This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] PC running slowly & ebay wont load?

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This seems to have happened following a MSN message which was sent to me by someone on my list, but they knew nothing about it. It has also been forwarded to people on my list without my knowledge.

Since then AVG keeps picking up a LOP and trojans.

Any help would be great, thanks.

Bezz

HJT file:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:47:39, on 18/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\svchost.exe
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\AnyDVD.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\Twain_32\SlimU2TA\HotKey.exe
C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe
C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe
C:\Program Files\Notebook Hardware Control\nhc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\setup_wm.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.co.uk/
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [AnyDVD] D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\AnyDVD.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HotKey] C:\WINDOWS\Twain_32\SlimU2TA\HotKey.exe
O4 - HKLM\..\Run: [SiSRaid] C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [vspdfprsrv.exe] C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe –background
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MSN Messenger] live.messenger.com
O4 - HKLM\..\Run: [BMb72243af] Rundll32.exe "C:\WINDOWS\system32\wawqaqny.dll",s
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Ashampoo PopUpBlocker] C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Search - ?p=ZB
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Jeff\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Jeff\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Jeff\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\SCRABBLE\Images\stg_drm.ocx
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1139570309508
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\SCRABBLE\Images\armhelper.ocx
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\RpcSandraSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 10854 bytes
Hello and Welcome to the forum.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.

Open the HijackThis Folder. Find the file HijackThis.exe, Right Click on the file and Select Rename. Rename Hijackthis.exe to Spyware.exe.

Next:

Download VundoFix to your desktop

  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Hi LD,

Thanks for the quick reply.

As you can see,VundoFix didn't find any files.

I thought the contents of the AVG virus vault might be some help so have included it at the end of this reply.

The file svchst.exe also hogs up the processor, which I'm not sure what it does. If I stop it maually via task manager it seem to have no detrimental effect of the programs I am running.

Thanks,

Bezz

VundoFix V7.0.3

Scan started at 06:02:36 20/03/2008

Listing files found while scanning….

No infected files were found.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:35:28, on 20/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\AnyDVD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\Twain_32\SlimU2TA\HotKey.exe
C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe
C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe
C:\Program Files\Notebook Hardware Control\nhc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Trend Micro\HijackThis\Spyware.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.co.uk/
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: (no name) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - (no file)
O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: (no name) - {14EE2693-5D69-4BA1-8CA5-C00CD167CE2E} - C:\WINDOWS\system32\khhif.dll (file missing)
O2 - BHO: Adssite Search Assistant - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - C:\WINDOWS\system32\adssite_sidebar.dll
O2 - BHO: BrowserCmp - {1D8282E6-BC4F-469B-AAED-7E4FF077AD93} - C:\WINDOWS\system32\iebrowserc.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUp.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A0B8A2E4-0C24-4DC0-A60A-C5B3DC374B27} - C:\WINDOWS\system32\jkkhifd.dll (file missing)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {CD2EA190-5AD4-42DF-8C6F-AB3A341898BD} - C:\WINDOWS\system32\iiiig.dll
O2 - BHO: MySidesearch Search Assistant - {DDFA1356-E6ED-42a5-9D62-93211D424A90} - C:\WINDOWS\system32\mysidesearch_sidebar.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [AnyDVD] D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\AnyDVD.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HotKey] C:\WINDOWS\Twain_32\SlimU2TA\HotKey.exe
O4 - HKLM\..\Run: [SiSRaid] C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [vspdfprsrv.exe] C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe –background
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MSN Messenger] live.messenger.com
O4 - HKLM\..\Run: [BMb72243af] Rundll32.exe "C:\WINDOWS\system32\khlgihdy.dll",s
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Ashampoo PopUpBlocker] C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1708537768-1563985344-854245398-1006\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Kat')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Search - ?p=ZB
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Jeff\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Jeff\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Jeff\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\SCRABBLE\Images\stg_drm.ocx
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1139570309508
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\SCRABBLE\Images\armhelper.ocx
O20 - Winlogon Notify: jkkhifd - jkkhifd.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\RpcSandraSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 13331 bytes

"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\8A4A4YK1\ptch[1]";"19/03/2008 05:54:11";"ptch[1]";"90.5 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nsoCF.dll";"18/03/2008 12:56:10";"nsoCF.dll";"79 KB"
"";"";"Trojan horse Generic10.BFO";"C:\WINDOWS\system32\pdjnycxo.dll";"18/03/2008 12:56:10";"pdjnycxo.dll";"93 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nsm34.dll";"16/03/2008 16:04:37";"nsm34.dll";"79 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\0G0PTW7A\hctp[1]";"19/03/2008 05:55:22";"hctp[1]";"85.5 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Kat\Local Settings\Temporary Internet Files\Content.IE5\63UZE5AR\ptch[1]";"19/03/2008 16:10:53";"ptch[1]";"91 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Kat\Local Settings\Temporary Internet Files\Content.IE5\63UZE5AR\hctp[1]";"19/03/2008 16:12:49";"hctp[1]";"86.5 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nsa20.dll";"11/03/2008 05:15:12";"nsa20.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nsh315.dll";"11/03/2008 05:15:23";"nsh315.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nsuDB.dll";"11/03/2008 05:15:27";"nsuDB.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nse459.dll";"11/03/2008 05:21:54";"nse459.dll";"79 KB"
"";"";"Trojan horse Agent.IAV";"G:\XPKey.exe";"24/09/2007 07:27:41";"XPKey.exe";"48 KB"
"";"";"Trojan horse Generic10.BCI";"C:\WINDOWS\system32\jkkhifd.dll";"17/03/2008 08:52:58";"jkkhifd.dll";"36.5 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nsv47.dll";"16/03/2008 14:11:55";"nsv47.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP621\A0352108.dll";"05/03/2008 12:43:40";"A0352108.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP621\A0352109.dll";"05/03/2008 12:43:41";"A0352109.dll";"79 KB"
"";"";"Trojan horse Generic10.BKI";"C:\WINDOWS\system32\yvflugng.dll";"19/03/2008 09:22:46";"yvflugng.dll";"91.56 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nsy1E5.dll";"13/03/2008 17:32:00";"nsy1E5.dll";"79 KB"
"";"";"Virus identified Obfustat.UUU";"C:\WINDOWS\system32\drivers\ctdvda2k.sys";"31/10/2007 10:53:25";"ctdvda2k.sys";"325.78 KB"
"";"";"Trojan horse Generic10.XQ";"C:\WINDOWS\system32\khhif.dll";"14/03/2008 14:26:31";"khhif.dll";"284 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP628\A0355318.dll";"11/03/2008 13:51:40";"A0355318.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP628\A0355319.dll";"11/03/2008 13:51:40";"A0355319.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP628\A0355320.dll";"11/03/2008 13:51:41";"A0355320.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP628\A0355321.dll";"11/03/2008 13:51:41";"A0355321.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nsc6E.dll";"01/03/2008 18:33:26";"nsc6E.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP602\A0344753.dll";"04/03/2008 12:52:41";"A0344753.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP603\A0344791.dll";"04/03/2008 12:52:42";"A0344791.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP606\A0345022.dll";"04/03/2008 12:52:42";"A0345022.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP608\A0345054.dll";"04/03/2008 12:52:43";"A0345054.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP609\A0345097.dll";"04/03/2008 12:52:43";"A0345097.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP610\A0345117.dll";"04/03/2008 12:52:45";"A0345117.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP610\A0346170.dll";"04/03/2008 12:52:46";"A0346170.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP612\A0346299.dll";"04/03/2008 12:52:46";"A0346299.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP613\A0346376.dll";"04/03/2008 12:52:47";"A0346376.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP614\A0346402.dll";"04/03/2008 12:52:47";"A0346402.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP616\A0349751.dll";"04/03/2008 12:52:48";"A0349751.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP617\A0349768.dll";"04/03/2008 12:52:49";"A0349768.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP618\A0349815.dll";"04/03/2008 12:52:50";"A0349815.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP618\A0350849.dll";"04/03/2008 12:52:51";"A0350849.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nse128.dll";"04/03/2008 12:52:51";"nse128.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nszC5.dll";"04/03/2008 12:52:52";"nszC5.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nse34.dll";"12/03/2008 17:11:10";"nse34.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nsxAE.dll";"11/03/2008 16:33:52";"nsxAE.dll";"79 KB"
"";"";"Trojan horse Dropper.Generic.WDF";"C:\WINDOWS\live.messenger.com";"14/03/2008 20:39:59";"live.messenger.com";"136.5 KB"
"";"";"Trojan horse Dropper.Generic.WDF";"C:\Documents and Settings\Jeff\Desktop\PIC006.JPG-live.messenger.com";"14/03/2008 20:40:01";"PIC006.JPG-live.messenger.com";"136.5 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\052JS16F\hctp[1]";"14/03/2008 20:40:01";"hctp[1]";"84 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\A36HFJ0L\ptch[1]";"14/03/2008 20:40:02";"ptch[1]";"92.5 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nsf8A.dll";"14/03/2008 20:40:04";"nsf8A.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nsc134.dll";"17/03/2008 20:27:10";"nsc134.dll";"79 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nsx529.dll";"08/03/2008 05:25:25";"nsx529.dll";"79 KB"
"";"";"Trojan horse Dropper.Generic.WDF";"C:\WINDOWS\live.messenger.com";"14/03/2008 02:31:37";"live.messenger.com";"136.5 KB"
"";"";"Trojan horse Dropper.Generic.WDF";"C:\Documents and Settings\Jeff\Desktop\PIC006.JPG-live.messenger.com";"14/03/2008 02:31:38";"PIC006.JPG-live.messenger.com";"136.5 KB"
"";"";"Virus found Win32/PolyCrypt";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\052JS16F\CA6VS90L";"14/03/2008 02:31:39";"CA6VS90L";"285.44 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\052JS16F\CA73EX32";"14/03/2008 02:31:39";"CA73EX32";"313 KB"
"";"";"Trojan horse Generic10.XQ";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\A36HFJ0L\CA2H4JWB";"14/03/2008 02:31:41";"CA2H4JWB";"283.94 KB"
"";"";"Virus found Win32/PolyCrypt";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\A36HFJ0L\CA9PFZ7N";"14/03/2008 02:31:41";"CA9PFZ7N";"285.44 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\A36HFJ0L\CAERW5E7";"14/03/2008 02:31:42";"CAERW5E7";"316.53 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\A36HFJ0L\CAH3X1CU";"14/03/2008 02:31:43";"CAH3X1CU";"316.53 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\A36HFJ0L\CAHM73L6";"14/03/2008 02:31:45";"CAHM73L6";"316.53 KB"
"";"";"Virus found Win32/PolyCrypt";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\A36HFJ0L\CAIDGX08";"14/03/2008 02:31:46";"CAIDGX08";"285.44 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\A36HFJ0L\CAS5E3KB";"14/03/2008 02:31:46";"CAS5E3KB";"316.53 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\C7ELWHY1\CA215LC6";"14/03/2008 02:31:47";"CA215LC6";"316.53 KB"
"";"";"Virus found Win32/PolyCrypt";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\C7ELWHY1\CAUJCDYV";"14/03/2008 02:31:48";"CAUJCDYV";"285.44 KB"
"";"";"Virus found Win32/PolyCrypt";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\SYJQMJL5\CAMBW1MN";"14/03/2008 02:31:49";"CAMBW1MN";"285.44 KB"
"";"";"Virus found Win32/PolyCrypt";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\SYJQMJL5\CAQF8D2F";"14/03/2008 02:31:50";"CAQF8D2F";"285.44 KB"
"";"";"Virus found Win32/PolyCrypt";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\SYJQMJL5\CAQJSHAR";"14/03/2008 02:31:50";"CAQJSHAR";"285.44 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\SYJQMJL5\CARUIHRJ";"14/03/2008 02:31:51";"CARUIHRJ";"316.53 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\SYJQMJL5\is151786[1].exe";"14/03/2008 02:31:51";"is151786[1].exe";"52 KB"
"";"";"Trojan horse Generic9.ZSR";"C:\Documents and Settings\Jeff\Desktop\Downloads\Setup.exe";"29/11/2007 10:53:28";"Setup.exe";"848 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\SYJQMJL5\ptch[1]";"15/03/2008 12:04:22";"ptch[1]";"96 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\SYJQMJL5\hctp[1]";"15/03/2008 12:06:30";"hctp[1]";"92 KB"
"";"";"Trojan horse NaviPromo.N";"C:\WINDOWS\system32\nst1AF.dll";"04/03/2008 21:53:31";"nst1AF.dll";"79 KB"
"";"";"Trojan horse Downloader.Small.58.AG";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\91B6JHF1\click[1].htm";"26/03/2007 11:09:07";"click[1].htm";"1.97 KB"
"";"";"Virus identified Exploit";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\91B6JHF1\popup_code[1].htm";"26/03/2007 11:09:08";"popup_code[1].htm";"6.67 KB"
"";"";"Virus found Win32/PolyCrypt";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\052JS16F\CASBQB6N";"14/03/2008 08:48:10";"CASBQB6N";"285.44 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\052JS16F\ptch[1]";"14/03/2008 08:48:11";"ptch[1]";"91.5 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\C7ELWHY1\CA0YUZK6";"14/03/2008 08:48:12";"CA0YUZK6";"316.53 KB"
"";"";"Virus found Win32/PolyCrypt";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\C7ELWHY1\hctp[1]";"14/03/2008 08:48:12";"hctp[1]";"84 KB"
"";"";"Virus found Lop";"C:\windows.exe";"13/03/2008 08:04:41";"windows.exe";"52 KB"
"";"";"Virus identified Exploit";"C:\Documents and Settings\Jeff\Local Settings\Application Data\Mozilla\Firefox\Profiles\2zctvnpk.default\Cache\8093380Ad01";"24/02/2008 09:04:35";"8093380Ad01";"21.91 KB"
"";"";"Trojan horse Generic10.XQ";"C:\WINDOWS\system32\khhif.dll";"13/03/2008 08:43:17";"khhif.dll";"284 KB"
"";"";"Virus found Lop";"C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\SYJQMJL5\CABJMBNZ";"13/03/2008 09:07:43";"CABJMBNZ";"316.53 KB"
"";"";"Virus identified Worm/VB.AUG";"C:\Documents and Settings\Jeff\Desktop\Downloads\Firefox Setup 1.5.0.1.exe";"12/03/2007 11:09:57";"Firefox Setup 1.5.0.1.exe";"4.94 MB"
"";"";"Virus identified Worm/VB.AUG";"C:\Em's C drive contents\Documents and Settings\Em\Desktop\Unused Desktop Shortcuts\Firefox Setup 1.0.7.exe";"12/03/2007 11:10:00";"Firefox Setup 1.0.7.exe";"4.6 MB"
"";"";"Virus identified Worm/VB.AUG";"C:\Em's C drive contents\Program Files\Firefox\Firefox Setup 1.0.4.exe";"12/03/2007 11:10:05";"Firefox Setup 1.0.4.exe";"112.32 KB"
"";"";"Virus identified Worm/VB.AUG";"C:\Program Files\C-Media\WIN_ME\Firefox Setup 1.5.0.1.exe";"12/03/2007 11:10:06";"Firefox Setup 1.5.0.1.exe";"4.94 MB"
"";"";"Trojan horse Agent.IAV";"C:\Documents and Settings\Jeff\My Documents\My Music\_Microsoft Windows Key Gen. 2003 or XP Pro or Office-XP keygen(1)\XPKey.exe";"23/09/2007 10:35:09";"XPKey.exe";"48 KB"
"";"";"Trojan horse Agent.IAV";"C:\Documents and Settings\Jeff\My Documents\My Music\_Microsoft Windows Key Gen. 2003 or XP Pro or Office-XP keygen(1).zip";"23/09/2007 10:36:05";"_Microsoft Windows Key Gen. 2003 or XP Pro or Office-XP keygen(1).zip";"20.27 KB"
"";"";"Trojan horse Flooder.AKE";"C:\RECYCLER\S-1-5-21-1708537768-1563985344-854245398-1003\Dc30.bak";"07/12/2006 10:38:34";"Dc30.bak";"420 KB"
"";"";"Trojan horse Flooder.AKE";"C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe";"07/12/2006 10:38:35";"winlogon.exe";"420 KB"
"";"";"Trojan horse Generic.LKW";"F:\System Volume Information\_restore{A60E6F18-C0F1-49D4-BA92-1E511B898365}\RP106\A0023040.sys";"16/12/2005 09:47:07";"A0023040.sys";"303.84 KB"
"";"";"Trojan horse PSW.Generic2.LHN";"E:\Documents and Settings\Jeff\My Documents\Downloads\CloneDVD2_ 2.0.5.3.+ Keygen\keygen.exe";"19/10/2006 10:49:23";"keygen.exe";"41.5 KB"
"";"";"Trojan horse Downloader.Delf.5.AU";"F:\Documents and Settings\Em\Local Settings\Temp\atiupdate.exe";"22/10/2005 17:54:03";"atiupdate.exe";"48 KB"
"";"";"Trojan horse Downloader.Delf.5.AU";"F:\Documents and Settings\Em\Local Settings\Temp\msshed32.exe";"22/10/2005 17:54:03";"msshed32.exe";"48 KB"
"";"";"Trojan horse Generic.APC";"F:\Documents and Settings\Em\Local Settings\Temp\orx3e.exe";"22/10/2005 17:54:03";"orx3e.exe";"205.96 KB"
"";"";"Trojan horse Generic.COF";"F:\Documents and Settings\Jeff\Local Settings\Temp\temp.fr4FEA";"22/10/2005 17:54:03";"temp.fr4FEA";"468.56 KB"
"";"";"Trojan horse Startpage.15.BT";"F:\Program Files\Torrent Search IE Toolbar\torrent_search.dll";"22/10/2005 17:54:03";"torrent_search.dll";"488 KB"
"";"";"Trojan horse Downloader.Delf.5.Z";"F:\WINDOWS\system32\msshed32.exe";"22/10/2005 17:54:03";"msshed32.exe";"40.5 KB"
"";"";"Virus identified Obfustat.UUU";"D:\WINDOWS\system32\drivers\ctdvda2k.sys";"31/10/2007 10:53:26";"ctdvda2k.sys";"325.78 KB"
"";"";"Trojan horse Generic.DZM";"F:\System Volume Information\_restore{A60E6F18-C0F1-49D4-BA92-1E511B898365}\RP67\A0015099.exe";"26/11/2005 09:34:22";"A0015099.exe";"131.41 KB"
"";"";"Trojan horse Generic.DZO";"F:\System Volume Information\_restore{A60E6F18-C0F1-49D4-BA92-1E511B898365}\RP67\A0015100.dll";"26/11/2005 09:34:22";"A0015100.dll";"329.23 KB"
"";"";"Trojan horse Generic.LKW";"F:\Documents and Settings\Jeff\Local Settings\Temp\jwz.sys";"15/12/2005 09:41:27";"jwz.sys";"303.84 KB"
"";"";"Trojan horse Generic.LKW";"F:\System Volume Information\_restore{A60E6F18-C0F1-49D4-BA92-1E511B898365}\RP105\A0022940.sys";"15/12/2005 09:41:27";"A0022940.sys";"172 KB"
"";"";"Trojan horse Generic.LKW";"F:\System Volume Information\_restore{A60E6F18-C0F1-49D4-BA92-1E511B898365}\RP105\A0022941.exe";"15/12/2005 09:41:27";"A0022941.exe";"229.79 KB"
"";"";"Trojan horse Generic.LKW";"F:\System Volume Information\_restore{A60E6F18-C0F1-49D4-BA92-1E511B898365}\RP105\A0022942.sys";"15/12/2005 09:41:27";"A0022942.sys";"242.54 KB"
"";"";"Trojan horse Generic.LKW";"F:\System Volume Information\_restore{A60E6F18-C0F1-49D4-BA92-1E511B898365}\RP105\A0022943.exe";"15/12/2005 09:41:27";"A0022943.exe";"159.5 KB"
"";"";"Virus identified I-Worm/Stration.DSU";"D:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP413\A0271346.exe";"11/07/2007 10:58:01";"A0271346.exe";"2.5 MB"
"";"";"Virus identified I-Worm/Stration.DSU";"D:\System Volume Information\_restore{DE5A4E44-9DED-4BDE-8CF0-2A0B6030F05C}\RP413\A0271347.exe";"11/07/2007 10:58:02";"A0271347.exe";"2.5 MB"
"";"";"Virus identified I-Worm/Stration.DSU";"D:\Documents and Settings\All Users.WINDOWS\Documents\My Music\My Playlists\ringtone\Mobile Music Polyphonic 1.5 + Serial convert midi and mp3 to mmf ringtones.zip";"10/07/2007 11:04:23";"Mobile Music Polyphonic 1.5 + Serial convert midi and mp3 to mmf ringtones.zip";"2.52 MB"
"";"";"Virus identified I-Worm/Stration.DSU";"D:\Documents and Settings\Jeff\Desktop\Unused Desktop Shortcuts\mmply130.exe";"10/07/2007 11:04:24";"mmply130.exe";"2.5 MB"
"";"";"Virus identified I-Worm/Stration.DSU";"D:\Documents and Settings\Jeff\My Documents\Downloads\all4mmp.exe";"10/07/2007 11:04:25";"all4mmp.exe";"2.5 MB"
"";"";"Virus identified I-Worm/Stration.DSU";"D:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP398\A0173510.exe";"10/07/2007 11:04:26";"A0173510.exe";"2.5 MB"
"";"";"Trojan horse Generic.DZM";"F:\WINDOWS\system32\251xxpw.exe";"25/11/2005 09:33:53";"251xxpw.exe";"131.41 KB"
"";"";"Trojan horse Generic.DZO";"F:\WINDOWS\system32\aa04j7.dll";"25/11/2005 09:33:54";"aa04j7.dll";"329.23 KB"
"";"";"Trojan horse Generic.LKW";"F:\WINDOWS\jwz.sys";"14/12/2005 09:52:14";"jwz.sys";"172 KB"
"";"";"Trojan horse Generic.LKW";"F:\WINDOWS\system32\ehf8hqz.exe";"14/12/2005 09:52:14";"ehf8hqz.exe";"229.79 KB"
"";"";"Trojan horse Generic.LKW";"F:\WINDOWS\system32\jwz.sys";"14/12/2005 09:52:14";"jwz.sys";"242.54 KB"
"";"";"Trojan horse Generic.LKW";"F:\WINDOWS\system32\mirindaspk.exe";"14/12/2005 09:52:14";"mirindaspk.exe";"159.5 KB"
"";"";"Trojan horse Downloader.Delf.5.AU";"F:\System Volume Information\_restore{A60E6F18-C0F1-49D4-BA92-1E511B898365}\RP2\A0004664.exe";"23/10/2005 09:20:11";"A0004664.exe";"48 KB"
"";"";"Trojan horse Downloader.Delf.5.AU";"F:\System Volume Information\_restore{A60E6F18-C0F1-49D4-BA92-1E511B898365}\RP2\A0004665.exe";"23/10/2005 09:20:12";"A0004665.exe";"48 KB"
"";"";"Trojan horse Generic.APC";"F:\System Volume Information\_restore{A60E6F18-C0F1-49D4-BA92-1E511B898365}\RP2\A0004666.exe";"23/10/2005 09:20:12";"A0004666.exe";"205.96 KB"
"";"";"Trojan horse Startpage.15.BT";"F:\System Volume Information\_restore{A60E6F18-C0F1-49D4-BA92-1E511B898365}\RP2\A0004667.dll";"23/10/2005 09:20:12";"A0004667.dll";"488 KB"
"";"";"Trojan horse Downloader.Delf.5.Z";"F:\System Volume Information\_restore{A60E6F18-C0F1-49D4-BA92-1E511B898365}\RP2\A0004668.exe";"23/10/2005 09:20:12";"A0004668.exe";"40.5 KB"
"";"";"Trojan horse Generic.BNS";"F:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP412\A0177687.exe";"23/10/2005 09:20:12";"A0177687.exe";"169.5 KB"
"";"";"Trojan horse Generic.LO";"F:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP412\A0177693.sys";"23/10/2005 09:20:12";"A0177693.sys";"269.35 KB"
"";"";"Trojan horse Kolweb.B";"F:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP412\A0177694.dll";"23/10/2005 09:20:12";"A0177694.dll";"516 KB"
"";"";"Trojan horse Generic.APD";"F:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP412\A0177695.exe";"23/10/2005 09:20:12";"A0177695.exe";"149 KB"
"";"";"Trojan horse Generic.LO";"F:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP412\A0177696.sys";"23/10/2005 09:20:12";"A0177696.sys";"303.32 KB"
"";"";"Trojan horse Generic.LO";"F:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP412\A0177697.exe";"23/10/2005 09:20:13";"A0177697.exe";"327.66 KB"
"";"";"Trojan horse Generic.BNS";"F:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP412\A0177713.exe";"23/10/2005 09:20:13";"A0177713.exe";"169.5 KB"
"";"";"Trojan horse Generic.BNS";"F:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP412\A0177714.exe";"23/10/2005 09:20:13";"A0177714.exe";"169.5 KB"
"";"";"Trojan horse Generic.COF";"F:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP419\A0180859.dll";"23/10/2005 09:20:13";"A0180859.dll";"534.21 KB"
"";"";"Trojan horse Generic.COF";"F:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP422\A0184035.dll";"23/10/2005 09:20:13";"A0184035.dll";"422.45 KB"
"";"";"Trojan horse Generic.COF";"F:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP422\A0184038.dll";"23/10/2005 09:20:13";"A0184038.dll";"468.56 KB"
"";"";"Trojan horse Generic.BNS";"F:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP445\A0212864.sys";"23/10/2005 09:20:14";"A0212864.sys";"229.96 KB"
"";"";"Trojan horse Generic.COF";"F:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP445\A0212865.dll";"23/10/2005 09:20:14";"A0212865.dll";"491.93 KB"
"";"";"Trojan horse Generic.BNS";"F:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP445\A0212867.sys";"23/10/2005 09:20:14";"A0212867.sys";"225.96 KB"
"";"";"Trojan horse Generic.BNS";"F:\System Volume Information\_restore{BD6D6C07-98AA-4642-9C15-093EA5A6BC05}\RP445\A0212868.exe";"23/10/2005 09:20:14";"A0212868.exe";"317.77 KB"
"";"";"Trojan horse Generic.YUE";"E:\b.tmp";"11/08/2006 17:36:44";"b.tmp";"266 KB"
"";"";"Virus identified Worm/VB.AUG";"D:\Documents and Settings\Jeff\Desktop\Firefox Setup 1.0.6.exe";"10/03/2007 09:54:09";"Firefox Setup 1.0.6.exe";"4.6 MB"
"";"";"Virus identified Worm/VB.AUG";"D:\Documents and Settings\Jeff\Desktop\Firefox Setup 1.0.7.exe";"10/03/2007 09:54:14";"Firefox Setup 1.0.7.exe";"4.6 MB"
"";"";"Virus identified Worm/VB.AUG";"D:\Documents and Settings\Jeff\Local Settings\Application Data\IM\Identities\{C8904E0D-9DDE-4C8E-AFFC-D86BEB9DFB1D}\Message Store\Attachments\Firefox Setup 1.0.4.exe";"10/03/2007 09:54:15";"Firefox Setup 1.0.4.exe";"4.6 MB"
"";"";"Virus identified Worm/VB.AUG";"D:\Documents and Settings\Jeff\My Documents\Downloads\Firefox Setup 1.0.4.exe";"10/03/2007 09:54:16";"Firefox Setup 1.0.4.exe";"4.6 MB"
"";"";"Virus identified Worm/VB.AUG";"D:\Documents and Settings\Jeff\My Documents\Downloads\Firefox Setup 1.0.6.exe";"10/03/2007 09:54:18";"Firefox Setup 1.0.6.exe";"4.6 MB"
"";"";"Virus identified Worm/VB.AUG";"D:\RECYCLER\S-1-5-21-1229272821-688789844-1060284298-1003\Dc8190.xpi";"10/03/2007 09:54:20";"Dc8190.xpi";"4.59 MB"
"";"";"Trojan horse PSW.Generic2.LHN";"D:\Documents and Settings\Jeff\Local Settings\Application Data\IM\Identities\{C8904E0D-9DDE-4C8E-AFFC-D86BEB9DFB1D}\Message Store\Attachments\CloneDVD2_ 2.0.5.3.+ Keygen.zip";"06/11/2006 10:49:59";"CloneDVD2_ 2.0.5.3.+ Keygen.zip";"4.2 MB"
"";"";"Trojan horse PSW.Generic2.LHN";"D:\Documents and Settings\Jeff\My Documents\Downloads\CloneDVD2_ 2.0.5.3.+ Keygen.zip";"06/11/2006 10:49:59";"CloneDVD2_ 2.0.5.3.+ Keygen.zip";"4.2 MB"
"";"";"Trojan horse PSW.Generic2.LHN";"E:\System Volume Information\_restore{FA78492E-2544-4A4D-B4B5-861FA66DFB89}\RP179\A0126046.exe";"29/10/2006 10:33:24";"A0126046.exe";"41.5 KB"
"";"";"Trojan horse Flooder.AKE";"D:\WINDOWS\$NtUninstallKB841533$\winlogon.exe";"07/12/2006 10:38:35";"winlogon.exe";"420 KB"
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hi,

My computer was superspeedy immediately after I rebooted as part of the removal process, and opening taskmanager shows that the svchost.exe that hogged 100% of the processor has gone away.

However, I closed down Firefox after ebay site failed to load (other sites worked fine) and now wont firefox won't open.

I just tried to open the mbam log to post here and it's not opening - the little egg timer has now been running for 10 mins. I can access the file via the network though so I've managed to post it.

The PC was taking 10-15 mins to boot last week and this afternoon it took about 2 mins, but now, like I say its stuck opening the mbam log.

I was re-running the malwarebytes software again and it's just returned no malicious items, and I've now re-booted.

Everything working OK apart from ebay site. I cleared the cookies and it loaded first page OK, now wont get past sign in. Has just returned the following when I tried to sign in:

'You have chosen to open eBayISAPA.dll which is a : Application Extension'

I'm not opening it. I can access it from another PC for now.

Thanks for all your efforts so far - I can see light at the end of the tunnel at least!

Bezz.
Malwarebytes' Anti-Malware 1.09
Database version: 515

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 291829
Time elapsed: 4 hour(s), 30 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 19
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\iebrowserc.dll (Adware.RightOnAds) -> No action taken.

Registry Keys Infected:
HKEY_CLASSES_ROOT\iebrowsercmp.browsercmp (Adware.RightOnAds) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{1d8282e6-bc4f-469b-aaed-7e4ff077ad93} (Adware.RightOnAds) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1d8282e6-bc4f-469b-aaed-7e4ff077ad93} (Adware.RightOnAds) -> No action taken.
HKEY_CLASSES_ROOT\iebrowsercmp.browsercmp.1 (Adware.RightOnAds) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{c1a6d8b8-93c3-4186-9dd1-13983f9f1d9b} (Adware.RightOnAds) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{3160f356-e8c3-4de2-a698-92eeeb3d3400} (Adware.RightOnAds) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IeBrowserCmp.BrowserCmp (Adware.RightOnAds) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\iebrowserc.dll (Adware.RightOnAds) -> No action taken.
C:\Program Files\MSN Messenger\riched20.dll (Adware.MyWeb.FunWeb) -> No action taken.
D:\RECYCLER\S-1-5-21-1229272821-688789844-1060284298-1003\Dc7234.frDC2D (Adware.Winad) -> No action taken.
C:\Documents and Settings\Kat\Application Data\urlredir.cfg (Adware.RightOnAds) -> No action taken.
C:\Documents and Settings\Jeff\Application Data\urlredir.cfg (Adware.RightOnAds) -> No action taken.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:56:33, on 21/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\AnyDVD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\Twain_32\SlimU2TA\HotKey.exe
C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe
C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe
C:\Program Files\Notebook Hardware Control\nhc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\Spyware.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.co.uk/
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: (no name) - {14EE2693-5D69-4BA1-8CA5-C00CD167CE2E} - C:\WINDOWS\system32\khhif.dll (file missing)
O2 - BHO: Adssite Search Assistant - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - C:\WINDOWS\system32\adssite_sidebar.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUp.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A0B8A2E4-0C24-4DC0-A60A-C5B3DC374B27} - C:\WINDOWS\system32\jkkhifd.dll (file missing)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {C7BF70AE-B074-4F14-A0EB-A5C7FF5259B1} - C:\WINDOWS\system32\iiiig.dll (file missing)
O2 - BHO: MySidesearch Search Assistant - {DDFA1356-E6ED-42a5-9D62-93211D424A90} - C:\WINDOWS\system32\mysidesearch_sidebar.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [AnyDVD] D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\AnyDVD.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HotKey] C:\WINDOWS\Twain_32\SlimU2TA\HotKey.exe
O4 - HKLM\..\Run: [SiSRaid] C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [vspdfprsrv.exe] C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe –background
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MSN Messenger] live.messenger.com
O4 - HKLM\..\Run: [BMb72243af] Rundll32.exe "C:\WINDOWS\system32\dewlhgyc.dll",s
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Ashampoo PopUpBlocker] C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Search - ?p=ZB
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Jeff\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Jeff\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Jeff\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\SCRABBLE\Images\stg_drm.ocx
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1139570309508
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\SCRABBLE\Images\armhelper.ocx
O20 - Winlogon Notify: jkkhifd - jkkhifd.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\RpcSandraSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 13047 bytes
Download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Give it atleast 20-30 minutes to finish
Hi,

PC back to slow booting (5 mins+)

SVCHOST.exe using 90%+ CPU. Wont allow me to set a lower prority.

Thanks for you help so far…


ComboFix 08-03-21.2 - Jeff 2008-03-22 10:58:37.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\adssite-remove.exe
C:\WINDOWS\system32\adssite_sidebar.dll
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\dewlhgyc.dll
C:\WINDOWS\system32\fihhk.ini
C:\WINDOWS\system32\fihhk.ini2
C:\WINDOWS\system32\giiii.ini
C:\WINDOWS\system32\giiii.ini2
C:\WINDOWS\system32\khlgihdy.dll
C:\WINDOWS\system32\krtjcumy.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\pstmveqj.dll
C:\WINDOWS\system32\rstwa.ini2
C:\WINDOWS\system32\ukfavlhw.dll
C:\WINDOWS\system32\wawqaqny.dll

.
((((((((((((((((((((((((( Files Created from 2008-02-22 to 2008-03-22 )))))))))))))))))))))))))))))))
.

2008-03-21 07:13 . 2008-03-21 07:13 d——– C:\Documents and Settings\Jeff\Application Data\Malwarebytes
2008-03-21 07:12 . 2008-03-21 07:13 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-03-21 07:12 . 2008-03-21 07:12 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-20 13:33 . 2008-03-20 13:34 d——– C:\Program Files\EmailGrabber
2008-03-20 06:02 . 2008-03-20 06:02 d——– C:\VundoFix Backups
2008-03-19 18:55 . 2008-03-19 18:55 d——– C:\Documents and Settings\Kat\Application Data\HPAppData
2008-03-18 16:47 . 2008-03-18 16:47 d——– C:\Program Files\Trend Micro
2008-03-11 04:47 . 2008-03-11 04:47 d——– C:\Program Files\Spybot - Search & Destroy
2008-03-11 04:47 . 2008-03-11 05:54 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-07 16:19 . 2008-03-22 06:42 84,729 –a—— C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
2008-03-06 11:01 . 2008-03-06 11:01 339,968 –a—— C:\WINDOWS\system32\mysidesearch_sidebar.dll
2008-03-05 15:07 . 2008-03-05 15:07 d——– C:\Program Files\Navman
2008-03-05 15:07 . 2006-09-18 13:48 30,329 –a—— C:\WINDOWS\system32\drivers\Navcar.sys
2008-03-03 04:22 . 2007-07-30 19:19 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2008-03-03 04:22 . 2007-07-30 19:19 207,736 –a—— C:\WINDOWS\system32\muweb.dll
2008-03-03 04:22 . 2007-07-30 19:19 30,072 –a—— C:\WINDOWS\system32\mucltui.dll.mui
2008-03-03 02:58 . 2008-03-04 06:53 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-03 02:57 . 2008-03-03 02:57 d——– C:\Program Files\SCRABBLE
2008-03-03 02:57 . 2008-03-03 02:57 d——– C:\Documents and Settings\Jeff\Application Data\SpinTop
2008-03-02 18:36 . 2006-11-29 13:06 3,426,072 –a—— C:\WINDOWS\system32\d3dx9_32.dll
2008-03-02 18:33 . 2008-03-02 18:33 d——– C:\Program Files\Microsoft SQL Server Compact Edition
2008-03-02 18:30 . 2008-03-02 18:32 d——– C:\Program Files\Windows Live Toolbar
2008-03-02 18:30 . 2008-03-02 18:30 d——– C:\Program Files\Windows Live Favorites
2008-03-02 18:06 . 2008-03-02 18:28 d–hsc— C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-02 18:03 . 2008-03-02 18:03 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-27 07:01 . 2003-06-26 03:56 36,867 -ra—— C:\WINDOWS\FindCD.exe
2008-02-27 07:01 . 2003-06-26 03:56 13,308 -ra—— C:\WINDOWS\system32\drivers\btxbar.sys
2008-02-27 06:59 . 2003-06-26 03:56 18,944 -ra—— C:\WINDOWS\system32\drivers\bttuner.sys
2008-02-27 06:52 . 2003-06-26 03:56 265,512 -ra—— C:\WINDOWS\system32\drivers\BT848.sys
2008-02-27 06:52 . 2003-06-26 03:56 16,376 -ra—— C:\WINDOWS\pctvlogo.bmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-22 11:38 15,251,475 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-03-22 11:37 22,528 —-a-w C:\WINDOWS\system32\drivers\nhcDriver.sys
2008-03-22 11:22 2,263,160 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-22 11:22 196,847,648 –sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-22 10:55 ——— d—–w C:\Documents and Settings\Jeff\Application Data\WholeSecurity
2008-03-22 10:14 2,483,712 —-a-w C:\WINDOWS\Internet Logs\xDBC.tmp
2008-03-22 08:00 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-21 17:32 ——— d—–w C:\Documents and Settings\Jeff\Application Data\eBay
2008-03-20 21:51 ——— d—–w C:\Documents and Settings\Kat\Application Data\WholeSecurity
2008-03-20 13:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-03-16 23:34 53,760 —-a-w C:\WINDOWS\Internet Logs\xDBB.tmp
2008-03-14 21:43 1,304,064 —-a-w C:\WINDOWS\Internet Logs\xDBA.tmp
2008-03-14 14:57 ——— d—–w C:\Documents and Settings\Jeff\Application Data\AVG7
2008-03-07 03:03 ——— d—–w C:\Program Files\Windows Live
2008-03-05 15:07 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-03-02 18:13 ——— d—–w C:\Program Files\MSN Messenger
2008-03-01 23:14 2,399,232 —-a-w C:\WINDOWS\Internet Logs\xDB13.tmp
2008-02-27 00:27 54,416 —-a-w C:\Documents and Settings\Em\Application Data\GDIPFONTCACHEV1.DAT
2008-02-19 06:51 ——— d—–w C:\Documents and Settings\Jeff\Application Data\HP
2008-02-18 21:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\WEBREG
2008-02-18 21:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-02-18 19:38 ——— d—–w C:\Program Files\HP
2008-02-18 19:38 ——— d—–w C:\Documents and Settings\Jeff\Application Data\HPAppData
2008-02-18 19:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-02-18 19:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\HP
2008-02-18 19:32 ——— d—–w C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-02-18 19:31 ——— d—–w C:\Program Files\Common Files\HP
2008-02-18 19:29 ——— d—–w C:\Program Files\Common Files\Hewlett-Packard
2008-02-15 15:54 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-02-14 11:58 54,416 —-a-w C:\Documents and Settings\Jeff\Application Data\GDIPFONTCACHEV1.DAT
2008-02-13 12:32 ——— d—–w C:\Program Files\Room Arranger
2008-02-04 18:35 ——— d—–w C:\Program Files\MSECache
2008-02-01 11:11 586,240 —-a-w C:\WINDOWS\WLXPGSS.SCR
2007-12-19 22:25 919,552 —-a-w C:\WINDOWS\Internet Logs\xDB9.tmp
2007-12-06 20:08 50,528 —-a-w C:\Documents and Settings\Kat\Application Data\GDIPFONTCACHEV1.DAT
2007-10-10 02:12 392,704 —-a-w C:\WINDOWS\Internet Logs\xDB8.tmp
2007-10-09 12:47 50,528 —-a-w C:\Documents and Settings\Sue.MAIN\Application Data\GDIPFONTCACHEV1.DAT
2007-09-25 04:17 2,172,928 —-a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2007-09-12 21:23 20,992 —-a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2007-09-12 21:04 828,928 —-a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2007-07-19 07:53 237,056 —-a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2007-06-30 09:55 1,988,608 —-a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2007-06-25 21:03 567,808 —-a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2007-05-07 20:31 663,040 —-a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2007-05-07 16:03 81,920 —-a-w C:\Documents and Settings\Jeff\Application Data\ezpinst.exe
2007-05-07 16:03 47,360 —-a-w C:\Documents and Settings\Jeff\Application Data\pcouffin.sys
2006-04-29 08:16 39,642 —-a-w C:\WINDOWS\Internet Logs\zlclient_2nd_1979_07_03_05_32_12_small.dmp.zip
2006-03-04 13:44 29,606 —-a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_03_04_13_39_45_small.dmp.zip
2006-03-04 13:44 29,227 —-a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_03_04_13_39_58_small.dmp.zip
2006-03-04 13:44 10,771,301 —-a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_03_04_13_39_22_full.dmp.zip
2001-11-23 12:08 712,704 —-a-w C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
16406-04-28 18:28 35,947 —-a-w C:\WINDOWS\Internet Logs\zlclient_2nd_1979_07_03_04_39_36_small.dmp.zip
16406-04-28 17:34 35,845 —-a-w C:\WINDOWS\Internet Logs\zlclient_2nd_1979_07_03_03_33_20_small.dmp.zip
16406-04-28 16:29 36,315 —-a-w C:\WINDOWS\Internet Logs\zlclient_2nd_1979_07_03_03_16_07_small.dmp.zip
16406-04-28 15:55 36,664 —-a-w C:\WINDOWS\Internet Logs\zlclient_2nd_1979_07_03_02_46_36_small.dmp.zip
.

——- Sigcheck ——-

2004-08-04 07:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2006-04-28 06:58 502272 32cc6d444728812f7c57f4800f779396 C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{14EE2693-5D69-4BA1-8CA5-C00CD167CE2E}]
C:\WINDOWS\system32\khhif.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C7BF70AE-B074-4F14-A0EB-A5C7FF5259B1}]
C:\WINDOWS\system32\iiiig.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DDFA1356-E6ED-42a5-9D62-93211D424A90}]
2008-03-06 11:01 339968 –a—— C:\WINDOWS\system32\mysidesearch_sidebar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2008-01-07 10:22 262144 –a—— C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL" [2008-01-07 10:22 262144]

[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-01-07 10:22 262144]

[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Ashampoo PopUpBlocker"="C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe" [2004-02-03 14:13 1216000]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 16:13 1207080]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnyDVD"="D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\AnyDVD.exe" [2004-12-07 19:21 449536]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-12-21 17:04 579072]
"HotKey"="C:\WINDOWS\Twain_32\SlimU2TA\HotKey.exe" [2004-01-06 12:02 618496]
"SiSRaid"="C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe" [2004-12-22 17:32 892928]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 10:15 106496]
"eBayToolbar"="C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe" [2008-01-19 08:53 623856]
"RemoteControl"="C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe" [2004-11-02 19:24 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 15:40 155648]
"vspdfprsrv.exe"="C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe" [2006-05-04 05:58 998912]
"NotebookHardwareControl"="C:\Program Files\Notebook Hardware Control\nhc.exe" [2007-05-04 00:33 2629632]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-20 22:18 185632]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-12 09:20 98304]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 21:34 49152]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 07:56 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-24 07:44 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 21:26:24 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkhifd]
jkkhifd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\PPMate\\PPMate\\ppmate.exe"=
"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XI\\RpcSandraSrv.exe"=
"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XI\\Win32\\RpcDataSrv.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R2 BT848;BtCap, WDM Video Capture;C:\WINDOWS\system32\drivers\BT848.sys [2003-06-26 03:56]
R2 BTTUNER;BtTuner, WDM TvTuner;C:\WINDOWS\system32\drivers\BTTUNER.sys [2003-06-26 03:56]
R2 BTXBAR;MPEG.TV, WDM Crossbar;C:\WINDOWS\system32\drivers\BTXBAR.sys [2003-06-26 03:56]
R2 HPSLPSVC;HP Network Devices Support;C:\WINDOWS\system32\svchost.exe [2004-08-04 07:56]
S2 Ca533av;Polaroid Video Camera Device;C:\WINDOWS\system32\Drivers\Ca533av.sys [2003-06-18 08:25]
S3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);C:\WINDOWS\system32\drivers\ES1370MP.sys [2001-08-17 12:19]
S3 Navcar;Navman In-car Navigator USB Driver Service;C:\WINDOWS\system32\DRIVERS\Navcar.sys [2006-09-18 13:48]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC

.
Contents of the 'Scheduled Tasks' folder
"2008-03-22 10:50:04 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-22 11:36:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
.
**************************************************************************
.
Completion time: 2008-03-22 11:47:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-22 11:47:18
.
2008-03-12 09:06:09 — E O F —


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:40:39, on 23/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\AnyDVD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\Twain_32\SlimU2TA\HotKey.exe
C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe
C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe
C:\Program Files\Notebook Hardware Control\nhc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Trend Micro\HijackThis\Spyware.exe
C:\Program Files\Windows Live Toolbar\msn_sl.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: (no name) - {14EE2693-5D69-4BA1-8CA5-C00CD167CE2E} - C:\WINDOWS\system32\khhif.dll (file missing)
O2 - BHO: (no name) - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - (no file)
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUp.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A0B8A2E4-0C24-4DC0-A60A-C5B3DC374B27} - (no file)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {C7BF70AE-B074-4F14-A0EB-A5C7FF5259B1} - C:\WINDOWS\system32\iiiig.dll (file missing)
O2 - BHO: MySidesearch Search Assistant - {DDFA1356-E6ED-42a5-9D62-93211D424A90} - C:\WINDOWS\system32\mysidesearch_sidebar.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [AnyDVD] D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\AnyDVD.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HotKey] C:\WINDOWS\Twain_32\SlimU2TA\HotKey.exe
O4 - HKLM\..\Run: [SiSRaid] C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [vspdfprsrv.exe] C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe –background
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MSN Messenger] live.messenger.com
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Ashampoo PopUpBlocker] C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Search - ?p=ZB
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Jeff\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Jeff\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Jeff\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\SCRABBLE\Images\stg_drm.ocx
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1139570309508
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\SCRABBLE\Images\armhelper.ocx
O20 - Winlogon Notify: jkkhifd - jkkhifd.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\RpcSandraSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 13283 bytes
Did you're infection start after you downloaded the crack for AnyDVD?


Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\khhif.dll
C:\WINDOWS\system32\iiiig.dll
C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\AnyDVD.exe
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe
C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL

Folder::
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND
C:\Program Files\AskPBar

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{14EE2693-5D69-4BA1-8CA5-C00CD167CE2E}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C7BF70AE-B074-4F14-A0EB-A5C7FF5259B1}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"=-
[-HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"=-
[-HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkhifd]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnyDVD"=-

Save this as Save this as "CFScript"


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Hi,

The virus appeared immediately after I had an MSN message "Is this really your image" with a link:

This then forwarded itself to all my friends.


Today is the first time I've been able to open MSN Messenger to retrive the message.


The anydvd program is on a slave drive that I was rescuing some photos from. According to add/remove programs it hasn't been used since March 2006.

The PC wouldn't load IE earlier but I rebooted and I've now got internet access back. Earlier I was unable to log on to my router, but other PC's were.

PC seems to be behaving normally again, but I have taken Firefox off temporarily.


ComboFix 08-03-21.2 - Jeff 2008-03-23 10:19:37.2 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jeff\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
C:\WINDOWS\system32\iiiig.dll
C:\WINDOWS\system32\khhif.dll
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\AnyDVD.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Jeff\Application Data\urlredir.cfg
C:\Documents and Settings\Sam\Application Data\urlredir.cfg
C:\Program Files\AskPBar
C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
C:\Program Files\AskPBar\bar\Cache\0018EF65
C:\Program Files\AskPBar\bar\Cache\0018F222.bin
C:\Program Files\AskPBar\bar\Cache\0018F421.bin
C:\Program Files\AskPBar\bar\Cache\0018F5D0.bin
C:\Program Files\AskPBar\bar\Cache\0018F77E.bin
C:\Program Files\AskPBar\bar\Cache\0018F9C3.bin
C:\Program Files\AskPBar\bar\Cache\042BC4FE.bin
C:\Program Files\AskPBar\bar\Cache\042BC6A2.bin
C:\Program Files\AskPBar\bar\Cache\042BC95F.bin
C:\Program Files\AskPBar\bar\Cache\042BCB0E.bin
C:\Program Files\AskPBar\bar\Cache\042BCD67.bin
C:\Program Files\AskPBar\bar\Cache\08064832
C:\Program Files\AskPBar\bar\Cache\files.ini
C:\Program Files\AskPBar\bar\History\search2
C:\Program Files\AskPBar\bar\Settings\prevcfg2.htm
C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe.zip
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\AnyDialog.dll
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\AnyDVD-uninst.ini
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\AnyDVD.exe
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\file_id.diz
D:\Documents and Settings\Jeff\My Documents\Downloads\AnyDVD.v4.3.0.1.Cracked.SND\snd-anydvd.4.3.0.1.cracked.exe\snd.nfo

.
((((((((((((((((((((((((( Files Created from 2008-02-23 to 2008-03-23 )))))))))))))))))))))))))))))))
.

2008-03-22 17:43 . 2008-03-22 17:43 d——– C:\Documents and Settings\Sam\Application Data\AdobeUM
2008-03-22 16:05 . 2008-03-22 16:05 d——– C:\Documents and Settings\Sam\Application Data\HPAppData
2008-03-21 07:13 . 2008-03-21 07:13 d——– C:\Documents and Settings\Jeff\Application Data\Malwarebytes
2008-03-21 07:12 . 2008-03-21 07:13 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-03-21 07:12 . 2008-03-21 07:12 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-20 13:33 . 2008-03-20 13:34 d——– C:\Program Files\EmailGrabber
2008-03-20 06:02 . 2008-03-20 06:02 d——– C:\VundoFix Backups
2008-03-19 18:55 . 2008-03-19 18:55 d——– C:\Documents and Settings\Kat\Application Data\HPAppData
2008-03-18 16:47 . 2008-03-18 16:47 d——– C:\Program Files\Trend Micro
2008-03-11 04:47 . 2008-03-11 04:47 d——– C:\Program Files\Spybot - Search & Destroy
2008-03-11 04:47 . 2008-03-11 05:54 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-07 16:19 . 2008-03-22 06:42 84,729 –a—— C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
2008-03-06 11:01 . 2008-03-06 11:01 339,968 –a—— C:\WINDOWS\system32\mysidesearch_sidebar.dll
2008-03-05 15:07 . 2008-03-05 15:07 d——– C:\Program Files\Navman
2008-03-05 15:07 . 2006-09-18 13:48 30,329 –a—— C:\WINDOWS\system32\drivers\Navcar.sys
2008-03-03 04:22 . 2007-07-30 19:19 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2008-03-03 04:22 . 2007-07-30 19:19 207,736 –a—— C:\WINDOWS\system32\muweb.dll
2008-03-03 04:22 . 2007-07-30 19:19 30,072 –a—— C:\WINDOWS\system32\mucltui.dll.mui
2008-03-03 02:58 . 2008-03-04 06:53 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-03 02:57 . 2008-03-03 02:57 d——– C:\Program Files\SCRABBLE
2008-03-03 02:57 . 2008-03-03 02:57 d——– C:\Documents and Settings\Jeff\Application Data\SpinTop
2008-03-02 18:36 . 2006-11-29 13:06 3,426,072 –a—— C:\WINDOWS\system32\d3dx9_32.dll
2008-03-02 18:33 . 2008-03-02 18:33 d——– C:\Program Files\Microsoft SQL Server Compact Edition
2008-03-02 18:30 . 2008-03-02 18:32 d——– C:\Program Files\Windows Live Toolbar
2008-03-02 18:30 . 2008-03-02 18:30 d——– C:\Program Files\Windows Live Favorites
2008-03-02 18:06 . 2008-03-02 18:28 d–hsc— C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-02 18:03 . 2008-03-02 18:03 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-27 07:01 . 2003-06-26 03:56 36,867 -ra—— C:\WINDOWS\FindCD.exe
2008-02-27 07:01 . 2003-06-26 03:56 13,308 -ra—— C:\WINDOWS\system32\drivers\btxbar.sys
2008-02-27 06:59 . 2003-06-26 03:56 18,944 -ra—— C:\WINDOWS\system32\drivers\bttuner.sys
2008-02-27 06:52 . 2003-06-26 03:56 265,512 -ra—— C:\WINDOWS\system32\drivers\BT848.sys
2008-02-27 06:52 . 2003-06-26 03:56 16,376 -ra—— C:\WINDOWS\pctvlogo.bmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-23 10:34 2,263,832 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-23 10:34 196,847,648 –sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-23 09:56 ——— d—–w C:\Documents and Settings\Jeff\Application Data\WholeSecurity
2008-03-23 09:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-03-23 09:50 22,528 —-a-w C:\WINDOWS\system32\drivers\nhcDriver.sys
2008-03-22 16:06 ——— d—–w C:\Documents and Settings\Sam\Application Data\WholeSecurity
2008-03-22 14:48 ——— d—–w C:\Program Files\Absolute Poker
2008-03-22 08:00 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-21 17:32 ——— d—–w C:\Documents and Settings\Jeff\Application Data\eBay
2008-03-20 21:51 ——— d—–w C:\Documents and Settings\Kat\Application Data\WholeSecurity
2008-03-14 14:57 ——— d—–w C:\Documents and Settings\Jeff\Application Data\AVG7
2008-03-07 03:03 ——— d—–w C:\Program Files\Windows Live
2008-03-05 15:07 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-03-02 18:13 ——— d—–w C:\Program Files\MSN Messenger
2008-02-27 00:27 54,416 —-a-w C:\Documents and Settings\Em\Application Data\GDIPFONTCACHEV1.DAT
2008-02-19 06:51 ——— d—–w C:\Documents and Settings\Jeff\Application Data\HP
2008-02-18 21:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\WEBREG
2008-02-18 21:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-02-18 19:38 ——— d—–w C:\Program Files\HP
2008-02-18 19:38 ——— d—–w C:\Documents and Settings\Jeff\Application Data\HPAppData
2008-02-18 19:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-02-18 19:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\HP
2008-02-18 19:32 ——— d—–w C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-02-18 19:31 ——— d—–w C:\Program Files\Common Files\HP
2008-02-18 19:29 ——— d—–w C:\Program Files\Common Files\Hewlett-Packard
2008-02-15 15:54 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-02-14 11:58 54,416 —-a-w C:\Documents and Settings\Jeff\Application Data\GDIPFONTCACHEV1.DAT
2008-02-13 12:32 ——— d—–w C:\Program Files\Room Arranger
2008-02-04 18:35 ——— d—–w C:\Program Files\MSECache
2008-02-01 11:11 586,240 —-a-w C:\WINDOWS\WLXPGSS.SCR
2007-12-06 20:08 50,528 —-a-w C:\Documents and Settings\Kat\Application Data\GDIPFONTCACHEV1.DAT
2007-10-09 12:47 50,528 —-a-w C:\Documents and Settings\Sue.MAIN\Application Data\GDIPFONTCACHEV1.DAT
2007-05-07 16:03 81,920 —-a-w C:\Documents and Settings\Jeff\Application Data\ezpinst.exe
2007-05-07 16:03 47,360 —-a-w C:\Documents and Settings\Jeff\Application Data\pcouffin.sys
.

——- Sigcheck ——-

2004-08-04 07:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2006-04-28 06:58 502272 32cc6d444728812f7c57f4800f779396 C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((( snapshot@2008-03-22_11.45.59.64 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-22 11:37:05 63,040 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-03-23 09:52:14 63,040 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-03-22 11:37:06 402,912 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-03-23 09:52:14 402,912 —-a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DDFA1356-E6ED-42a5-9D62-93211D424A90}]
2008-03-06 11:01 339968 –a—— C:\WINDOWS\system32\mysidesearch_sidebar.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Ashampoo PopUpBlocker"="C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe" [2004-02-03 14:13 1216000]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 16:13 1207080]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-12-21 17:04 579072]
"HotKey"="C:\WINDOWS\Twain_32\SlimU2TA\HotKey.exe" [2004-01-06 12:02 618496]
"SiSRaid"="C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe" [2004-12-22 17:32 892928]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 10:15 106496]
"eBayToolbar"="C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe" [2008-03-22 16:02 652528]
"RemoteControl"="C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe" [2004-11-02 19:24 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 15:40 155648]
"vspdfprsrv.exe"="C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe" [2006-05-04 05:58 998912]
"NotebookHardwareControl"="C:\Program Files\Notebook Hardware Control\nhc.exe" [2007-05-04 00:33 2629632]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-20 22:18 185632]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-12 09:20 98304]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 21:34 49152]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 07:56 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-24 07:44 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 21:26:24 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\PPMate\\PPMate\\ppmate.exe"=
"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XI\\RpcSandraSrv.exe"=
"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XI\\Win32\\RpcDataSrv.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R2 BT848;BtCap, WDM Video Capture;C:\WINDOWS\system32\drivers\BT848.sys [2003-06-26 03:56]
R2 BTTUNER;BtTuner, WDM TvTuner;C:\WINDOWS\system32\drivers\BTTUNER.sys [2003-06-26 03:56]
R2 BTXBAR;MPEG.TV, WDM Crossbar;C:\WINDOWS\system32\drivers\BTXBAR.sys [2003-06-26 03:56]
R2 HPSLPSVC;HP Network Devices Support;C:\WINDOWS\system32\svchost.exe [2004-08-04 07:56]
S2 Ca533av;Polaroid Video Camera Device;C:\WINDOWS\system32\Drivers\Ca533av.sys [2003-06-18 08:25]
S3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);C:\WINDOWS\system32\drivers\ES1370MP.sys [2001-08-17 12:19]
S3 Navcar;Navman In-car Navigator USB Driver Service;C:\WINDOWS\system32\DRIVERS\Navcar.sys [2006-09-18 13:48]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC

.
Contents of the 'Scheduled Tasks' folder
"2008-03-23 10:50:04 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-23 10:39:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2008-03-23 10:51:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-23 10:51:04
ComboFix2.txt 2008-03-22 11:47:34
.
2008-03-12 09:06:09 — E O F —

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:10:20, on 23/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\Twain_32\SlimU2TA\HotKey.exe
C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe
C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe
C:\Program Files\Notebook Hardware Control\nhc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\Spyware.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL (file missing)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUp.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: MySidesearch Search Assistant - {DDFA1356-E6ED-42a5-9D62-93211D424A90} - C:\WINDOWS\system32\mysidesearch_sidebar.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL (file missing)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HotKey] C:\WINDOWS\Twain_32\SlimU2TA\HotKey.exe
O4 - HKLM\..\Run: [SiSRaid] C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [vspdfprsrv.exe] C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe –background
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Ashampoo PopUpBlocker] C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Search - ?p=ZB
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Jeff\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Jeff\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Jeff\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\SCRABBLE\Images\stg_drm.ocx
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1139570309508
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\SCRABBLE\Images\armhelper.ocx
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\RpcSandraSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 11749 bytes
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL (file missing)
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL (file missing)
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk

Close ALL windows and browsers except HijackThis and click "Fix checked"


After the above:

Good job :thumbup:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    Here's my usual all clean post

    Log looks good :D


    You need to create a new Clean restore point.

    Note: This will remove all previous Restore Points

    Click Start Menu > Run > copy and paste

    %SystemRoot%\System32\restore\rstrui.exe

    Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

    Double-click My Computer.
    Click the Tools menu, and then click Folder Options.
    Click the View tab.
    Check "Hide file extensions for known file types."
    Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
    Check "Hide protected operating system files."
    Click Apply, and then click OK.

    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:
    Note: I no longer suggest Zone Alarm

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
    settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

    Using IE-SPYAD to help block unwanted sites and activities

  • Winpatrol


  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Hi, Well I ticked all the HJT things you mentioned- Now the PC wont boot into windows at all. Gets as far as Memory Testing : 524288 OK Cannot enter SETUP and thus alter any BIOS settings.
Hi, Yeah, I tried that. I tried resetting, completely cutting power and leaving it switched of while I was at work and restarted - Still the same. Is it worth clearing CMOS? Or is it now officially dead? :-( It was all looking so good too, lol. Ah well its only a bit of metal and plastic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI