This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Unable to turn on Windows Firewall

134 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Windows security center has been giving me pop-up notifications that I have spy-ware/trojan infection and that I should download new anti-virus software. I already have symantec antivirus and nothing has come up when I run a full system scan using that (although I have been having trouble updating the virus definitions). The windows security center is also telling me that the firewall is disabled, when I try to enable it manually the option to turn the firewall on cannot be clicked. I've tried restoring the original firewall settings but no luck. Any help you could give would be greatly appreciated.


Thanks,

here is the log file that get after running hijack this:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:19:52 PM, on 6/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\COMPAQ\CPQ650TP\Ver. 2.3\LWBWHEEL.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\aspimgr.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\junebug.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\WINDOWS\system32\rundll32.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NetZero\SearchEnh1.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [bascstray] BascsTray.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\COMPAQ\CPQ650TP\Ver. 2.3\LWBWHEEL.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [braviax] braviax.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - HKUS\S-1-5-18\..\Run: [braviax] C:\WINDOWS\system32\braviax.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [braviax] C:\WINDOWS\system32\braviax.exe (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540012} - http://www.funnytaf.com/fun/installer/Install.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1211693090298
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1211693062538
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.3 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\System32\basfipm.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 10309 bytes

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.


Unless informed of in advance, failure to post replies within 5 days will result in this thread being closed.


Hi junebug

I'm Gary R, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
If you can do these things, everything should go smoothly.
  • If you're using XP, you'll need Administrator privileges to perform the fixes. (XP accounts are Administrator by default)
  • If you're using Vista, it will be necessary to right click all tools we use and select —-> Run as Admistrator

It may be helpful to you to print out or take a copy of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.


There are some new infections that damage your ability to boot if they are removed. So before we go any further, I need you to install Recovery Console to your computer. This is purely a precautionary measure, I don't see signs of them on your computer, but it's better to be a little cautious now than regretful later.

Recovery Console gives us the ability to recover your computer if things go wrong.

  • Download combofix.exe by sUBs to your Desktop (it must be in this location).
  • Alternate Download
  • If you already have a previous version, delete it and download a new version.
  • Go to Microsoft's website
  • Select the download that's appropriate for your Operating System (if you have XP Media Centre, use download for XP Pro)

[external image: Posted Image]

  • Download the file & save it as it's originally named, to your Desktop.
  • Next
  • Disconnect from the Internet.
  • Important! Temporarily disable your anti-virus, and anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its files which may cause unpredictable results.
  • Click here to see a list of programs that should be disabled (ignore the firewalls). The list is not all inclusive. If yours are not listed and you don't know how to disable them, please ask.

[external image: Posted Image]

  • Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it.
  • Follow the prompts to start ComboFix.
  • When prompted, agree to the End-User License Agreement to install Microsoft Recovery Console.
  • When complete a mesage will pop up asking if you want to continue scanning for Malware.
    • Click Yes
    • Combofix will now run a scan. (Usually takes 15-20 mins, but could be slightly longer)
    • When finished, it will
    • Produce a log for you. (it can also be found at C:\Combofix.txt)
  • Post the log in your next reply please.
  • Now run a new HJT scan and send me the log from that as well please.
[*]Don't forget to re-enable your anti-virus and anti-malware protection before re-connecting to the Internet.


IMPORTANT
  • Do not use your computer while Combofix is running.
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • If you've lost your Internet connection when Combofix has completely finished, re-start your computer to restore it.
If you have any problems with these instructions, a detailed Tutorial for how to use Combofix is available here.
Thanks so much for you help.


Combofix Log:

ComboFix 08-06-19.4 - Rushelle Byfield 2008-06-21 5:38:28.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Rushelle Byfield\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Rushelle Byfield\Local Settings\Temporary Internet Files\anojyx.com
C:\Documents and Settings\Rushelle Byfield\Local Settings\Temporary Internet Files\nipamikig.bat
C:\Documents and Settings\Rushelle Byfield\Local Settings\Temporary Internet Files\yhybequ.com
C:\WINDOWS\braviax.exe
C:\WINDOWS\g32.txt
C:\WINDOWS\s32.txt
C:\WINDOWS\system32\aspimgr.exe
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\system32\DelSelf.bat
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\winivstr.exe
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\ws386.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ASPIMGR
——-\Legacy_NPF
——-\Service_aspimgr
——-\Service_NPF


((((((((((((((((((((((((( Files Created from 2008-05-20 to 2008-06-20 )))))))))))))))))))))))))))))))
.

2008-06-21 04:32 . 2006-08-21 18:14 128,896 ——— C:\windows\system32\DllCache\fltmgr.sys
2008-06-21 04:32 . 2006-08-21 18:14 23,040 ——— C:\windows\system32\DllCache\fltmc.exe
2008-06-21 04:32 . 2006-08-21 21:21 16,896 ——— C:\windows\system32\DllCache\fltlib.dll
2008-06-21 04:17 . 2008-06-21 04:17 d——– C:\Program Files\MSXML 4.0
2008-06-20 20:28 . 2008-06-13 22:10 272,128 ——— C:\windows\system32\DllCache\bthport.sys
2008-06-20 04:39 . 2008-06-20 04:37 102,664 –a—— C:\windows\system32\drivers\tmcomm.sys
2008-06-20 04:37 . 2008-06-20 06:52 d——– C:\Documents and Settings\Rushelle Byfield\.housecall6.6
2008-06-20 03:12 . 2007-07-09 22:09 584,192 ——— C:\windows\system32\DllCache\rpcrt4.dll
2008-06-20 03:01 . 2008-06-21 04:54 d–h—– C:\windows\$hf_mig$
2008-06-20 01:53 . 2008-06-20 01:53 d——– C:\Program Files\Trend Micro
2008-06-20 01:30 . 2007-07-30 19:19 271,224 –a—— C:\windows\system32\mucltui.dll
2008-06-20 01:30 . 2007-07-30 19:19 30,072 –a—— C:\windows\system32\mucltui.dll.mui
2008-06-19 22:21 . 2008-06-19 22:21 19,448 –a—— C:\Program Files\Common Files\qymywyxa.bat
2008-06-19 22:21 . 2008-06-19 22:21 19,403 –a—— C:\Documents and Settings\Rushelle Byfield\Application Data\fijizojeqy.scr
2008-06-19 22:21 . 2008-06-19 22:21 19,255 –a—— C:\Program Files\Common Files\exehiqudaw.sys
2008-06-19 22:21 . 2008-06-19 22:21 18,221 –a—— C:\windows\miwohej.lib
2008-06-19 22:21 . 2008-06-19 22:21 16,907 –a—— C:\Documents and Settings\All Users\Application Data\ydedotyne.exe
2008-06-19 22:21 . 2008-06-19 22:21 15,290 –a—— C:\windows\nypejuh.dll
2008-06-19 22:21 . 2008-06-19 22:21 13,916 –a—— C:\windows\aqucutuq.inf
2008-06-19 22:21 . 2008-06-19 22:21 13,319 –a—— C:\windows\jadematy._sy
2008-06-19 22:21 . 2008-06-19 22:21 13,228 –a—— C:\windows\ufokypi.exe
2008-06-19 22:21 . 2008-06-19 22:21 13,212 –a—— C:\Documents and Settings\Rushelle Byfield\Application Data\subybalus.vbs
2008-06-19 22:21 . 2008-06-19 22:21 12,438 –a—— C:\windows\hucyl._dl
2008-06-19 22:21 . 2008-06-19 22:21 12,375 –a—— C:\windows\kiqyji.scr
2008-06-19 22:21 . 2008-06-19 22:21 12,076 –a—— C:\windows\ysej.bat
2008-06-19 22:21 . 2008-06-19 22:21 11,946 –a—— C:\windows\system32\kiqeduh.reg
2008-06-19 22:21 . 2008-06-19 22:21 10,127 –a—— C:\Documents and Settings\All Users\Application Data\esabodomy.dat
2008-06-19 15:55 . 2008-06-21 05:51 54,156 –ah—– C:\windows\QTFont.qfn
2008-06-19 15:55 . 2008-06-19 15:55 1,409 –a—— C:\windows\QTFont.for
2008-06-12 21:04 . 2006-11-01 12:48 2,129,920 –a—— C:\windows\system32\WLBCGCBPRO731.DLL
2008-06-12 21:04 . 2006-11-01 12:48 1,392,640 –a—— C:\windows\system32\WLTRAY.EXE
2008-06-12 21:04 . 2006-11-01 12:48 757,760 –a—— C:\windows\system32\bcm1xsup.dll
2008-06-12 21:04 . 2006-11-01 12:48 86,016 –a—— C:\windows\system32\preflib.dll
2008-06-12 21:04 . 2006-11-01 12:48 69,632 –a—— C:\windows\system32\bcmwlpkt.dll
2008-06-12 21:04 . 2006-11-01 12:48 44,032 –a—— C:\windows\system32\wltrynt.dll
2008-06-12 21:04 . 2006-11-01 12:48 33,664 –a—— C:\windows\system32\drivers\BCMWLNPF.SYS
2008-06-12 21:04 . 2006-11-01 12:48 20,480 –a—— C:\windows\system32\WLTRYSVC.EXE
2008-06-11 08:45 . 2008-06-11 08:47 d——– C:\NetZeroInstaller
2008-06-11 08:45 . 2008-06-11 08:45 d——– C:\Documents and Settings\All Users\Application Data\NetZero
2008-06-07 10:59 . 2008-06-11 07:43 d——– C:\Program Files\Windows Media Connect 2
2008-06-07 10:55 . 2008-06-11 07:43 d——– C:\windows\system32\drivers\UMDF
2008-06-04 03:15 . 2008-06-04 03:15 d——– C:\Documents and Settings\Rushelle Byfield\Application Data\OLYMPUS
2008-06-04 03:02 . 2008-06-04 03:02 d——– C:\Binaries
2008-06-04 03:01 . 2008-06-04 03:01 d——– C:\windows\system32\QuickTime
2008-06-04 03:01 . 2008-06-04 03:01 d——– C:\Program Files\OLYMPUS
2008-06-04 03:01 . 2004-06-09 07:41 319,488 ——— C:\windows\system32\Pvmjpg21.dll
2008-06-04 03:00 . 2004-03-09 02:55 13,567 –a—— C:\windows\system32\drivers\CDRBSDRV.SYS
2008-06-04 02:59 . 2008-06-04 02:59 d——– C:\Program Files\PIXELA
2008-05-31 23:43 . 2008-05-31 23:43 d——– C:\Documents and Settings\Rushelle Byfield\Application Data\Qualcomm
2008-05-31 23:42 . 2008-05-31 23:42 d——– C:\Program Files\Qualcomm
2008-05-31 15:24 . 2008-05-31 15:24 d——– C:\Documents and Settings\Default User\Application Data\Apple Computer
2008-05-25 21:18 . 2008-05-25 21:19 d——– C:\Program Files\iTunes
2008-05-25 21:15 . 2008-05-25 21:16 d——– C:\Program Files\QuickTime
2008-05-25 21:12 . 2008-05-25 21:12 d—-c— C:\windows\system32\DRVSTORE
2008-05-25 21:11 . 2008-05-25 21:11 d——– C:\Program Files\Common Files\Apple
2008-05-25 15:21 . 2008-05-25 15:21 d——– C:\windows\peernet
2008-05-25 15:20 . 2008-05-25 15:20 d——– C:\windows\provisioning
2008-05-25 15:16 . 2008-05-25 15:16 d——– C:\windows\ServicePackFiles
2008-05-25 15:09 . 2005-06-28 10:21 22,752 –a—— C:\windows\system32\spupdsvc.exe
2008-05-25 15:04 . 2008-05-25 15:04 d——– C:\windows\EHome
2008-05-25 14:54 . 2002-04-16 11:11 67,866 ——— C:\windows\system32\drivers\netwlan5.img
2008-05-25 14:54 . 2004-08-04 14:56 11,776 ——— C:\windows\system32\spnpinst.exe
2008-05-25 14:54 . 2004-08-03 04:20 7,208 ——— C:\windows\system32\secupd.sig
2008-05-25 14:54 . 2004-08-03 04:20 4,569 ——— C:\windows\system32\secupd.dat
2008-05-25 14:28 . 2008-05-25 14:28 d——– C:\windows\system32\bits
2008-05-25 14:27 . 2004-08-04 16:56 438,784 ——— C:\windows\system32\xpob2res.dll
2008-05-25 14:27 . 2004-08-04 16:56 351,232 –a—— C:\windows\system32\winhttp.dll
2008-05-25 14:27 . 2004-08-04 16:56 18,944 –a—— C:\windows\system32\qmgrprxy.dll
2008-05-25 14:27 . 2004-08-04 16:56 8,192 ——— C:\windows\system32\bitsprx2.dll
2008-05-25 14:27 . 2004-08-04 16:56 7,168 ——— C:\windows\system32\bitsprx3.dll
2008-05-25 14:25 . 2007-07-31 09:19 549,720 –a—— C:\windows\system32\wuapi.dll
2008-05-25 14:25 . 2007-07-31 09:19 325,976 –a—— C:\windows\system32\wucltui.dll
2008-05-25 14:25 . 2007-07-31 09:19 216,408 –a—— C:\windows\system32\wuaucpl.cpl
2008-05-25 14:25 . 2007-07-31 09:19 43,352 –a—— C:\windows\system32\wups2.dll
2008-05-25 14:25 . 2007-07-31 09:18 34,136 –a—— C:\windows\system32\wucltui.dll.mui
2008-05-25 14:25 . 2007-07-31 09:18 33,624 –a—— C:\windows\system32\wups.dll
2008-05-25 14:25 . 2007-07-31 09:19 25,944 –a—— C:\windows\system32\wuaucpl.cpl.mui
2008-05-25 14:25 . 2007-07-31 09:19 25,944 –a—— C:\windows\system32\wuapi.dll.mui
2008-05-25 14:25 . 2007-07-31 09:18 20,312 –a—— C:\windows\system32\wuaueng.dll.mui

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-20 20:53 ——— d—–w C:\Documents and Settings\Rushelle Byfield\Application Data\Skype
2008-06-20 20:45 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-06-20 06:28 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-06-19 19:21 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-06-19 19:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-19 18:53 ——— d—–w C:\Program Files\Symantec
2008-06-19 13:21 16,038 —-a-w C:\Program Files\Common Files\ziti.db
2008-06-19 13:21 14,741 —-a-w C:\Program Files\Common Files\ebyjodav._dl
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-12 12:04 ——— d—–w C:\Program Files\Dell
2008-06-10 23:47 ——— d—–w C:\Program Files\NetZero
2008-06-08 18:13 ——— d–h–w C:\Documents and Settings\Rushelle Byfield\Application Data\Move Networks
2008-06-03 17:59 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-02 12:54 ——— d—–w C:\Program Files\Common Files\Adobe
2008-06-02 12:50 ——— d—–w C:\Documents and Settings\Rushelle Byfield\Application Data\AdobeUM
2008-05-28 06:33 ——— d—–w C:\Program Files\Soulseek
2008-05-25 12:18 ——— d—–w C:\Program Files\iPod
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-23 01:25 ——— d—–w C:\Program Files\Apple Software Update
2008-04-23 01:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 16:56 15360]
"NetZero_uoltray"="C:\Program Files\NetZero\exec.exe" [2007-03-07 09:51 1629184]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [ ]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-10-14 07:20 20058152]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2005-11-30 09:19 57344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-02-03 11:32 155648]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-05 11:24 28672 C:\windows\system32\Ati2mdxx.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 18:25 144784]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-30 03:30 335872]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2004-03-05 10:59 487424]
"bascstray"="BascsTray.exe" []
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-07-18 00:18 28672]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-18 02:28 684032]
"LWBMOUSE"="C:\Program Files\COMPAQ\CPQ650TP\Ver. 2.3\LWBWHEEL.exe" [2003-05-19 12:24 438272]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-11-11 08:11 180269]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 13:11 49152]
"ClubBox"="" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-22 06:38 52840]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2007-03-15 08:49 125632]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-10 14:28 36352]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-29 13:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-31 00:36 267048]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2005-11-30 09:19 40960]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-01 12:48 1392640]

C:\Documents and Settings\Rushelle Byfield\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-11-02 10:29:28 344064]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-04-12 00:01:07 49254]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 17:38:16 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2004-07-27 01:38:26 24576]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-05 08:28:24 258048]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-05 08:50:52 53248]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 05:05:56 65588]
VPN Client.lnk - C:\WINDOWS\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [2007-07-13 10:02:55 6144]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\Program Files\Qualcomm\Eudora\EuShlExt.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=


.
Contents of the 'Scheduled Tasks' folder
"2008-06-18 08:26:24 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-21 05:50:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
C:\windows\system32\ati2evxx.exe
C:\windows\system32\WLTRYSVC.EXE
C:\windows\system32\BCMWLTRY.EXE
C:\windows\system32\scardsvr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\windows\system32\BAsfIpM.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\windows\system32\ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\windows\system32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Apoint\ApntEx.exe
C:\windows\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\NetZero\qsacc\x1exec.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
.
**************************************************************************
.
Completion time: 2008-06-21 6:09:34 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-20 21:08:40

Pre-Run: 5,523,357,696 bytes free
Post-Run: 5,721,866,240 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

246 — E O F — 2008-06-20 19:55:38








HijackThis Log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:41:57 AM, on 6/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\COMPAQ\CPQ650TP\Ver. 2.3\LWBWHEEL.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\NetZero\qsacc\x1exec.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\junebug.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NetZero\SearchEnh1.dll
O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [bascstray] BascsTray.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\COMPAQ\CPQ650TP\Ver. 2.3\LWBWHEEL.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540012} - http://www.funnytaf.com/fun/installer/Install.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1211693090298
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1211693062538
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.3 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\System32\basfipm.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 10244 bytes
OK, still some work to do.

  • Click Start > Run type Notepad click OK.
  • This will open an empty Notepad file.
  • Copy/Paste the contents of the box below into Notepad.
C:\Program Files\Common Files\qymywyxa.bat
C:\Documents and Settings\Rushelle Byfield\Application Data\fijizojeqy.scr
C:\Program Files\Common Files\exehiqudaw.sys
C:\windows\miwohej.lib
C:\Documents and Settings\All Users\Application Data\ydedotyne.exe
C:\windows\nypejuh.dll
C:\windows\aqucutuq.inf
C:\windows\jadematy._sy
C:\windows\ufokypi.exe
C:\Documents and Settings\Rushelle Byfield\Application Data\subybalus.vbs
C:\windows\hucyl._dl
C:\windows\kiqyji.scr
C:\windows\ysej.bat
C:\windows\system32\kiqeduh.reg
C:\Documents and Settings\All Users\Application Data\esabodomy.dat
C:\windows\QTFont.qfn
C:\windows\QTFont.for
C:\Program Files\Common Files\ziti.db
C:\Program Files\Common Files\ebyjodav._dl
  • Click Format and ensure Wordwrap is unchecked.
  • Save as CFScript.txt to your Desktop.
[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Combofix will now process that file.

When finished, it will produce a log for you. Post that log in your next reply please. (it can also be found at C:\Combofix.txt)

Next

Please download Malwarebytes' Anti-Malware to your Desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.

  • Click on the Malwarebytes' Anti-Malware icon to launch the programme.
    • Click the Updates tab.
    • Click Check for Updates and allow the programme to download the latest definitions.
  • Click the Scanner tab.
    • Check Perform Quick Scan.
    • Click Scan and wait for the scan to complete.
    • When the scan is complete, click OK, then Show Results.
    • Ensure all items are checked then click Remove Selected.
    • A box will pop-up telling you that files have been quarantined.
    • A log will pop-up.
  • Post the log in your next reply please.

You can also access the log by doing the following
  • Click on the Logs tab.
  • Click on the log at the bottom of those listed to highlight it.
  • Click Open

Next

Run a new scan with HJT and post me the log please.

Summary of the logs I need from you in your next post:
  • Latest Combofix log
  • MBAM log
  • New HJT log


Please post each log separately to prevent them being cut off by the forum post size limiter.

Let me know how your computer is behaving now.
ComboFix Log

ComboFix 08-06-19.4 - Rushelle Byfield 2008-06-21 17:05:31.2 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Rushelle Byfield\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-05-21 to 2008-06-21 )))))))))))))))))))))))))))))))
.

2008-06-21 04:32 . 2006-08-21 18:14 128,896 ——— C:\windows\system32\DllCache\fltmgr.sys
2008-06-21 04:32 . 2006-08-21 18:14 23,040 ——— C:\windows\system32\DllCache\fltmc.exe
2008-06-21 04:32 . 2006-08-21 21:21 16,896 ——— C:\windows\system32\DllCache\fltlib.dll
2008-06-21 04:17 . 2008-06-21 04:17 d——– C:\Program Files\MSXML 4.0
2008-06-20 20:28 . 2008-06-13 22:10 272,128 ——— C:\windows\system32\DllCache\bthport.sys
2008-06-20 04:39 . 2008-06-20 04:37 102,664 –a—— C:\windows\system32\drivers\tmcomm.sys
2008-06-20 04:37 . 2008-06-20 06:52 d——– C:\Documents and Settings\Rushelle Byfield\.housecall6.6
2008-06-20 03:12 . 2007-07-09 22:09 584,192 ——— C:\windows\system32\DllCache\rpcrt4.dll
2008-06-20 03:01 . 2008-06-21 04:54 d–h—– C:\windows\$hf_mig$
2008-06-20 01:53 . 2008-06-20 01:53 d——– C:\Program Files\Trend Micro
2008-06-20 01:30 . 2007-07-30 19:19 271,224 –a—— C:\windows\system32\mucltui.dll
2008-06-20 01:30 . 2007-07-30 19:19 30,072 –a—— C:\windows\system32\mucltui.dll.mui
2008-06-19 22:21 . 2008-06-19 22:21 19,448 –a—— C:\Program Files\Common Files\qymywyxa.bat
2008-06-19 22:21 . 2008-06-19 22:21 19,403 –a—— C:\Documents and Settings\Rushelle Byfield\Application Data\fijizojeqy.scr
2008-06-19 22:21 . 2008-06-19 22:21 19,255 –a—— C:\Program Files\Common Files\exehiqudaw.sys
2008-06-19 22:21 . 2008-06-19 22:21 18,221 –a—— C:\windows\miwohej.lib
2008-06-19 22:21 . 2008-06-19 22:21 16,907 –a—— C:\Documents and Settings\All Users\Application Data\ydedotyne.exe
2008-06-19 22:21 . 2008-06-19 22:21 15,290 –a—— C:\windows\nypejuh.dll
2008-06-19 22:21 . 2008-06-19 22:21 13,916 –a—— C:\windows\aqucutuq.inf
2008-06-19 22:21 . 2008-06-19 22:21 13,319 –a—— C:\windows\jadematy._sy
2008-06-19 22:21 . 2008-06-19 22:21 13,228 –a—— C:\windows\ufokypi.exe
2008-06-19 22:21 . 2008-06-19 22:21 13,212 –a—— C:\Documents and Settings\Rushelle Byfield\Application Data\subybalus.vbs
2008-06-19 22:21 . 2008-06-19 22:21 12,438 –a—— C:\windows\hucyl._dl
2008-06-19 22:21 . 2008-06-19 22:21 12,375 –a—— C:\windows\kiqyji.scr
2008-06-19 22:21 . 2008-06-19 22:21 12,076 –a—— C:\windows\ysej.bat
2008-06-19 22:21 . 2008-06-19 22:21 11,946 –a—— C:\windows\system32\kiqeduh.reg
2008-06-19 22:21 . 2008-06-19 22:21 10,127 –a—— C:\Documents and Settings\All Users\Application Data\esabodomy.dat
2008-06-19 15:55 . 2008-06-21 12:24 54,156 –ah—– C:\windows\QTFont.qfn
2008-06-19 15:55 . 2008-06-19 15:55 1,409 –a—— C:\windows\QTFont.for
2008-06-12 21:04 . 2006-11-01 12:48 2,129,920 –a—— C:\windows\system32\WLBCGCBPRO731.DLL
2008-06-12 21:04 . 2006-11-01 12:48 1,392,640 –a—— C:\windows\system32\WLTRAY.EXE
2008-06-12 21:04 . 2006-11-01 12:48 757,760 –a—— C:\windows\system32\bcm1xsup.dll
2008-06-12 21:04 . 2006-11-01 12:48 86,016 –a—— C:\windows\system32\preflib.dll
2008-06-12 21:04 . 2006-11-01 12:48 69,632 –a—— C:\windows\system32\bcmwlpkt.dll
2008-06-12 21:04 . 2006-11-01 12:48 44,032 –a—— C:\windows\system32\wltrynt.dll
2008-06-12 21:04 . 2006-11-01 12:48 33,664 –a—— C:\windows\system32\drivers\BCMWLNPF.SYS
2008-06-12 21:04 . 2006-11-01 12:48 20,480 –a—— C:\windows\system32\WLTRYSVC.EXE
2008-06-11 08:45 . 2008-06-11 08:47 d——– C:\NetZeroInstaller
2008-06-11 08:45 . 2008-06-11 08:45 d——– C:\Documents and Settings\All Users\Application Data\NetZero
2008-06-07 10:59 . 2008-06-11 07:43 d——– C:\Program Files\Windows Media Connect 2
2008-06-07 10:55 . 2008-06-11 07:43 d——– C:\windows\system32\drivers\UMDF
2008-06-04 03:15 . 2008-06-04 03:15 d——– C:\Documents and Settings\Rushelle Byfield\Application Data\OLYMPUS
2008-06-04 03:02 . 2008-06-04 03:02 d——– C:\Binaries
2008-06-04 03:01 . 2008-06-04 03:01 d——– C:\windows\system32\QuickTime
2008-06-04 03:01 . 2008-06-04 03:01 d——– C:\Program Files\OLYMPUS
2008-06-04 03:01 . 2004-06-09 07:41 319,488 ——— C:\windows\system32\Pvmjpg21.dll
2008-06-04 03:00 . 2004-03-09 02:55 13,567 –a—— C:\windows\system32\drivers\CDRBSDRV.SYS
2008-06-04 02:59 . 2008-06-04 02:59 d——– C:\Program Files\PIXELA
2008-05-31 23:43 . 2008-05-31 23:43 d——– C:\Documents and Settings\Rushelle Byfield\Application Data\Qualcomm
2008-05-31 23:42 . 2008-05-31 23:42 d——– C:\Program Files\Qualcomm
2008-05-31 15:24 . 2008-05-31 15:24 d——– C:\Documents and Settings\Default User\Application Data\Apple Computer
2008-05-25 21:18 . 2008-05-25 21:19 d——– C:\Program Files\iTunes
2008-05-25 21:15 . 2008-05-25 21:16 d——– C:\Program Files\QuickTime
2008-05-25 21:12 . 2008-05-25 21:12 d—-c— C:\windows\system32\DRVSTORE
2008-05-25 21:11 . 2008-05-25 21:11 d——– C:\Program Files\Common Files\Apple
2008-05-25 15:21 . 2008-05-25 15:21 d——– C:\windows\peernet
2008-05-25 15:20 . 2008-05-25 15:20 d——– C:\windows\provisioning
2008-05-25 15:16 . 2008-05-25 15:16 d——– C:\windows\ServicePackFiles
2008-05-25 15:09 . 2005-06-28 10:21 22,752 –a—— C:\windows\system32\spupdsvc.exe
2008-05-25 15:04 . 2008-05-25 15:04 d——– C:\windows\EHome
2008-05-25 14:54 . 2002-04-16 11:11 67,866 ——— C:\windows\system32\drivers\netwlan5.img
2008-05-25 14:54 . 2004-08-04 14:56 11,776 ——— C:\windows\system32\spnpinst.exe
2008-05-25 14:54 . 2004-08-03 04:20 7,208 ——— C:\windows\system32\secupd.sig
2008-05-25 14:54 . 2004-08-03 04:20 4,569 ——— C:\windows\system32\secupd.dat
2008-05-25 14:28 . 2008-05-25 14:28 d——– C:\windows\system32\bits
2008-05-25 14:27 . 2004-08-04 16:56 438,784 ——— C:\windows\system32\xpob2res.dll
2008-05-25 14:27 . 2004-08-04 16:56 351,232 –a—— C:\windows\system32\winhttp.dll
2008-05-25 14:27 . 2004-08-04 16:56 18,944 –a—— C:\windows\system32\qmgrprxy.dll
2008-05-25 14:27 . 2004-08-04 16:56 8,192 ——— C:\windows\system32\bitsprx2.dll
2008-05-25 14:27 . 2004-08-04 16:56 7,168 ——— C:\windows\system32\bitsprx3.dll
2008-05-25 14:25 . 2007-07-31 09:19 549,720 –a—— C:\windows\system32\wuapi.dll
2008-05-25 14:25 . 2007-07-31 09:19 325,976 –a—— C:\windows\system32\wucltui.dll
2008-05-25 14:25 . 2007-07-31 09:19 216,408 –a—— C:\windows\system32\wuaucpl.cpl
2008-05-25 14:25 . 2007-07-31 09:19 43,352 –a—— C:\windows\system32\wups2.dll
2008-05-25 14:25 . 2007-07-31 09:18 34,136 –a—— C:\windows\system32\wucltui.dll.mui
2008-05-25 14:25 . 2007-07-31 09:18 33,624 –a—— C:\windows\system32\wups.dll
2008-05-25 14:25 . 2007-07-31 09:19 25,944 –a—— C:\windows\system32\wuaucpl.cpl.mui
2008-05-25 14:25 . 2007-07-31 09:19 25,944 –a—— C:\windows\system32\wuapi.dll.mui
2008-05-25 14:25 . 2007-07-31 09:18 20,312 –a—— C:\windows\system32\wuaueng.dll.mui

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-21 08:03 ——— d—–w C:\Documents and Settings\Rushelle Byfield\Application Data\Skype
2008-06-21 03:31 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-06-20 06:28 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-06-19 19:21 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-06-19 19:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-19 18:53 ——— d—–w C:\Program Files\Symantec
2008-06-19 13:21 16,038 —-a-w C:\Program Files\Common Files\ziti.db
2008-06-19 13:21 14,741 —-a-w C:\Program Files\Common Files\ebyjodav._dl
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-12 12:04 ——— d—–w C:\Program Files\Dell
2008-06-10 23:47 ——— d—–w C:\Program Files\NetZero
2008-06-08 18:13 ——— d–h–w C:\Documents and Settings\Rushelle Byfield\Application Data\Move Networks
2008-06-03 17:59 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-02 12:54 ——— d—–w C:\Program Files\Common Files\Adobe
2008-06-02 12:50 ——— d—–w C:\Documents and Settings\Rushelle Byfield\Application Data\AdobeUM
2008-05-28 06:33 ——— d—–w C:\Program Files\Soulseek
2008-05-25 12:18 ——— d—–w C:\Program Files\iPod
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-23 01:25 ——— d—–w C:\Program Files\Apple Software Update
2008-04-23 01:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
.

((((((((((((((((((((((((((((( snapshot@2008-06-21_ 6.07.25.52 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-20 20:46:37 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-21 03:23:06 2,048 –s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 16:56 15360]
"NetZero_uoltray"="C:\Program Files\NetZero\exec.exe" [2007-03-07 09:51 1629184]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [ ]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-10-14 07:20 20058152]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2005-11-30 09:19 57344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-02-03 11:32 155648]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-05 11:24 28672 C:\windows\system32\Ati2mdxx.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 18:25 144784]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-30 03:30 335872]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2004-03-05 10:59 487424]
"bascstray"="BascsTray.exe" []
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-07-18 00:18 28672]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-18 02:28 684032]
"LWBMOUSE"="C:\Program Files\COMPAQ\CPQ650TP\Ver. 2.3\LWBWHEEL.exe" [2003-05-19 12:24 438272]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-11-11 08:11 180269]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 13:11 49152]
"ClubBox"="" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-22 06:38 52840]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2007-03-15 08:49 125632]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-10 14:28 36352]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-29 13:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-31 00:36 267048]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2005-11-30 09:19 40960]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-01 12:48 1392640]

C:\Documents and Settings\Rushelle Byfield\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-11-02 10:29:28 344064]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-04-12 00:01:07 49254]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 17:38:16 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2004-07-27 01:38:26 24576]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-05 08:28:24 258048]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-05 08:50:52 53248]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 05:05:56 65588]
VPN Client.lnk - C:\WINDOWS\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [2007-07-13 10:02:55 6144]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\Program Files\Qualcomm\Eudora\EuShlExt.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=


*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-06-18 08:26:24 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-21 17:12:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
Completion time: 2008-06-21 17:19:09
ComboFix-quarantined-files.txt 2008-06-21 08:18:33
ComboFix2.txt 2008-06-20 21:09:49

Pre-Run: 5,898,055,680 bytes free
Post-Run: 5,877,686,272 bytes free

194 — E O F — 2008-06-20 19:55:38
MBAM Log


Malwarebytes' Anti-Malware 1.18
Database version: 873

5:32:36 PM 6/21/2008
mbam-log-6-21-2008 (17-32-27).txt

Scan type: Quick Scan
Objects scanned: 40028
Time elapsed: 9 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 11
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{40722371-e24c-4b36-8e76-010bb6c7185b} (Adware.CWS) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{825c19d3-35ce-428f-876b-88e080466689} (Adware.CWS) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{0409743c-e5e3-4bdd-9ec7-eff622530282} (Adware.CWS) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{6f553c18-15e6-4e5e-8f44-add50de754ed} (Adware.CWS) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{072039ab-2117-4ed5-a85f-9b9eb903e021} (Adware.CWS) -> No action taken.
HKEY_CLASSES_ROOT\nowstarter.nowstarterctrl.1 (Adware.CWS) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> No action taken.
C:\windows\system32\NowStarter.ocx (Adware.CWS) -> No action taken.
HijackThis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:33:31 PM, on 6/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\COMPAQ\CPQ650TP\Ver. 2.3\LWBWHEEL.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\NetZero\qsacc\x1exec.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\junebug.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NetZero\SearchEnh1.dll
O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [bascstray] BascsTray.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\COMPAQ\CPQ650TP\Ver. 2.3\LWBWHEEL.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540012} - http://www.funnytaf.com/fun/installer/Install.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1211693090298
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1211693062538
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.3 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\System32\basfipm.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 10171 bytes




My computer seems to be working fine now, I was able to upload the latest virus definitions of symantec as well as turn the windows firewall back on. Once again, thanks for the help.
You didn't follow the MBAM instructions as I wrote them.

Please run the scan again and this time pay attention to the part I've highlighted in red.

  • Click on the Malwarebytes' Anti-Malware icon to launch the programme.
    • Click the Updates tab.
    • Click Check for Updates and allow the programme to download the latest definitions.
  • Click the Scanner tab.
    • Check Perform Quick Scan.
    • Click Scan and wait for the scan to complete.
    • When the scan is complete, click OK, then Show Results.
    • Ensure all items are checked then click Remove Selected.
    • A box will pop-up telling you that files have been quarantined.
    • A log will pop-up.
  • Post the log in your next reply please.

You can also access the log by doing the following
  • Click on the Logs tab.
  • Click on the log at the bottom of those listed to highlight it.
  • Click Open
Sorry about that. I ran the scan again but it said that no items were found. Malwarebytes' Anti-Malware 1.18 Database version: 873 6:22:34 PM 6/21/2008 mbam-log-6-21-2008 (18-22-34).txt Scan type: Quick Scan Objects scanned: 40166 Time elapsed: 14 minute(s), 26 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Not sure what happened there.

Can you open MBAM.
Click on the Quarantine tab.
Are there any items shown in the Quarantine box ?

Because of the discrepancies I'd like you to run another scan for me.

Please do an online scan with Kaspersky Online Scanner

Note: You must be using Internet Explorer as your browser as it will be necessary to install an Active X component to your computer.

Important If you have previously used Kaspersky Online Scanner (before 8th Aug 2006), you will have to uninstall the old version using Add/Remove Programs in Control Panel before you can use the new version.

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK.
  • Now under select a target to scan select My Computer.
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Click the Save Report As… button (see red arrow below)

    [external image: Posted Image]
  • In the Save as… prompt, select Desktop
  • In the File name box, name the file KAVScan
  • In the Save as type prompt, select Text file (see below)

    [external image: Posted Image]
  • Copy and paste that information in your next post please.

Note: The Kaspersky online scanner is not yet fully compatible with IE7. You may get returned to a window without the Accept/Decline buttons after allowing the ActiveX control. The buttons are there - you just can't see them! Click on the zoom button (bottom, right of the window) and change it from 100% to 75%. You should now see the buttons. Reset to 100% once the license has been accepted.
For some reason MBAM will no longer open. I get an error message that says Error Loading database. However before I ran the last scan the quarantine had 13 items in it.
Not sure why that should be, I suggest you uninstall MBAM. If you wish you can try downloading a new copy and see if you have problems with that version. In any case, please run a Kaspersky scan as directed in my last post and send me the log if you will.
Kaspersky Scan log file


——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Sunday, June 22, 2008 3:07:50 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/06/2008
Kaspersky Anti-Virus database records: 879999
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 79523
Number of viruses found: 2
Number of infected objects: 17
Number of suspicious objects: 0
Duration of the scan process: 02:31:22

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\NetZero\Accelerator\dblog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\NetZero\Accelerator\MainExceptions.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\NetZero\Accelerator\sdi.db Object is locked skipped
C:\Documents and Settings\All Users\Application Data\NetZero\Accelerator\sdi.lg Object is locked skipped
C:\Documents and Settings\All Users\Application Data\NetZero\Isp\BootExceptions.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\NetZero\Isp\ExecExceptions.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\NetZero\Isp\IspDblog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\NetZero\Isp\MainExceptions.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\.housecall6.6\Quarantine\A0215932.sys.bac_a00524 Infected: not-a-virus:FraudTool.Win32.UltimateDefender.cm skipped
C:\Documents and Settings\Rushelle Byfield\.housecall6.6\Quarantine\beep.sys.bac_a00524 Infected: not-a-virus:FraudTool.Win32.UltimateDefender.cm skipped
C:\Documents and Settings\Rushelle Byfield\Application Data\Microsoft\Templates\Normal.dot Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Application Data\Mozilla\Firefox\Profiles\29h1coem.default\cert8.db Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Application Data\Mozilla\Firefox\Profiles\29h1coem.default\history.dat Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Application Data\Mozilla\Firefox\Profiles\29h1coem.default\key3.db Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Application Data\Mozilla\Firefox\Profiles\29h1coem.default\parent.lock Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Application Data\Mozilla\Firefox\Profiles\29h1coem.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Application Data\Mozilla\Firefox\Profiles\29h1coem.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\ApplicationHistory\hpqgalry.exe.cf8dd223.ini.inuse Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.cdx Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.dbf Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.cdx Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.dbf Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.cdx Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.dbf Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.fpt Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.cdx Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.dbf Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.cdx Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.dbf Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.cdx Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.dbf Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Identities\{F829C281-A79D-4034-86C6-0FF290663427}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx/[From "Kris.. Mccauley" <[removed]>][Date Fri, 08 Apr 2005 18:21:35 -0800]/UNNAMED/Kriss_HERBVIAGRA.htm Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Identities\{F829C281-A79D-4034-86C6-0FF290663427}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx/[From "Kris.. Mccauley" <[removed]>][Date Fri, 08 Apr 2005 18:21:35 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Identities\{F829C281-A79D-4034-86C6-0FF290663427}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx/[From "Rosalyn.. Clayton" <[removed]>][Date Fri, 08 Apr 2005 14:42:17 -0800]/UNNAMED/Rosalyns_HERBVIAGRA.htm Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Identities\{F829C281-A79D-4034-86C6-0FF290663427}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx/[From "Rosalyn.. Clayton" <[removed]>][Date Fri, 08 Apr 2005 14:42:17 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Identities\{F829C281-A79D-4034-86C6-0FF290663427}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx/[From "Peterson Allan" <[removed]>][Date Wed, 27 Apr 2005 05:20:33 -0800]/UNNAMED/AllansEnlarGer.htm Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Identities\{F829C281-A79D-4034-86C6-0FF290663427}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx/[From "Peterson Allan" <[removed]>][Date Wed, 27 Apr 2005 05:20:33 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Identities\{F829C281-A79D-4034-86C6-0FF290663427}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx/[From "Men's Health" <[removed]>][Date Tue, 26 Apr 2005 12:30:45 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Identities\{F829C281-A79D-4034-86C6-0FF290663427}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx/[From "Rosalyn.. Clayton" <[removed]>][Date Fri, 08 Apr 2005 14:42:17 -0800]/UNNAMED/Rosalyns_HERBVIAGRA.htm Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Identities\{F829C281-A79D-4034-86C6-0FF290663427}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx/[From "Rosalyn.. Clayton" <[removed]>][Date Fri, 08 Apr 2005 14:42:17 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Identities\{F829C281-A79D-4034-86C6-0FF290663427}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx/[From "Kris.. Mccauley" <[removed]>][Date Fri, 08 Apr 2005 18:21:35 -0800]/UNNAMED/Kriss_HERBVIAGRA.htm Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Identities\{F829C281-A79D-4034-86C6-0FF290663427}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx/[From "Kris.. Mccauley" <[removed]>][Date Fri, 08 Apr 2005 18:21:35 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Identities\{F829C281-A79D-4034-86C6-0FF290663427}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx/[From "Men's Health" <[removed]>][Date Tue, 26 Apr 2005 12:30:45 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Identities\{F829C281-A79D-4034-86C6-0FF290663427}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx/[From "Peterson Allan" <[removed]>][Date Wed, 27 Apr 2005 05:20:33 -0800]/UNNAMED/AllansEnlarGer.htm Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Identities\{F829C281-A79D-4034-86C6-0FF290663427}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx/[From "Peterson Allan" <[removed]>][Date Wed, 27 Apr 2005 05:20:33 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Identities\{F829C281-A79D-4034-86C6-0FF290663427}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx MailMSOutlook5: infected - 14 skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\History\History.IE5\MSHist012008062120080622\index.dat Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Temp\Perflib_Perfdata_d48.dat Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Temp\Perflib_Perfdata_e7c.dat Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Temp\~DF72F9.tmp Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\ntuser.dat Object is locked skipped
C:\Documents and Settings\Rushelle Byfield\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0696NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0935NAV~.TMP Object is locked skipped
C:\QooBox\Quarantine\C\windows\system32\winivstr.exe.vir Object is locked skipped
C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP808\A0219054.exe Object is locked skipped
C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP809\A0219076.exe Object is locked skipped
C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP810\A0219101.exe Object is locked skipped
C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP811\A0220100.exe Object is locked skipped
C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP813\A0220696.exe Object is locked skipped
C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP814\change.log Object is locked skipped
C:\windows\Debug\passwd.log Object is locked skipped
C:\windows\Internet Logs\tvDebug.log Object is locked skipped
C:\windows\SchedLgU.Txt Object is locked skipped
C:\windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\windows\Sti_Trace.log Object is locked skipped
C:\windows\system32\CatRoot2\edb.log Object is locked skipped
C:\windows\system32\CatRoot2\tmp.edb Object is locked skipped
C:\windows\system32\config\AppEvent.Evt Object is locked skipped
C:\windows\system32\config\default Object is locked skipped
C:\windows\system32\config\default.log Object is locked skipped
C:\windows\system32\config\sam Object is locked skipped
C:\windows\system32\config\sam.log Object is locked skipped
C:\windows\system32\config\SecEvent.Evt Object is locked skipped
C:\windows\system32\config\security Object is locked skipped
C:\windows\system32\config\security.log Object is locked skipped
C:\windows\system32\config\software Object is locked skipped
C:\windows\system32\config\software.log Object is locked skipped
C:\windows\system32\config\SysEvent.Evt Object is locked skipped
C:\windows\system32\config\system Object is locked skipped
C:\windows\system32\config\system.log Object is locked skipped
C:\windows\system32\h323log.txt Object is locked skipped
C:\windows\system32\wbem\Repository\fs\index.btr Object is locked skipped
C:\windows\system32\wbem\Repository\fs\INDEX.MAP Object is locked skipped
C:\windows\system32\wbem\Repository\fs\MAPPING.VER Object is locked skipped
C:\windows\system32\wbem\Repository\fs\MAPPING1.MAP Object is locked skipped
C:\windows\system32\wbem\Repository\fs\MAPPING2.MAP Object is locked skipped
C:\windows\system32\wbem\Repository\fs\OBJECTS.DATA Object is locked skipped
C:\windows\system32\wbem\Repository\fs\OBJECTS.MAP Object is locked skipped
C:\windows\wiadebug.log Object is locked skipped
C:\windows\wiaservc.log Object is locked skipped
C:\windows\WindowsUpdate.log Object is locked skipped

Scan process completed.
OK everything's looking good.

The "infections" found by Kaspersky are the encrypted quarantine files by Housecall, they're safe and can't re-infect you.

There are a few suspicious e-mails in your Outlook Express Hotmail deleted items folder, so I'd empty that folder if I were you.

Let's clear out Combofix and the files/folders it created
  • Click Start > Run
  • Copy/Paste ComboFix /u into the Run box.
  • Click OK
  • The following items will now be processed.
    • Deletes the following files/folders:
    • ComboFix.exe
    • %system%\swxcacls.exe
    • %system%\swsc.exe
    • %system%\VFind.exe
    • %system%\moveex.exe
    • %system%\swreg.exe
    • %systemroot%\catchme.exe
    • \ComboFix
    • \Qoobox
    • \VundoFix Backups
    • \Deckard
    • \_OTMoveIt
    • %systemroot%\erdnt\subs
  • Resets the clock settings.
  • Hides file extensions
  • Hides System/Hidden files
  • Clears System Restore cache and create new Restore point

IMPORTANT
  • Do not use your computer while Combofix is running.
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

As far as I can see, your computer looks clear of infection now.

Are you still noticing any problems ?
  • If you are let me know about them.
  • If not it's time to make your computer more secure.

Before I make any recommendations, I'd like to give a simplified overview of how your defensive systems work and what you can do to protect yourself better in future.

The average home computer has approximately 64,000 ports through which it can communicate. By default these ports are open and can be used by any programme which cares to access them, either from within the computer or from without. If you were to go online with a computer in this condition you would quickly be attacked and your computer would be infected.

To prevent this you install a Firewall. A firewall will close all open ports and you then open the ones you need by setting "rules" for them according to the instructions supplied with the Firewall programme. Usually you will have ports open for your Internet Browser, your e-mail client, and the update functions for various programmes.

These "open" ports will not be fully accessible, in that they will only allow a communication if it was instigated from within your computer. Any unsolicited communications from outside are blocked.

However if you are tricked into starting the communication, then as far as your Firewall is concerned it is a legit transaction and it will open the port. So by clicking on malicious links, replying to unsolicited e-mails and attachments, and downloading from unsafe sources, you are effectively bypassing any protection your Firewall supplies.

At this point your Anti-Spyware and Anti-Virus programmes take over. The real-time-protection in these constantly scan the data stream in your open ports looking for things that match with items in the database they have within them. If they find something then they will alert you, or quarantine it, or delete it, according to the rules set within the programme.

However as you can see, if the database does not contain details of the infection that's attacking you, then your Anti-Virus or Anti-Spyware programmes will not protect you. There are new infections (or new variations of old infections) created every day, which is why it's vital to keep your programmes up to date. Even with a fully updated database though, you are though still playing catchup, which is why your Firewall, Anti-Virus and Anti-Spyware programmes cannot ever give you 100% protection.

Adding more and more programmes will not give you more and more protection, it's up to you to take some responsibility for your online actions, and modify them to give your programmes the best chance of protecting you.

Be careful what you click on.

  • Don't download anything from a site you do not know and trust. Remember, there's no such thing as a free lunch, if something seems too good to be true it is. Malware purveyors love to offer out freebies as bait knowing full well that one unguarded click is all it takes.
  • Don't reply to unsolicited e-mails.
  • Don't open e-mail attachments (even from friends) without checking with the source to ensure they actually sent them.
  • Don't use P2P file sharing programmes. Even the ones that don't come bundled (and many do) are not safe. By using them you are effectively downloading from an unknown source, with all the dangers described above.


OK, so how do we set about protecting you.

You should definitely have one of each of the following programmes.
  • Firewall
  • Anti-Virus
  • Anti-Spyware
You do not need more than one of each. More than one will cause conflicts, and will not improve your security.

If you don't already have them, then these are links to lists of free programmes.
You'll increase your chances of not getting infected if you don't land on an infected website in the first place.

There are a couple of ways to do this
  • Block access to sites known to spread Malware.
  • Give you clear indication of which they are, so that you can make choices.
To block access to known bad sites we use a Hosts file.
  • Hosts file
  • Make sure you read the instructions here on how to install the hosts file.
To give you an indication of which sites may contain bad links or suspect downloads I like to use Site Advisor.
This is a utility that can be downloaded and installed. It loads an icon to the taskbar of your browser (versions for IE and Firefox), indicating the trustworthiness of the site you are on. Green for safe, Red for suspicious. Click on the icon to access details that SiteAdvisor has about the site. It also gives the same colour indications in the results page when you do a Google search, making it easier to decide which sites are safe to visit.

Remove known vulnerabilities
  • Update your Java
    Older versions have vulnerabilities that malware can and are using to infect systems.

    Please follow these steps to remove older version Java components.

  • Close any programmes you may have running, ESPECIALLY your web browser
  • Click Start > Control Panel.
  • Click Add/Remove Programs.
  • Check any item with Java Runtime Environment (JRE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove all versions of Java.
  • Reboot your computer once all Java components are removed.
Download the latest version of Java Runtime Environment (JRE) 6u6, and install it to your computer.

This is important as it's still possible to get infected through an old install even if you're using the latest version of Java.
  • Update Windows and Internet Explorer It is essential you keep your Operating System up to date with all the latest patches. The bad guys watch for the latest exploits, as soon as Microsoft brings out a patch, the bad guys will bring out an infection to exploit that vulnerability. If you don't have all the latest patches your computer is vulnerable. Please go to the windows update site and get the critical updates.
  • Use a "secure" browser Install Internet Explorer 7 or an alternative browser like Firefox or Opera for more secure surfing.
    Please remember that there is no such thing as a totally secure browser. Your browsing habits will be the major factor in determining just how safe you are online. If you visit, Crack/Warez sites, Porn sites, or other sites of a questionable nature, you still run a severe risk of getting infected.
  • Do not use P2P file sharing programmes I'd like you to read the Guidelines for P2P Programs where it's explained why it's not a good idea to have them.

    My recommendation is you go to Control Panel > Add/Remove Programs and uninstall any P2P programs you have installed.
  • Obviously you have probably already taken care of some of the issues mentioned, but it is important that you read through them, and address any that you may have missed.
Here's links to a few articles which are worth reading

Finally

NOW is the time you can start to hit back at the people who infected you.
[external image: Posted Image]
Please take the time to go and complain - that forum has a topic for your infection which is Vundo…….. (if not, post in the Is your infection not listed here? topic). Please post as a reply, you do not need to register to do so (but you can if you wish). It will also have a list of other places you can go to to register your complaint, depending on the country you are resident in. Please read the topics and complain, it is only with such complaints to government or government agencies that something will get done.

Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI