Tips and Tricks Vol 1
2008-02-06 17:59 ——— d—–w C:\Program Files\WINv7xSetup
2008-02-06 17:50 737,280 —-a-w C:\WINDOWS\iun6002.exe
2008-02-06 17:50 ——— d—–w C:\Program Files\PlayPianoTODAY
2008-01-27 13:22 93,184 —-a-w C:\WINDOWS\system32\MsVersion.exe
2008-01-27 13:22 93,184 —-a-w C:\WINDOWS\system32\C5019.exe
2008-01-22 22:40 1,653,248 —-a-w C:\WINDOWS\Internet Logs\xDB39.tmp
2008-01-19 16:58 ——— d—–w C:\Program Files\iTunes
2008-01-19 16:57 ——— d—–w C:\Program Files\iPod
2008-01-19 16:54 ——— d—–w C:\Program Files\QuickTime
2008-01-07 16:18 20,541 —-a-w C:\WINDOWS\system32\detoured.dll
2008-01-07 09:54 77,824 —-a-w C:\WINDOWS\system32\wxptdi.sys
2007-12-29 13:33 755,200 —-a-w C:\WINDOWS\Internet Logs\xDB38.tmp
2007-12-11 15:05 605,696 —-a-w C:\WINDOWS\Internet Logs\xDB37.tmp
2007-12-02 15:47 151,552 —-a-w C:\WINDOWS\Internet Logs\xDB36.tmp
2007-12-01 05:01 268,288 —-a-w C:\WINDOWS\Internet Logs\xDB35.tmp
2007-11-29 09:44 3,322,368 —-a-w C:\WINDOWS\Internet Logs\xDB34.tmp
2007-09-28 07:53 139,264 —-a-w C:\WINDOWS\Internet Logs\xDB33.tmp
2007-09-26 17:57 2,190,336 —-a-w C:\WINDOWS\Internet Logs\xDB32.tmp
2007-09-05 08:47 791,040 —-a-w C:\WINDOWS\Internet Logs\xDB31.tmp
2007-08-14 17:47 305,152 —-a-w C:\WINDOWS\Internet Logs\xDB30.tmp
2007-08-04 16:30 444,928 —-a-w C:\WINDOWS\Internet Logs\xDB2F.tmp
2007-07-19 11:01 1,510,912 —-a-w C:\WINDOWS\Internet Logs\xDB2E.tmp
2007-06-25 16:45 3,110,912 —-a-w C:\WINDOWS\Internet Logs\xDB2D.tmp
2007-06-16 10:36 2,956,800 —-a-w C:\WINDOWS\Internet Logs\xDB2C.tmp
2007-06-08 15:03 520,704 —-a-w C:\WINDOWS\Internet Logs\xDB2A.tmp
2007-06-01 09:32 2,131,968 —-a-w C:\WINDOWS\Internet Logs\xDB29.tmp
2007-05-25 13:02 139,264 —-a-w C:\WINDOWS\Internet Logs\xDB28.tmp
2007-05-24 15:21 232,960 —-a-w C:\WINDOWS\Internet Logs\xDB27.tmp
2007-05-21 22:38 1,192,448 —-a-w C:\WINDOWS\Internet Logs\xDB26.tmp
2007-05-09 10:29 60,928 —-a-w C:\WINDOWS\Internet Logs\xDB25.tmp
2007-05-09 10:29 1,490,944 —-a-w C:\WINDOWS\Internet Logs\xDB2B.tmp
2007-05-07 15:19 662,528 —-a-w C:\WINDOWS\Internet Logs\xDB24.tmp
2007-05-06 16:02 38,712 —-a-w C:\Documents and Settings\Chris Ow\Application Data\GDIPFONTCACHEV1.DAT
2007-05-02 13:21 132,096 —-a-w C:\WINDOWS\Internet Logs\xDB23.tmp
2007-05-01 08:14 459,776 —-a-w C:\WINDOWS\Internet Logs\xDB22.tmp
2007-04-26 13:44 227,328 —-a-w C:\WINDOWS\Internet Logs\xDB21.tmp
2007-04-24 14:58 91,648 —-a-w C:\WINDOWS\Internet Logs\xDB20.tmp
2007-04-22 22:36 1,736,192 —-a-w C:\WINDOWS\Internet Logs\xDB1F.tmp
2007-04-20 17:27 663,040 —-a-w C:\WINDOWS\Internet Logs\xDB1E.tmp
2007-04-16 11:20 514,048 —-a-w C:\WINDOWS\Internet Logs\xDB1D.tmp
2007-04-11 17:04 155,136 —-a-w C:\WINDOWS\Internet Logs\xDB1B.tmp
2007-04-11 17:04 1,463,808 —-a-w C:\WINDOWS\Internet Logs\xDB1C.tmp
2007-04-10 22:37 2,382,336 —-a-w C:\WINDOWS\Internet Logs\xDB1A.tmp
2007-04-01 07:01 3,847,627 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-03-26 22:35 245,248 —-a-w C:\WINDOWS\Internet Logs\xDB19.tmp
2007-03-24 18:00 794,112 —-a-w C:\WINDOWS\Internet Logs\xDB18.tmp
2007-03-19 22:33 543,232 —-a-w C:\WINDOWS\Internet Logs\xDB17.tmp
2007-03-14 17:42 652,800 —-a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2007-03-08 06:34 350,208 —-a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2007-03-04 18:32 674,816 —-a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2007-02-26 18:29 373,760 —-a-w C:\WINDOWS\Internet Logs\xDB13.tmp
2007-02-24 07:45 541,696 —-a-w C:\WINDOWS\Internet Logs\xDB11.tmp
2007-02-24 07:45 1,422,848 —-a-w C:\WINDOWS\Internet Logs\xDB12.tmp
2007-02-14 15:08 74,240 —-a-w C:\WINDOWS\Internet Logs\xDB10.tmp
2007-02-11 17:16 281,600 —-a-w C:\WINDOWS\Internet Logs\xDBF.tmp
2007-02-06 16:41 442,880 —-a-w C:\WINDOWS\Internet Logs\xDBE.tmp
2007-01-31 22:21 414,208 —-a-w C:\WINDOWS\Internet Logs\xDBD.tmp
2007-01-28 19:12 936,448 —-a-w C:\WINDOWS\Internet Logs\xDBC.tmp
2007-01-18 07:33 264,192 —-a-w C:\WINDOWS\Internet Logs\xDBA.tmp
2007-01-18 07:33 1,380,864 —-a-w C:\WINDOWS\Internet Logs\xDBB.tmp
2007-01-15 04:47 491,008 —-a-w C:\WINDOWS\Internet Logs\xDB9.tmp
2007-01-07 17:49 422,400 —-a-w C:\WINDOWS\Internet Logs\xDB8.tmp
2007-01-01 20:00 214,528 —-a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2006-12-31 15:36 1,360,384 —-a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2006-12-30 04:24 960,512 —-a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2006-12-19 16:01 189,952 —-a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2006-12-15 18:07 275,968 —-a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2006-12-02 19:13 2,900,992 —-a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2006-10-10 10:02 2,745,344 —-a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2006-05-21 15:19 0 —-a-w C:\Documents and Settings\SoM 3\sdd1dat.dat
2006-02-18 19:28 12,288 —-a-w C:\WINDOWS\Fonts\RandFont.dll
2001-09-30 12:43 440,832 —-a-w C:\Documents and Settings\SoM 3\ZSNESW.EXE
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 00:24 1694208]
"Norton SystemWorks"="C:\Program Files\Norton SystemWorks\cfgwiz.exe" [2004-09-10 10:12 132248]
"ares"="C:\Program Files\Ares\Ares.exe" [ ]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-02-05 18:15 171448]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2006-03-16 11:34 755480]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2003-05-01 13:59 180316]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 17:32 58984]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-08-21 19:21 100056]
"ATIModeChange"="Ati2mdxx.exe" []
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-01-20 21:10 335872]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-20 23:34 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43 83608]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2002-12-28 12:14 77824]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-06-26 01:32:15 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe [2006-02-10 07:56:20 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kavsvc.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVsvcUI.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVFW.EXE.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVMonXP.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ravtimer.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rising.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
–a—— 2005-03-04 15:01 88209 C:\WINDOWS\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
–a—— 2004-01-20 21:10 335872 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
–a—— 2004-11-04 18:38 688218 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
–a—— 2004-11-04 18:40 98394 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Documents and Settings\\Chris Ow\\My Documents\\My Completed Downloads\\utorrent.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R3 st3bus28;st3bus28;C:\WINDOWS\system32\DRIVERS\st3bus28.sys [2002-12-28 12:16]
R3 st3mp28;st3mp28;C:\WINDOWS\system32\DRIVERS\st3mp28.sys [2002-12-28 12:16]
R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;C:\WINDOWS\system32\Drivers\WBSD.SYS [2003-03-20 17:24]
S0 4yj94j6b3;4yj94j6b;C:\WINDOWS\system32\DRIVERS\4yj94j6b3.sys []
S2 32veqjw7os;32veqjw7os;C:\WINDOWS\system32\drivers\32veqjw7os.sys []
S2 C5019;C5019;C:\WINDOWS\system32\C5019.exe [2008-01-27 21:22]
S2 ntptdb;ntptdb;C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{170ad970-220a-11dc-8559-0004235b5517}]
\Shell\AutoRun\command - I:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1c5e4ea0-f5c3-11da-8323-0004235b5517}]
\Shell\AutoRun\command - ie.exe
\Shell\explore\Command - ie.exe
\Shell\open\Command - ie.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1c5e4ea2-f5c3-11da-8323-0004235b5517}]
\Shell\AutoRun\command - D:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{42439470-2ffa-11db-8373-0004235b5517}]
\Shell\AutoRun\command - G:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{51014af0-2f25-11db-8370-0004235b5517}]
\Shell\AutoRun\command - D:\setupSNK.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-16 07:11:15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-29 12:01:38 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Chris Ow.job"
- C:\PROGRA~1\NORTON~1\NORTON~3\Navw32.exeh/task:
"2007-12-31 09:12:31 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
- C:\Program Files\Norton SystemWorks\OBC.exe
"2008-03-14 16:00:00 C:\WINDOWS\Tasks\Symantec Drmc.job"
- C:\Program Files\Common Files\Symantec Shared\SymDrmc.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-17 20:35:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
.
**************************************************************************

——————————- HIJACK THIS LOG ————————————–
Logfile of HijackThis v1.99.1
Scan saved at 20:45, on 2008-03-17
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: del.icio.us Toolbar Helper - {7AA07AE6-01EF-44EC-93CA-9D7CD41CCDB6} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: del.icio.us - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-SG/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1149523250647
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149543421608
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/chainz2/sis/mjolauncher.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C5019 - Unknown owner - C:\WINDOWS\system32\C5019.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe



.
Completion time: 2008-03-17 20:43:24 - machine was rebooted [Chris Ow]
ComboFix-quarantined-files.txt 2008-03-17 12:43:20
.
2008-03-12 16:44:52 — E O F —
A. 1. Go to Start->Run and type in notepad and hit OK.

2. Then copy and paste the content of the following codebox into Notepad:

@Echo off
FOR %%G IN (
"C:\WINDOWS\Internet Logs\xDB*.tmp"
) DO (
attrib -r -h -s %%G
del /q /f %%G
)
del delete.bat

3. Save the file to your DESKTOP as "delete.bat". Make sure to save it with the quotes. Once saved, the icon to click should look like this on your desktop: [external image: Posted Image]

4. Double click delete.bat.


B. A. Make sure that your security programs are disabled as per previous intructions


C. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll:

File::
C:\WINDOWS\system32\C5019.exe
C:\WINDOWS\system32\DE0AA.exe
C:\WINDOWS\system32\MsVersion.exe
C:\WINDOWS\system32\wxptdi.sys
C:\WINDOWS\Fonts\RandFont.dll

Folder::
C:\Program Files\WINv7xSetup

Drivers::
4yj94j6b3
32veqjw7os
C5019
ntptdb 

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ares"=-
"BitTorrent"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIModeChange"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


D. Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
Hi Again :)

Here's the New 1) Hijackthis Text 2) ComboFix Text 3) Kaspersky Text

Logfile of HijackThis v1.99.1
Scan saved at 00:41, on 2008-03-19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: del.icio.us Toolbar Helper - {7AA07AE6-01EF-44EC-93CA-9D7CD41CCDB6} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: del.icio.us - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-SG/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1149523250647
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149543421608
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/chainz2/sis/mjolauncher.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C5019 - Unknown owner - C:\WINDOWS\system32\C5019.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

————————- COMBO FIX TEXT —————————-
ComboFix 08-03-14.4 - Chris Ow 2008-03-18 20:53:59.4 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.314 [GMT 8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Chris Ow\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\Fonts\RandFont.dll
C:\WINDOWS\system32\C5019.exe
C:\WINDOWS\system32\DE0AA.exe
C:\WINDOWS\system32\MsVersion.exe
C:\WINDOWS\system32\wxptdi.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\WINv7xSetup
C:\Program Files\WINv7xSetup\modulation1setup\Download Progress.html
C:\Program Files\WINv7xSetup\modulation1setup\files.ini
C:\Program Files\WINv7xSetup\modulation1setup\Join32.exe
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.001
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.002
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.003
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.004
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.005
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.006
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.007
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.008
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.009
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.010
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.011
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.012
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.013
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.014
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.015
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.016
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.017
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.018
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.019
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.020
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.021
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.exe.022
C:\Program Files\WINv7xSetup\modulation1setup\modulation1setup.ini
C:\Program Files\WINv7xSetup\modulation1setup\resume.swf
C:\WINDOWS\Fonts\RandFont.dll
C:\WINDOWS\system32\C5019.exe
C:\WINDOWS\system32\DE0AA.exe
C:\WINDOWS\system32\MsVersion.exe
C:\WINDOWS\system32\wxptdi.sys

.
((((((((((((((((((((((((( Files Created from 2008-02-18 to 2008-03-18 )))))))))))))))))))))))))))))))
.

2008-03-16 23:08 . 2008-03-16 23:44 d——– C:\Program Files\Spyware Doctor
2008-03-16 23:08 . 2008-03-18 20:46 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-16 23:08 . 2008-03-16 23:08 d——– C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-03-16 23:08 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-16 23:08 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-16 23:08 . 2008-02-01 12:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-16 23:08 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-03-16 22:13 . 2008-03-16 22:13 d——– C:\Program Files\MalwareAlarm
2008-03-16 22:12 . 2008-03-16 22:14 1,272,856 –a—— C:\Install
2008-03-16 22:03 . 2005-08-27 02:38 1,435,272 –a—— C:\WINDOWS\system32\Flash.ocx
2008-03-16 22:03 . 2003-11-19 13:59 512,688 –a—— C:\WINDOWS\system32\XceedCry.dll
2008-03-16 22:03 . 2004-05-11 09:56 423,784 –a—— C:\WINDOWS\system32\XceedBkp.dll
2008-03-16 22:03 . 2004-02-05 20:53 389,120 –a—— C:\WINDOWS\system32\ACTSKN43.OCX
2008-03-16 22:03 . 2004-01-09 10:54 188,416 –a—— C:\WINDOWS\system32\actsplash.ocx
2008-03-16 22:03 . 2004-03-08 23:00 131,856 –a—— C:\WINDOWS\system32\MSADODC.ocx
2008-03-16 22:03 . 2000-07-15 05:00 101,888 –a—— C:\WINDOWS\system32\VB6STKIT.DLL
2008-03-16 22:03 . 2001-03-28 22:02 89,088 –a—— C:\WINDOWS\system32\ProgressBar4.ocx
2008-03-16 22:03 . 1999-01-26 19:36 11,012 –a—— C:\WINDOWS\system32\threadapi.tlb
2008-03-16 20:55 . 2008-03-16 20:55 d—s—- C:\Documents and Settings\Administrator\UserData

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-15 12:53 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-12 10:49 ——— d—–w C:\Documents and Settings\Chris Ow\Application Data\uTorrent
2008-03-10 10:19 13,195 —-a-w C:\Documents and Settings\SoM 3\ZGUICFGW.DAT
2008-02-06 19:47 982,016 —-a-w C:\WINDOWS\Internet Logs\xDB3A.tmp
2008-02-06 18:02 ——— d—–w C:\Program Files\PayPerView Lessons Modulation Tips and Tricks Vol 1
2008-02-06 17:50 737,280 —-a-w C:\WINDOWS\iun6002.exe
2008-02-06 17:50 ——— d—–w C:\Program Files\PlayPianoTODAY
2008-01-22 22:40 1,653,248 —-a-w C:\WINDOWS\Internet Logs\xDB39.tmp
2008-01-19 16:58 ——— d—–w C:\Program Files\iTunes
2008-01-19 16:57 ——— d—–w C:\Program Files\iPod
2008-01-19 16:54 ——— d—–w C:\Program Files\QuickTime
2008-01-07 16:18 20,541 —-a-w C:\WINDOWS\system32\detoured.dll
2007-12-29 13:33 755,200 —-a-w C:\WINDOWS\Internet Logs\xDB38.tmp
2007-12-11 15:05 605,696 —-a-w C:\WINDOWS\Internet Logs\xDB37.tmp
2007-12-02 15:47 151,552 —-a-w C:\WINDOWS\Internet Logs\xDB36.tmp
2007-12-01 05:01 268,288 —-a-w C:\WINDOWS\Internet Logs\xDB35.tmp
2007-11-29 09:44 3,322,368 —-a-w C:\WINDOWS\Internet Logs\xDB34.tmp
2007-09-28 07:53 139,264 —-a-w C:\WINDOWS\Internet Logs\xDB33.tmp
2007-09-26 17:57 2,190,336 —-a-w C:\WINDOWS\Internet Logs\xDB32.tmp
2007-09-05 08:47 791,040 —-a-w C:\WINDOWS\Internet Logs\xDB31.tmp
2007-08-14 17:47 305,152 —-a-w C:\WINDOWS\Internet Logs\xDB30.tmp
2007-08-04 16:30 444,928 —-a-w C:\WINDOWS\Internet Logs\xDB2F.tmp
2007-07-19 11:01 1,510,912 —-a-w C:\WINDOWS\Internet Logs\xDB2E.tmp
2007-06-25 16:45 3,110,912 —-a-w C:\WINDOWS\Internet Logs\xDB2D.tmp
2007-06-16 10:36 2,956,800 —-a-w C:\WINDOWS\Internet Logs\xDB2C.tmp
2007-06-08 15:03 520,704 —-a-w C:\WINDOWS\Internet Logs\xDB2A.tmp
2007-06-01 09:32 2,131,968 —-a-w C:\WINDOWS\Internet Logs\xDB29.tmp
2007-05-25 13:02 139,264 —-a-w C:\WINDOWS\Internet Logs\xDB28.tmp
2007-05-24 15:21 232,960 —-a-w C:\WINDOWS\Internet Logs\xDB27.tmp
2007-05-21 22:38 1,192,448 —-a-w C:\WINDOWS\Internet Logs\xDB26.tmp
2007-05-09 10:29 60,928 —-a-w C:\WINDOWS\Internet Logs\xDB25.tmp
2007-05-09 10:29 1,490,944 —-a-w C:\WINDOWS\Internet Logs\xDB2B.tmp
2007-05-07 15:19 662,528 —-a-w C:\WINDOWS\Internet Logs\xDB24.tmp
2007-05-06 16:02 38,712 —-a-w C:\Documents and Settings\Chris Ow\Application Data\GDIPFONTCACHEV1.DAT
2007-05-02 13:21 132,096 —-a-w C:\WINDOWS\Internet Logs\xDB23.tmp
2007-05-01 08:14 459,776 —-a-w C:\WINDOWS\Internet Logs\xDB22.tmp
2007-04-26 13:44 227,328 —-a-w C:\WINDOWS\Internet Logs\xDB21.tmp
2007-04-24 14:58 91,648 —-a-w C:\WINDOWS\Internet Logs\xDB20.tmp
2007-04-22 22:36 1,736,192 —-a-w C:\WINDOWS\Internet Logs\xDB1F.tmp
2007-04-20 17:27 663,040 —-a-w C:\WINDOWS\Internet Logs\xDB1E.tmp
2007-04-16 11:20 514,048 —-a-w C:\WINDOWS\Internet Logs\xDB1D.tmp
2007-04-11 17:04 155,136 —-a-w C:\WINDOWS\Internet Logs\xDB1B.tmp
2007-04-11 17:04 1,463,808 —-a-w C:\WINDOWS\Internet Logs\xDB1C.tmp
2007-04-10 22:37 2,382,336 —-a-w C:\WINDOWS\Internet Logs\xDB1A.tmp
2007-04-01 07:01 3,847,627 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-03-26 22:35 245,248 —-a-w C:\WINDOWS\Internet Logs\xDB19.tmp
2007-03-24 18:00 794,112 —-a-w C:\WINDOWS\Internet Logs\xDB18.tmp
2007-03-19 22:33 543,232 —-a-w C:\WINDOWS\Internet Logs\xDB17.tmp
2007-03-14 17:42 652,800 —-a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2007-03-08 06:34 350,208 —-a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2007-03-04 18:32 674,816 —-a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2007-02-26 18:29 373,760 —-a-w C:\WINDOWS\Internet Logs\xDB13.tmp
2007-02-24 07:45 541,696 —-a-w C:\WINDOWS\Internet Logs\xDB11.tmp
2007-02-24 07:45 1,422,848 —-a-w C:\WINDOWS\Internet Logs\xDB12.tmp
2007-02-14 15:08 74,240 —-a-w C:\WINDOWS\Internet Logs\xDB10.tmp
2007-02-11 17:16 281,600 —-a-w C:\WINDOWS\Internet Logs\xDBF.tmp
2007-02-06 16:41 442,880 —-a-w C:\WINDOWS\Internet Logs\xDBE.tmp
2007-01-31 22:21 414,208 —-a-w C:\WINDOWS\Internet Logs\xDBD.tmp
2007-01-28 19:12 936,448 —-a-w C:\WINDOWS\Internet Logs\xDBC.tmp
2007-01-18 07:33 264,192 —-a-w C:\WINDOWS\Internet Logs\xDBA.tmp
2007-01-18 07:33 1,380,864 —-a-w C:\WINDOWS\Internet Logs\xDBB.tmp
2007-01-15 04:47 491,008 —-a-w C:\WINDOWS\Internet Logs\xDB9.tmp
2007-01-07 17:49 422,400 —-a-w C:\WINDOWS\Internet Logs\xDB8.tmp
2007-01-01 20:00 214,528 —-a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2006-12-31 15:36 1,360,384 —-a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2006-12-30 04:24 960,512 —-a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2006-12-19 16:01 189,952 —-a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2006-12-15 18:07 275,968 —-a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2006-12-02 19:13 2,900,992 —-a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2006-10-10 10:02 2,745,344 —-a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2006-05-21 15:19 0 —-a-w C:\Documents and Settings\SoM 3\sdd1dat.dat
2001-09-30 12:43 440,832 —-a-w C:\Documents and Settings\SoM 3\ZSNESW.EXE
.

((((((((((((((((((((((((((((( snapshot@2008-03-17_19.58.00.21 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-16 15:26:52 52,764 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-03-18 12:50:33 52,764 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-03-16 15:26:52 380,350 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-03-18 12:50:33 380,350 —-a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 00:24 1694208]
"Norton SystemWorks"="C:\Program Files\Norton SystemWorks\cfgwiz.exe" [2004-09-10 10:12 132248]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-02-05 18:15 171448]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2006-03-16 11:34 755480]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2003-05-01 13:59 180316]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 17:32 58984]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-08-21 19:21 100056]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-01-20 21:10 335872]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-20 23:34 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43 83608]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2002-12-28 12:14 77824]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-06-26 01:32:15 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe [2006-02-10 07:56:20 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kavsvc.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVsvcUI.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVFW.EXE.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVMonXP.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ravtimer.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rising.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
–a—— 2005-03-04 15:01 88209 C:\WINDOWS\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
–a—— 2004-01-20 21:10 335872 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
–a—— 2004-11-04 18:38 688218 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
–a—— 2004-11-04 18:40 98394 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Documents and Settings\\Chris Ow\\My Documents\\My Completed Downloads\\utorrent.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R3 st3bus28;st3bus28;C:\WINDOWS\system32\DRIVERS\st3bus28.sys [2002-12-28 12:16]
R3 st3mp28;st3mp28;C:\WINDOWS\system32\DRIVERS\st3mp28.sys [2002-12-28 12:16]
R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;C:\WINDOWS\system32\Drivers\WBSD.SYS [2003-03-20 17:24]
S0 4yj94j6b3;4yj94j6b;C:\WINDOWS\system32\DRIVERS\4yj94j6b3.sys []
S2 32veqjw7os;32veqjw7os;C:\WINDOWS\system32\drivers\32veqjw7os.sys []
S2 C5019;C5019;C:\WINDOWS\system32\C5019.exe []
S2 ntptdb;ntptdb;C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{170ad970-220a-11dc-8559-0004235b5517}]
\Shell\AutoRun\command - I:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1c5e4ea0-f5c3-11da-8323-0004235b5517}]
\Shell\AutoRun\command - ie.exe
\Shell\explore\Command - ie.exe
\Shell\open\Command - ie.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1c5e4ea2-f5c3-11da-8323-0004235b5517}]
\Shell\AutoRun\command - D:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{42439470-2ffa-11db-8373-0004235b5517}]
\Shell\AutoRun\command - G:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{51014af0-2f25-11db-8370-0004235b5517}]
\Shell\AutoRun\command - D:\setupSNK.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-16 07:11:15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-29 12:01:38 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Chris Ow.job"
- C:\PROGRA~1\NORTON~1\NORTON~3\Navw32.exeh/task:
"2007-12-31 09:12:31 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
- C:\Program Files\Norton SystemWorks\OBC.exe
"2008-03-14 16:00:00 C:\WINDOWS\Tasks\Symantec Drmc.job"
- C:\Program Files\Common Files\Symantec Shared\SymDrmc.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-18 21:03:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????9?1?7?1??????? ?pTB???????????????B? ??????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-18 21:09:24
ComboFix-quarantined-files.txt 2008-03-18 13:09:22
ComboFix2.txt 2008-03-17 12:43:30
.
2008-03-12 16:44:52 — E O F —

———————— KASPERSKY TEXT ——————————–
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
2008-03-19 00:39
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 18/03/2008
Kaspersky Anti-Virus database records: 636984
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
E:\
F:\
G:\
H:\

Scan Statistics:
Total number of scanned objects: 74137
Number of viruses found: 24
Number of infected objects: 123
Number of suspicious objects: 0
Duration of the scan process: 02:30:33

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\001e6e4ddd2ad55d774f70fdeb500dab_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e54cd17c3ce84fd00238f031503ce32_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4676ac5b84ffa4d5638d5ff1cb2e8519_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4ac19d7bcffa97f8e1f3b7f35e8b8347_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5423b3ab7cccd50759d6646c0f9f4901_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\666aacb8fe4d69dd831e1510c9bb891c_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6af7be32907b9ca1fbd610bbd212b29c_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d5b51446aecba7513852352fada95e0_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\82699b5320a8a5c97abca44c94b30027_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9e454cad879895d8deda98a60feac701_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\adf48c4f0ef5d14b5311a7a2cd93ee6d_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b60b739b5a569e4cd9879f07b7b0c19e_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b9cd804e632b0b44f9c0a24bebd16315_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d43754f5ac46f4f284306cc8af03698a_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed53bcf56386f6db73fc43458868bb2a_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ef1f611a383340d7f42d38169dd73462_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f46fcfee15ceb8f91c2221453c2e7d03_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f5bc19ea7c81592a0a823c46f0575c25_ea1bda05-990d-4ad7-af4f-b42da0944526 Object is locked skipped
C:\Documents and Settings\Chris Ow\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Chris Ow\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Chris Ow\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Chris Ow\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Chris Ow\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Chris Ow\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Chris Ow\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\DriveCleaner 2006 Free\udcpas.exe Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped
C:\Program Files\Common Files\DriveCleaner 2006 Free\udcsdr.exe Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped
C:\Program Files\MalwareAlarm\MalwareAlarm.exe Infected: not-a-virus:FraudTool.Win32.DrAntispy.ax skipped
C:\Program Files\MalwareAlarm\MalwareAlarm0.dll Infected: not-a-virus:FraudTool.Win32.BraveSentry.f skipped
C:\Program Files\MalwareAlarm\MalwareAlarm3.dll Infected: not-a-virus:FraudTool.Win32.BraveSentry.b skipped
C:\Program Files\Microsoft Office\SYSTEM\dodolook_7456.exe Infected: Trojan-Downloader.Win32.Agent.jrn skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\16C65F31.htm Infected: Trojan-Downloader.JS.Agent.fq skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\66C02EC1.tmp Infected: Trojan-Dropper.Win32.Delf.fl skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\70E82652.exe Infected: not-a-virus:Downloader.Win32.WinFixer.ar skipped
C:\QooBox\Quarantine\C\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\finder.dll.vir Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\QooBox\Quarantine\C\WINDOWS\45209.exe.vir Infected: Trojan-Downloader.Win32.VB.cmg skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\DE0AA.exe.vir Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\32veqjw7os.sys.vir Infected: Trojan-Downloader.Win32.Hmir.qc skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\wxptdi.sys.vir Infected: Worm.Win32.Downloader.en skipped
C:\QooBox\Quarantine\C\WINDOWS\tempaq.vir Infected: Trojan-Downloader.Win32.Hmir.qd skipped
C:\QooBox\Quarantine\catchme2008-03-17_195401.39.zip/4yj94j6b3.sys Infected: Trojan-Downloader.Win32.Hmir.qb skipped
C:\QooBox\Quarantine\catchme2008-03-17_195401.39.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\A0094929.exe/data0001.bin Infected: Trojan-Downloader.Win32.Agent.iwq skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\A0094929.exe EmbeddedEXE: infected - 1 skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\A0094929.exe PE_Patch: infected - 1 skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\A0094940.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\A0094992.DLL Infected: not-a-virus:AdWare.Win32.IEHlpr.gd skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\A0095009.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\A0095011.dll Infected: Trojan-Downloader.Win32.Agent.jdu skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\A0095044.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\A0095046.dll Infected: Trojan-Downloader.Win32.Agent.jdu skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\A0095132.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\A0095134.dll Infected: Trojan-Downloader.Win32.Agent.jdu skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\A0095214.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\A0095216.dll Infected: Trojan-Downloader.Win32.Agent.jdu skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\snapshot\MFEX-1.DAT/data0000.bin Infected: Trojan-Downloader.Win32.Agent.jdu skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\snapshot\MFEX-1.DAT/data0001.bin Infected: Trojan-Downloader.Win32.Agent.jdz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\snapshot\MFEX-1.DAT EmbeddedEXE: infected - 2 skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP411\snapshot\MFEX-1.DAT PE_Patch: infected - 2 skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095391.exe/data0000.bin Infected: Trojan-Downloader.Win32.Agent.jdu skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095391.exe/data0001.bin Infected: Trojan-Downloader.Win32.Agent.jdz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095391.exe EmbeddedEXE: infected - 2 skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095391.exe PE_Patch: infected - 2 skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095395.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095397.dll Infected: Trojan-Downloader.Win32.Agent.jdu skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095613.COM/data0002/data0000.bin Infected: Trojan-Downloader.Win32.Agent.jdu skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095613.COM/data0002/data0001.bin Infected: Trojan-Downloader.Win32.Agent.jdz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095613.COM/data0002 Infected: Trojan-Downloader.Win32.Agent.jdz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095613.COM NSIS: infected - 3 skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095614.EXE/data0002/data0000.bin Infected: Trojan-Downloader.Win32.Agent.jdu skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095614.EXE/data0002/data0001.bin Infected: Trojan-Downloader.Win32.Agent.jdz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095614.EXE/data0002 Infected: Trojan-Downloader.Win32.Agent.jdz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095614.EXE NSIS: infected - 3 skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095656.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095658.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095915.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095917.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0095975.DLL Infected: not-a-virus:AdWare.Win32.IEHlpr.dk skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0096028.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0096030.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0096083.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\A0096085.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\snapshot\MFEX-1.DAT/data0000.bin Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\snapshot\MFEX-1.DAT EmbeddedEXE: infected - 1 skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP412\snapshot\MFEX-1.DAT PE_Patch: infected - 1 skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096141.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096143.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096212.EXE/data0002/data0000.bin Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096212.EXE/data0002 Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096212.EXE NSIS: infected - 2 skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096311.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096313.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096368.DLL Infected: not-a-virus:AdWare.Win32.IEHlpr.ds skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096375.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096377.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096391.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096393.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096451.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096453.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096486.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096488.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096551.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096553.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096640.DLL Infected: not-a-virus:AdWare.Win32.IEHlpr.fy skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096647.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096649.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096748.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096750.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096819.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096821.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096878.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096880.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096925.exe/data0000.bin Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096925.exe EmbeddedEXE: infected - 1 skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096925.exe PE_Patch: infected - 1 skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096930.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP413\A0096966.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP414\A0096987.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP415\A0097019.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0097097.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0098095.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0099095.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0100095.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0101095.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0102095.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0103095.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0104095.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0105095.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0106095.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0107095.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0108095.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0109101.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0110105.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0111105.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0112105.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0113108.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0117108.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0119152.exe Infected: not-virus:Hoax.Win32.Renos.apg skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0119157.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0121230.exe Infected: Trojan-Downloader.Win32.VB.cmg skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0121231.sys Infected: Trojan-Downloader.Win32.Hmir.qc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0121233.dll Infected: Trojan-Downloader.Win32.Agent.jrc skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0121245.exe Infected: not-virus:Hoax.Win32.Renos.apg skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0121251.exe Infected: not-virus:Hoax.Win32.Renos.apg skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0122467.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0122577.exe Infected: Trojan-Downloader.Win32.VB.chz skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\A0122579.sys Infected: Worm.Win32.Downloader.en skipped
C:\System Volume Information\_restore{5E3CC3EF-F76F-4AB0-B147-84D089A75369}\RP416\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\system32\286gf.dll Infected: Trojan-Downloader.Win32.Hmir.qe skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

Scan process completed.
A. First we must disable some of your security programs so that they do not interfere with the running of our tools:

NORTON ANTIVIRUS
Please navigate to the system tray on the bottom right hand corner and look for a [external image: Posted Image] sign.
  • right-click it -> chose "Disable Auto-Protect."
  • select a duration of 5 hours (this assures no interference with the cleanup of your pc)
  • click "Ok."
  • a popup will warn that protection will now be disabled and the sign will now look like this: [external image: Posted Image]
You succesfully disabled the Norton Antivirus Guard.


SPYWARE DOCTOR
  • Click the Spyware Doctor icon in the System Tray.
  • Click Settings.
  • Click Startup Settings under Pick a Category.
  • Uncheck "Run at Windows startup".
  • Click Apply and Exit Spyware Doctor.
  • From within Spyware Doctor, click the "OnGuard" button on the left side.
  • Uncheck "Activate OnGuard".
  • (When we are done, you can reenable Spyware Doctor)



B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\Internet Logs\xDB25.tmp
C:\WINDOWS\Internet Logs\xDB2B.tmp
C:\WINDOWS\Internet Logs\xDB24.tmp
C:\WINDOWS\Internet Logs\xDB23.tmp
C:\WINDOWS\Internet Logs\xDB22.tmp
C:\WINDOWS\Internet Logs\xDB21.tmp
C:\WINDOWS\Internet Logs\xDB20.tmp
C:\WINDOWS\Internet Logs\xDB1F.tmp
C:\WINDOWS\Internet Logs\xDB1E.tmp
C:\WINDOWS\Internet Logs\xDB1D.tmp
C:\WINDOWS\Internet Logs\xDB1B.tmp
C:\WINDOWS\Internet Logs\xDB1C.tmp
C:\WINDOWS\Internet Logs\xDB1A.tmp
C:\WINDOWS\Internet Logs\xDB19.tmp
C:\WINDOWS\Internet Logs\xDB18.tmp
C:\WINDOWS\Internet Logs\xDB17.tmp
C:\WINDOWS\Internet Logs\xDB16.tmp
C:\WINDOWS\Internet Logs\xDB15.tmp
C:\WINDOWS\Internet Logs\xDB14.tmp
C:\WINDOWS\Internet Logs\xDB13.tmp
C:\WINDOWS\Internet Logs\xDB11.tmp
C:\WINDOWS\Internet Logs\xDB12.tmp
C:\WINDOWS\Internet Logs\xDB10.tmp
C:\WINDOWS\Internet Logs\xDBF.tmp
C:\WINDOWS\Internet Logs\xDBE.tmp
C:\WINDOWS\Internet Logs\xDBD.tmp
C:\WINDOWS\Internet Logs\xDBC.tmp
C:\WINDOWS\Internet Logs\xDBA.tmp
C:\WINDOWS\Internet Logs\xDBB.tmp
C:\WINDOWS\Internet Logs\xDB9.tmp
C:\WINDOWS\Internet Logs\xDB8.tmp
C:\WINDOWS\Internet Logs\xDB7.tmp
C:\WINDOWS\Internet Logs\xDB6.tmp
C:\WINDOWS\Internet Logs\xDB5.tmp
C:\WINDOWS\Internet Logs\xDB4.tmp
C:\WINDOWS\Internet Logs\xDB3.tmp
C:\WINDOWS\Internet Logs\xDB2.tmp
C:\WINDOWS\Internet Logs\xDB1.tmp
C:\Program Files\Microsoft Office\SYSTEM\dodolook_7456.exe
C:\WINDOWS\system32\286gf.dll
C:\WINDOWS\Internet Logs\xDB3A.tmp
C:\WINDOWS\Internet Logs\xDB39.tmp
C:\WINDOWS\Internet Logs\xDB38.tmp
C:\WINDOWS\Internet Logs\xDB37.tmp
C:\WINDOWS\Internet Logs\xDB36.tmp
C:\WINDOWS\Internet Logs\xDB35.tmp
C:\WINDOWS\Internet Logs\xDB34.tmp
C:\WINDOWS\Internet Logs\xDB33.tmp
C:\WINDOWS\Internet Logs\xDB32.tmp
C:\WINDOWS\Internet Logs\xDB31.tmp
C:\WINDOWS\Internet Logs\xDB30.tmp
C:\WINDOWS\Internet Logs\xDB2F.tmp
C:\WINDOWS\Internet Logs\xDB2E.tmp
C:\WINDOWS\Internet Logs\xDB2D.tmp
C:\WINDOWS\Internet Logs\xDB2C.tmp
C:\WINDOWS\Internet Logs\xDB2A.tmp
C:\WINDOWS\Internet Logs\xDB29.tmp
C:\WINDOWS\Internet Logs\xDB28.tmp
C:\WINDOWS\Internet Logs\xDB27.tmp
C:\WINDOWS\Internet Logs\xDB26.tmp

Folder::
C:\Program Files\Common Files\DriveCleaner 2006 Free
C:\Program Files\MalwareAlarm

Driver::
4yj94j6b3
32veqjw7os
C5019
ntptdb
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi :)

Here's the new hijackthis Log and ComboFix Text

Logfile of HijackThis v1.99.1
Scan saved at 23:29, on 2008-03-19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: del.icio.us Toolbar Helper - {7AA07AE6-01EF-44EC-93CA-9D7CD41CCDB6} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: del.icio.us - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-SG/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1149523250647
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149543421608
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/chainz2/sis/mjolauncher.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

——————- COMBO FIX ————————

ComboFix 08-03-14.4 - Chris Ow 2008-03-19 23:07:56.5 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.328 [GMT 8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Chris Ow\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Program Files\Microsoft Office\SYSTEM\dodolook_7456.exe
C:\WINDOWS\Internet Logs\xDB1.tmp
C:\WINDOWS\Internet Logs\xDB10.tmp
C:\WINDOWS\Internet Logs\xDB11.tmp
C:\WINDOWS\Internet Logs\xDB12.tmp
C:\WINDOWS\Internet Logs\xDB13.tmp
C:\WINDOWS\Internet Logs\xDB14.tmp
C:\WINDOWS\Internet Logs\xDB15.tmp
C:\WINDOWS\Internet Logs\xDB16.tmp
C:\WINDOWS\Internet Logs\xDB17.tmp
C:\WINDOWS\Internet Logs\xDB18.tmp
C:\WINDOWS\Internet Logs\xDB19.tmp
C:\WINDOWS\Internet Logs\xDB1A.tmp
C:\WINDOWS\Internet Logs\xDB1B.tmp
C:\WINDOWS\Internet Logs\xDB1C.tmp
C:\WINDOWS\Internet Logs\xDB1D.tmp
C:\WINDOWS\Internet Logs\xDB1E.tmp
C:\WINDOWS\Internet Logs\xDB1F.tmp
C:\WINDOWS\Internet Logs\xDB2.tmp
C:\WINDOWS\Internet Logs\xDB20.tmp
C:\WINDOWS\Internet Logs\xDB21.tmp
C:\WINDOWS\Internet Logs\xDB22.tmp
C:\WINDOWS\Internet Logs\xDB23.tmp
C:\WINDOWS\Internet Logs\xDB24.tmp
C:\WINDOWS\Internet Logs\xDB25.tmp
C:\WINDOWS\Internet Logs\xDB26.tmp
C:\WINDOWS\Internet Logs\xDB27.tmp
C:\WINDOWS\Internet Logs\xDB28.tmp
C:\WINDOWS\Internet Logs\xDB29.tmp
C:\WINDOWS\Internet Logs\xDB2A.tmp
C:\WINDOWS\Internet Logs\xDB2B.tmp
C:\WINDOWS\Internet Logs\xDB2C.tmp
C:\WINDOWS\Internet Logs\xDB2D.tmp
C:\WINDOWS\Internet Logs\xDB2E.tmp
C:\WINDOWS\Internet Logs\xDB2F.tmp
C:\WINDOWS\Internet Logs\xDB3.tmp
C:\WINDOWS\Internet Logs\xDB30.tmp
C:\WINDOWS\Internet Logs\xDB31.tmp
C:\WINDOWS\Internet Logs\xDB32.tmp
C:\WINDOWS\Internet Logs\xDB33.tmp
C:\WINDOWS\Internet Logs\xDB34.tmp
C:\WINDOWS\Internet Logs\xDB35.tmp
C:\WINDOWS\Internet Logs\xDB36.tmp
C:\WINDOWS\Internet Logs\xDB37.tmp
C:\WINDOWS\Internet Logs\xDB38.tmp
C:\WINDOWS\Internet Logs\xDB39.tmp
C:\WINDOWS\Internet Logs\xDB3A.tmp
C:\WINDOWS\Internet Logs\xDB4.tmp
C:\WINDOWS\Internet Logs\xDB5.tmp
C:\WINDOWS\Internet Logs\xDB6.tmp
C:\WINDOWS\Internet Logs\xDB7.tmp
C:\WINDOWS\Internet Logs\xDB8.tmp
C:\WINDOWS\Internet Logs\xDB9.tmp
C:\WINDOWS\Internet Logs\xDBA.tmp
C:\WINDOWS\Internet Logs\xDBB.tmp
C:\WINDOWS\Internet Logs\xDBC.tmp
C:\WINDOWS\Internet Logs\xDBD.tmp
C:\WINDOWS\Internet Logs\xDBE.tmp
C:\WINDOWS\Internet Logs\xDBF.tmp
C:\WINDOWS\system32\286gf.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Common Files\DriveCleaner 2006 Free
C:\Program Files\Common Files\DriveCleaner 2006 Free\udcpas.exe
C:\Program Files\Common Files\DriveCleaner 2006 Free\udcsdr.exe
C:\Program Files\MalwareAlarm
C:\Program Files\MalwareAlarm\MalwareAlarm.exe
C:\Program Files\MalwareAlarm\MalwareAlarm.lic
C:\Program Files\MalwareAlarm\MalwareAlarm0.dll
C:\Program Files\MalwareAlarm\MalwareAlarm0.ma
C:\Program Files\MalwareAlarm\MalwareAlarm1.dll
C:\Program Files\MalwareAlarm\MalwareAlarm1.ma
C:\Program Files\MalwareAlarm\MalwareAlarm3.dll
C:\Program Files\MalwareAlarm\routines.dll
C:\Program Files\MalwareAlarm\Uninstall.exe
C:\Program Files\Microsoft Office\SYSTEM\dodolook_7456.exe
C:\WINDOWS\Internet Logs\xDB1.tmp
C:\WINDOWS\Internet Logs\xDB10.tmp
C:\WINDOWS\Internet Logs\xDB11.tmp
C:\WINDOWS\Internet Logs\xDB12.tmp
C:\WINDOWS\Internet Logs\xDB13.tmp
C:\WINDOWS\Internet Logs\xDB14.tmp
C:\WINDOWS\Internet Logs\xDB15.tmp
C:\WINDOWS\Internet Logs\xDB16.tmp
C:\WINDOWS\Internet Logs\xDB17.tmp
C:\WINDOWS\Internet Logs\xDB18.tmp
C:\WINDOWS\Internet Logs\xDB19.tmp
C:\WINDOWS\Internet Logs\xDB1A.tmp
C:\WINDOWS\Internet Logs\xDB1B.tmp
C:\WINDOWS\Internet Logs\xDB1C.tmp
C:\WINDOWS\Internet Logs\xDB1D.tmp
C:\WINDOWS\Internet Logs\xDB1E.tmp
C:\WINDOWS\Internet Logs\xDB1F.tmp
C:\WINDOWS\Internet Logs\xDB2.tmp
C:\WINDOWS\Internet Logs\xDB20.tmp
C:\WINDOWS\Internet Logs\xDB21.tmp
C:\WINDOWS\Internet Logs\xDB22.tmp
C:\WINDOWS\Internet Logs\xDB23.tmp
C:\WINDOWS\Internet Logs\xDB24.tmp
C:\WINDOWS\Internet Logs\xDB25.tmp
C:\WINDOWS\Internet Logs\xDB26.tmp
C:\WINDOWS\Internet Logs\xDB27.tmp
C:\WINDOWS\Internet Logs\xDB28.tmp
C:\WINDOWS\Internet Logs\xDB29.tmp
C:\WINDOWS\Internet Logs\xDB2A.tmp
C:\WINDOWS\Internet Logs\xDB2B.tmp
C:\WINDOWS\Internet Logs\xDB2C.tmp
C:\WINDOWS\Internet Logs\xDB2D.tmp
C:\WINDOWS\Internet Logs\xDB2E.tmp
C:\WINDOWS\Internet Logs\xDB2F.tmp
C:\WINDOWS\Internet Logs\xDB3.tmp
C:\WINDOWS\Internet Logs\xDB30.tmp
C:\WINDOWS\Internet Logs\xDB31.tmp
C:\WINDOWS\Internet Logs\xDB32.tmp
C:\WINDOWS\Internet Logs\xDB33.tmp
C:\WINDOWS\Internet Logs\xDB34.tmp
C:\WINDOWS\Internet Logs\xDB35.tmp
C:\WINDOWS\Internet Logs\xDB36.tmp
C:\WINDOWS\Internet Logs\xDB37.tmp
C:\WINDOWS\Internet Logs\xDB38.tmp
C:\WINDOWS\Internet Logs\xDB39.tmp
C:\WINDOWS\Internet Logs\xDB3A.tmp
C:\WINDOWS\Internet Logs\xDB4.tmp
C:\WINDOWS\Internet Logs\xDB5.tmp
C:\WINDOWS\Internet Logs\xDB6.tmp
C:\WINDOWS\Internet Logs\xDB7.tmp
C:\WINDOWS\Internet Logs\xDB8.tmp
C:\WINDOWS\Internet Logs\xDB9.tmp
C:\WINDOWS\Internet Logs\xDBA.tmp
C:\WINDOWS\Internet Logs\xDBB.tmp
C:\WINDOWS\Internet Logs\xDBC.tmp
C:\WINDOWS\Internet Logs\xDBD.tmp
C:\WINDOWS\Internet Logs\xDBE.tmp
C:\WINDOWS\Internet Logs\xDBF.tmp
C:\WINDOWS\system32\286gf.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\LEGACY_32VEQJW7OS
——-\LEGACY_4YJ94J6B3
——-\LEGACY_C5019
——-\LEGACY_NTPTDB
——-\32veqjw7os
——-\4yj94j6b3
——-\C5019
——-\ntptdb


((((((((((((((((((((((((( Files Created from 2008-02-19 to 2008-03-19 )))))))))))))))))))))))))))))))
.

2008-03-18 21:15 . 2008-03-18 21:15 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-03-18 21:15 . 2008-03-18 21:15 d——– C:\WINDOWS\LastGood.Tmp
2008-03-18 21:15 . 2008-03-18 21:15 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-16 23:08 . 2008-03-16 23:44 d——– C:\Program Files\Spyware Doctor
2008-03-16 23:08 . 2008-03-19 23:22 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-16 23:08 . 2008-03-16 23:08 d——– C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-03-16 23:08 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-16 23:08 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-16 23:08 . 2008-02-01 12:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-16 23:08 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-03-16 22:12 . 2008-03-16 22:14 1,272,856 –a—— C:\Install
2008-03-16 22:03 . 2005-08-27 02:38 1,435,272 –a—— C:\WINDOWS\system32\Flash.ocx
2008-03-16 22:03 . 2003-11-19 13:59 512,688 –a—— C:\WINDOWS\system32\XceedCry.dll
2008-03-16 22:03 . 2004-05-11 09:56 423,784 –a—— C:\WINDOWS\system32\XceedBkp.dll
2008-03-16 22:03 . 2004-02-05 20:53 389,120 –a—— C:\WINDOWS\system32\ACTSKN43.OCX
2008-03-16 22:03 . 2004-01-09 10:54 188,416 –a—— C:\WINDOWS\system32\actsplash.ocx
2008-03-16 22:03 . 2004-03-08 23:00 131,856 –a—— C:\WINDOWS\system32\MSADODC.ocx
2008-03-16 22:03 . 2000-07-15 05:00 101,888 –a—— C:\WINDOWS\system32\VB6STKIT.DLL
2008-03-16 22:03 . 2001-03-28 22:02 89,088 –a—— C:\WINDOWS\system32\ProgressBar4.ocx
2008-03-16 22:03 . 1999-01-26 19:36 11,012 –a—— C:\WINDOWS\system32\threadapi.tlb
2008-03-16 20:55 . 2008-03-16 20:55 d—s—- C:\Documents and Settings\Administrator\UserData

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-15 12:53 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-12 10:49 ——— d—–w C:\Documents and Settings\Chris Ow\Application Data\uTorrent
2008-03-10 10:19 13,195 —-a-w C:\Documents and Settings\SoM 3\ZGUICFGW.DAT
2008-02-06 18:02 ——— d—–w C:\Program Files\PayPerView Lessons Modulation Tips and Tricks Vol 1
2008-02-06 17:50 737,280 —-a-w C:\WINDOWS\iun6002.exe
2008-02-06 17:50 ——— d—–w C:\Program Files\PlayPianoTODAY
2008-01-19 16:58 ——— d—–w C:\Program Files\iTunes
2008-01-19 16:57 ——— d—–w C:\Program Files\iPod
2008-01-19 16:54 ——— d—–w C:\Program Files\QuickTime
2008-01-07 16:18 20,541 —-a-w C:\WINDOWS\system32\detoured.dll
2007-05-06 16:02 38,712 —-a-w C:\Documents and Settings\Chris Ow\Application Data\GDIPFONTCACHEV1.DAT
2007-04-01 07:01 3,847,627 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2006-05-21 15:19 0 —-a-w C:\Documents and Settings\SoM 3\sdd1dat.dat
2001-09-30 12:43 440,832 —-a-w C:\Documents and Settings\SoM 3\ZSNESW.EXE
.

((((((((((((((((((((((((((((( snapshot@2008-03-17_19.58.00.21 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-05-24 04:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 07:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 07:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2008-03-16 15:26:52 52,764 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-03-18 12:50:33 52,764 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-03-16 15:26:52 380,350 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-03-18 12:50:33 380,350 —-a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 00:24 1694208]
"Norton SystemWorks"="C:\Program Files\Norton SystemWorks\cfgwiz.exe" [2004-09-10 10:12 132248]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-02-05 18:15 171448]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2006-03-16 11:34 755480]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2003-05-01 13:59 180316]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 17:32 58984]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-08-21 19:21 100056]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-01-20 21:10 335872]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-20 23:34 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43 83608]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2002-12-28 12:14 77824]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-06-26 01:32:15 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe [2006-02-10 07:56:20 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kavsvc.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVsvcUI.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVFW.EXE.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVMonXP.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ravtimer.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rising.exe]
Debugger=C:\WINDOWS\system32\svchost.exe

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
–a—— 2005-03-04 15:01 88209 C:\WINDOWS\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
–a—— 2004-01-20 21:10 335872 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
–a—— 2004-11-04 18:38 688218 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
–a—— 2004-11-04 18:40 98394 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Documents and Settings\\Chris Ow\\My Documents\\My Completed Downloads\\utorrent.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R3 st3bus28;st3bus28;C:\WINDOWS\system32\DRIVERS\st3bus28.sys [2002-12-28 12:16]
R3 st3mp28;st3mp28;C:\WINDOWS\system32\DRIVERS\st3mp28.sys [2002-12-28 12:16]
R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;C:\WINDOWS\system32\Drivers\WBSD.SYS [2003-03-20 17:24]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{170ad970-220a-11dc-8559-0004235b5517}]
\Shell\AutoRun\command - I:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1c5e4ea0-f5c3-11da-8323-0004235b5517}]
\Shell\AutoRun\command - ie.exe
\Shell\explore\Command - ie.exe
\Shell\open\Command - ie.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1c5e4ea2-f5c3-11da-8323-0004235b5517}]
\Shell\AutoRun\command - D:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{42439470-2ffa-11db-8373-0004235b5517}]
\Shell\AutoRun\command - G:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{51014af0-2f25-11db-8370-0004235b5517}]
\Shell\AutoRun\command - D:\setupSNK.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-16 07:11:15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-29 12:01:38 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Chris Ow.job"
- C:\PROGRA~1\NORTON~1\NORTON~3\Navw32.exeh/task:
"2007-12-31 09:12:31 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
- C:\Program Files\Norton SystemWorks\OBC.exe
"2008-03-14 16:00:00 C:\WINDOWS\Tasks\Symantec Drmc.job"
- C:\Program Files\Common Files\Symantec Shared\SymDrmc.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-19 23:22:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
.
**************************************************************************
.
Completion time: 2008-03-19 23:28:44 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-19 15:28:35
ComboFix2.txt 2008-03-18 13:09:25
ComboFix3.txt 2008-03-17 12:43:30
.
2008-03-12 16:44:52 — E O F —
So far, so good. Now please run the following scan and post the resulys along with a fresh HJT log. Note: The scan will takr about 60 minutes to run.

Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
hi :)

The Kaspersky didn't produce a report.

Here's the hijack this report

Logfile of HijackThis v1.99.1
Scan saved at 22:06, on 2008-03-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\DllHost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: del.icio.us Toolbar Helper - {7AA07AE6-01EF-44EC-93CA-9D7CD41CCDB6} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: del.icio.us - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-SG/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1149523250647
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149543421608
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/chainz2/sis/mjolauncher.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
I need a report from a powerful AntiVirus so I can see what remains onyour system. We will run with another.


I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
I hope you are well and not experiencing any difficulties carrying out my last set of instructions. If you are, do not hesitate to ask for further explanations. If however, your problem has been solved or you no longer require our assistance, please advise us accordingly and we will archive your topic.

Trevuren
Hi Trevuren, Thank you for all your help for the past week :) Sorry, i've been extremely busy at work and had no time to perform the esat online scan. I think it would be okay to close the thread as I might not have time to perform the scan :S. Thanks again ApplePears :)
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI