This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] nokia and samsung removal baseline

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello, after all the help you guys gave me earlier in the year i was wondering if you could take a look at this for me and give me your opinions?
i have on here both samsung and nokia packages from old mobile phones. i have a tried to remove both by going through add/remove progs but for some strange reason there still appears to be elements of both packages floating around, that prevent me from getting rid altogether. could you tell me where to go from here?

hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:57:43, on 23/06/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\BHROOT\BIN\NT611SVC.EXE
C:\BHROOT\BIN\monitor.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\BHROOT\BIN\PORTMAP.EXE
C:\WINDOWS\System32\svchost.exe
C:\BHROOT\BIN\DBMANG.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Nokia\Nokia PC Suite 6\ConnectionManager.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://gb8.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {4C4FD08B-7411-8914-7E32-5616B183926F} - C:\WINDOWS\System32\neveoiv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: (no name) - {8B68564D-53FD-4293-B80C-993A9F3988EE} - (no file)
O3 - Toolbar: eBay Toolbar - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - C:\Program Files\eBay\eBay Toolbar\4.3.0.9\eBayBand.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LanGuard] "C:\WINDOWS\languard.exe"
O4 - HKLM\..\Run: [cpds] C:\WINDOWS\cpds.exe
O4 - HKLM\..\Run: [scrbmk] "C:\WINDOWS\scrbmk.exe"
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera 301x
O4 - HKLM\..\Run: [ws3Q39S] dmbseq.exe
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKCU\..\Run: [hBs4RVe9e] dinns.exe
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global User Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: eBay Toolbar - {92D7F210-7F20-11d3-8157-0090278B20DE} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: eBay Toolbar - {92D7F210-7F20-11d3-8157-0090278B20DE} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1168367918046
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: bh611 - Bell& Howell - C:\BHROOT\BIN\NT611SVC.EXE
O23 - Service: Bell & Howell Monitor Service (BHMonitorService) - Bell & Howell - C:\BHROOT\BIN\monitor.exe
O23 - Service: Bell & Howell Database Manager (dbmang) - Bell & Howell - C:\BHROOT\BIN\DBMANG.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ONC/RPC Portmapper (portmapper) - Bell & Howell - C:\BHROOT\BIN\PORTMAP.EXE
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 6754 bytes


malware removal tool (as advised in your intro) log:

Malwarebytes' Anti-Malware 1.17
Database version: 846

22:32:04 23/06/2008
mbam-log-6-23-2008 (22-32-04).txt

Scan type: Quick Scan
Objects scanned: 43546
Time elapsed: 6 minute(s), 8 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 21
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 8
Files Infected: 32

Memory Processes Infected:
C:\Program Files\WinFixer 2006\wfxcwr.exe (Rogue.WinFixer) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{85e0b171-04fa-11d1-b7da-00a0c90348a7} (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\clientax.requiredcomponent (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\clientax.requiredcomponent.1 (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\clientax.zangoclientax (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\clientax.zangoclientax.1 (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mediagatewayx.installer (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mediagatewayx.installer.1 (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\clientax.clientinstaller (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\clientax.clientinstaller.1 (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\lmgr180.wmdrmax (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\lmgr180.wmdrmax.1 (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{054fda33-5b46-46ee-8e9e-924ef7d36058} (Rogue.WinFixer) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\fis.amo (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\fis.amo.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\fis.momo (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\fis.momo.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\fis.ohb (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\fis.ohb.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Zango (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WinFixer 2006 helper (Rogue.WinFixer) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\WinFixer 2006 (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\Backup (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\Download (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\Mp3DB (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\MpegDB (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\Repaired (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\Tasks (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\WaveDB (Rogue.WinFixer) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\WinFixer 2006\Activate.dat (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\Activate.exe (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\Activate.log (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\appupdate.dat (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\DataBase.sav (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\flash.ini (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\flfxr19.dll (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\FRec.dll (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\FWraper.dll (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\FxCore.dll (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\InstHelp.exe (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\lapv.dat (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\License.rtf (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\lock.dat (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\manual.pdf (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\MMFx.dll (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\Program.sav (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\ps.dat (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\pv.dat (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\sr.log (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\support.exe (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\trace.log (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\unins000.dat (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\unins000.exe (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\up.dat (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\update.log (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\updater.dat (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\Updater.exe (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\wfx6.url (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\wfxcwr.exe (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\Program Files\WinFixer 2006\WWFX6.exe (Rogue.WinFixer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\stera.exe (Rogue.WinAntivirus) -> Quarantined and deleted successfully.

worth a mention, both phones sold with all software etc ages ago so i dont have access to original software. is this anything you guys can help with?

–
End of file - 6754 bytes
i have a new amendment im afraid, think the rabbit hole goes deeper! i noticed that the pc didnt have service pack 2 (something i was sure id downloaded when i still lived with my mum!) so i thought id update that but it got about 80% through then said that it couldnnt continue and rolled back to before i started. same sort of thing when i tried to make sure that i had all the available windows updates. it seems that everything i try to download, upload, or remove, it wont complete. could it be some sort of virus or spyware making it work (or not as the case may be) like this? im going to stop playing around with it now till i hear from someone as im afriad i could end up making things worse. many thanx people!
[external image: Posted Image]

Sorry about the delay in responding :(

We look for post with 0 replies, so when you posted to your own log, we assumed you were being helped.

If you still need help, Scan again with HijackThis, and copy/paste" a new log file into this thread.

Also please describe how your computer behaves at the moment.
hi, and thanx for getting back to me. i knew i shouldnt have replied to my own log but i thought the information might be relevent so i took the chance. when i realised that was probably a mistake i re posted under a different heading (http://forums.whatthetech.com/findpost_p470123.html) but if you can help me on this line then could you shut down the other please?

so, on to the problem then. the pc seems to be working fine in itself, ie: not slow, no pop ups etc… The problen has come from the fact that i cant seem to A: delete the nokia and samsung phone applications (they get most of the way through then say that they cant complete the un-install process and roll back) and i cant seem to be able to install some things either (mainly microsoft packages) i recall seeing something about there being a problem with windows installer (which would make sense to me of limited knowledge) but i cant install any version of it from microsoft home.
hope that made sense….
so here is my hijackthis log, make of it what you will! :thumbup:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:06:45, on 30/06/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\BHROOT\BIN\NT611SVC.EXE
C:\BHROOT\BIN\monitor.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\BHROOT\BIN\PORTMAP.EXE
C:\WINDOWS\System32\svchost.exe
C:\BHROOT\BIN\DBMANG.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {4C4FD08B-7411-8914-7E32-5616B183926F} - C:\WINDOWS\System32\neveoiv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: (no name) - {8B68564D-53FD-4293-B80C-993A9F3988EE} - (no file)
O3 - Toolbar: eBay Toolbar - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - C:\Program Files\eBay\eBay Toolbar\4.3.0.9\eBayBand.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LanGuard] "C:\WINDOWS\languard.exe"
O4 - HKLM\..\Run: [cpds] C:\WINDOWS\cpds.exe
O4 - HKLM\..\Run: [scrbmk] "C:\WINDOWS\scrbmk.exe"
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera 301x
O4 - HKLM\..\Run: [ws3Q39S] dmbseq.exe
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKCU\..\Run: [hBs4RVe9e] dinns.exe
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global User Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: eBay Toolbar - {92D7F210-7F20-11d3-8157-0090278B20DE} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: eBay Toolbar - {92D7F210-7F20-11d3-8157-0090278B20DE} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} (Microsoft Genuine Advantage Self Support Tool) - http://go.microsoft.com/fwlink/?LinkId=82580
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1168367918046
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: bh611 - Bell& Howell - C:\BHROOT\BIN\NT611SVC.EXE
O23 - Service: Bell & Howell Monitor Service (BHMonitorService) - Bell & Howell - C:\BHROOT\BIN\monitor.exe
O23 - Service: Bell & Howell Database Manager (dbmang) - Bell & Howell - C:\BHROOT\BIN\DBMANG.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ONC/RPC Portmapper (portmapper) - Bell & Howell - C:\BHROOT\BIN\PORTMAP.EXE
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 7282 bytes

cheers for looking at this and giving me your time.
Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Give it atleast 20-30 minutes to finish
ok here goes….

combofix log:

ComboFix 08-06-20.4 - Owner 2008-06-30 22:17:35.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.242 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-30 )))))))))))))))))))))))))))))))
.

2008-06-26 20:44 . 2008-06-26 20:44 d–h-c— C:\WINDOWS\$MSI30UninstallMSI30-KB884016$
2008-06-26 19:43 . 2004-09-01 23:27 209,280 —–c— C:\WINDOWS\system32\dllcache\update.sys
2008-06-25 20:01 . 2008-06-25 20:01 d——– C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-06-24 07:31 . 2004-08-04 00:56 382,464 –a—— C:\WINDOWS\system32\SET127A.tmp
2008-06-24 07:31 . 2004-08-04 00:56 351,232 –a—— C:\WINDOWS\system32\SET1268.tmp
2008-06-24 07:30 . 2004-08-04 00:56 6,656 –a—— C:\WINDOWS\system32\SET1262.tmp
2008-06-24 07:21 . 2004-08-04 00:56 1,082,368 –a—— C:\WINDOWS\system32\SET7DF.tmp
2008-06-24 07:20 . 2004-08-04 00:56 3,003,392 –a—— C:\WINDOWS\system32\SET6EF.tmp
2008-06-24 07:19 . 2004-08-04 00:56 8,384,000 –a—— C:\WINDOWS\system32\SET4DB.tmp
2008-06-24 07:18 . 2004-08-04 00:56 723,456 –a—— C:\WINDOWS\system32\SET30A.tmp
2008-06-24 07:17 . 2004-08-04 00:56 359,936 –a—— C:\WINDOWS\system32\SET19A.tmp
2008-06-24 07:17 . 2004-08-04 00:56 264,192 –a—— C:\WINDOWS\system32\SET1C7.tmp
2008-06-24 07:17 . 2004-08-04 00:56 172,032 –a—— C:\WINDOWS\system32\SET1EF.tmp
2008-06-24 07:17 . 2004-08-04 00:56 92,672 –a—— C:\WINDOWS\system32\SET1DF.tmp
2008-06-24 07:17 . 2004-08-04 00:56 82,944 –a—— C:\WINDOWS\system32\SET1C0.tmp
2008-06-24 07:17 . 2004-08-04 00:56 22,528 –a—— C:\WINDOWS\system32\SET1A6.tmp
2008-06-24 07:17 . 2004-08-04 00:56 19,968 –a—— C:\WINDOWS\system32\SET1BF.tmp
2008-06-24 07:17 . 2004-08-04 00:56 19,968 –a—— C:\WINDOWS\system32\SET1A8.tmp
2008-06-24 07:17 . 2004-08-04 00:56 18,432 –a—— C:\WINDOWS\system32\SET1A2.tmp
2008-06-24 07:17 . 2004-08-04 00:56 5,632 –a—— C:\WINDOWS\system32\SET1DD.tmp
2008-06-24 07:12 . 2004-07-17 11:40 19,528 –a—— C:\WINDOWS\002438_.tmp
2008-06-24 07:10 . 2003-01-21 08:20 4,186,256 ——— C:\WINDOWS\system32\dllcache\luna.mst
2008-06-23 22:49 . 2008-06-23 22:49 d——– C:\Program Files\Trend Micro
2008-06-23 22:23 . 2008-06-23 22:28 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-06-23 22:23 . 2008-06-23 22:23 d——– C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-06-23 22:23 . 2008-06-23 22:23 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-23 22:23 . 2008-06-19 17:48 34,296 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-23 22:23 . 2008-06-19 17:47 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-06-23 22:19 . 2008-06-23 22:19 d——– C:\Program Files\Common Files\Download Manager
2008-06-23 21:58 . 2008-06-23 21:58 1,756 –a—— C:\WINDOWS\system32\WinSvc32\Adobe Reader Speed Launch.lnk
2008-06-23 21:23 . 2008-06-23 21:23 d——– C:\Program Files\Windows Installer Clean Up
2008-06-23 21:23 . 2008-06-23 21:23 d——– C:\Program Files\MSECACHE

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-25 18:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\Installations
2008-06-25 17:57 ——— d—–w C:\Program Files\Nokia
2008-06-23 21:06 ——— d—a-w C:\Program Files\Common Files\Adobe
2008-06-23 20:59 ——— d—–w C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-06-23 20:31 ——— d—–w C:\Program Files\Java
2008-06-23 19:57 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-06-23 19:54 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-23 19:54 ——— d—–w C:\Program Files\DivX
2008-06-23 19:52 ——— d—–w C:\Program Files\Common Files\Ahead
2008-06-23 19:52 ——— d—–w C:\Program Files\Ahead
2008-06-23 19:08 ——— d—a-w C:\Program Files\Microsoft Money
2008-06-23 19:07 ——— d—–w C:\Program Files\Google
2005-03-21 11:30 85 -c–a-w C:\Documents and Settings\Owner\delsmltr.bat
.

((((((((((((((((((((((((((((( snapshot@2008-06-26_ 7.49.17.33 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-26 06:41:54 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-30 21:21:13 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-03-24 18:33:02 1,527,056 —-a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.3\FP_AX_CAB_INSTALLER.exe
+ 2008-03-24 18:33:02 1,527,056 —-a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.4\FP_AX_CAB_INSTALLER.exe
- 2008-06-26 06:42:07 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-06-30 21:06:11 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-06-26 06:42:07 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-06-30 21:06:11 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-06-26 06:42:07 278,528 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-30 21:06:11 278,528 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2005-10-21 18:58:52 49,920 —-a-w C:\WINDOWS\system32\drivers\HPZid412.sys
+ 2005-10-22 06:22:48 21,568 —-a-w C:\WINDOWS\system32\drivers\HPZius12.sys
- 2003-01-20 17:23:00 137,088 —-a-w C:\WINDOWS\system32\drivers\update.sys
+ 2004-09-01 22:27:22 209,280 —-a-w C:\WINDOWS\system32\drivers\update.sys
+ 2005-10-25 15:27:28 286,720 —-a-w C:\WINDOWS\system32\HPZc3212.dll
- 2008-05-29 23:35:11 17,486,968 —-a-w C:\WINDOWS\system32\MRT.exe
+ 2008-05-29 15:35:12 17,486,968 —-a-w C:\WINDOWS\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4C4FD08B-7411-8914-7E32-5616B183926F}]
2002-01-13 01:52 74752 –a—— C:\WINDOWS\System32\neveoiv.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hBs4RVe9e"="dinns.exe" []
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2005-07-19 11:14 57344]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2005-06-24 14:08 860160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-08 00:04 52736]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-12 04:02 61440]
"SSC_UserPrompt"="C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [2004-11-02 17:59 218240]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-17 00:57 81920]
"LanGuard"="C:\WINDOWS\languard.exe" [ ]
"cpds"="C:\WINDOWS\cpds.exe" [ ]
"scrbmk"="C:\WINDOWS\scrbmk.exe" [2006-01-12 11:33 30733]
"BigDogPath"="C:\WINDOWS\VM_STI.EXE" [ ]
"ws3Q39S"="dmbseq.exe" []
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2005-07-19 11:06 40960]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 17:16 376912]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-06-29 15:29 176128]
"DataLayer"="C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-06-07 11:31 819712]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2004-12-14 12:24 263824]

C:\WINDOWS\system32\WinSvc32\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
"VIDC.I263"= i263_32.drv
"msacm.divxa32"= DivXa32.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli scecli scecli

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIEW]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

S3 mdxgthkn;mdxgthkn;C:\DOCUME~1\andrew\LOCALS~1\Temp\mdxgthkn.sys []
S3 Smc1046;EZ Connect USB to Dual Speed Ethernet Converter;C:\WINDOWS\System32\DRIVERS\SMCUSB.sys [2002-06-21 11:36]

.
Contents of the 'Scheduled Tasks' folder
"2005-07-04 00:35:16 C:\WINDOWS\Tasks\easy Internet sign-up.job"
- C:\Program Files\Easy Internet signup\HPSdpApp.exe
"2005-09-26 13:09:14 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-30 22:22:06
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\BHROOT\BIN\NT611SVC.EXE
C:\BHROOT\BIN\MONITOR.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\BHROOT\BIN\PORTMAP.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\BHROOT\BIN\DBMANG.EXE
.
**************************************************************************
.
Completion time: 2008-06-30 22:29:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-30 21:28:47
ComboFix2.txt 2008-06-26 06:50:27

Pre-Run: 64,920,571,904 bytes free
Post-Run: 64,910,069,760 bytes free

156 — E O F — 2008-06-12 10:16:38



hijackthis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:37:42, on 30/06/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\BHROOT\BIN\NT611SVC.EXE
C:\BHROOT\BIN\monitor.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\BHROOT\BIN\PORTMAP.EXE
C:\WINDOWS\System32\svchost.exe
C:\BHROOT\BIN\DBMANG.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {4C4FD08B-7411-8914-7E32-5616B183926F} - C:\WINDOWS\System32\neveoiv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: (no name) - {8B68564D-53FD-4293-B80C-993A9F3988EE} - (no file)
O3 - Toolbar: eBay Toolbar - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - C:\Program Files\eBay\eBay Toolbar\4.3.0.9\eBayBand.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LanGuard] "C:\WINDOWS\languard.exe"
O4 - HKLM\..\Run: [cpds] C:\WINDOWS\cpds.exe
O4 - HKLM\..\Run: [scrbmk] "C:\WINDOWS\scrbmk.exe"
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera 301x
O4 - HKLM\..\Run: [ws3Q39S] dmbseq.exe
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKCU\..\Run: [hBs4RVe9e] dinns.exe
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global User Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: eBay Toolbar - {92D7F210-7F20-11d3-8157-0090278B20DE} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: eBay Toolbar - {92D7F210-7F20-11d3-8157-0090278B20DE} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} (Microsoft Genuine Advantage Self Support Tool) - http://go.microsoft.com/fwlink/?LinkId=82580
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1168367918046
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: bh611 - Bell& Howell - C:\BHROOT\BIN\NT611SVC.EXE
O23 - Service: Bell & Howell Monitor Service (BHMonitorService) - Bell & Howell - C:\BHROOT\BIN\monitor.exe
O23 - Service: Bell & Howell Database Manager (dbmang) - Bell & Howell - C:\BHROOT\BIN\DBMANG.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ONC/RPC Portmapper (portmapper) - Bell & Howell - C:\BHROOT\BIN\PORTMAP.EXE
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 7124 bytes


thanx,
andy
The Nokia items aren't bad, but you said you want to ger rid of them.


Open notepad and copy/paste the text in the Codebox below into it:

File::
C:\WINDOWS\system32\SET127A.tmp
C:\WINDOWS\system32\SET1268.tmp
C:\WINDOWS\system32\SET1262.tmp
C:\WINDOWS\system32\SET7DF.tmp
C:\WINDOWS\system32\SET6EF.tmp
C:\WINDOWS\system32\SET4DB.tmp
C:\WINDOWS\system32\SET30A.tmp
C:\WINDOWS\system32\SET19A.tmp
C:\WINDOWS\system32\SET1C7.tmp
C:\WINDOWS\system32\SET1EF.tmp
C:\WINDOWS\system32\SET1DF.tmp
C:\WINDOWS\system32\SET1C0.tmp
C:\WINDOWS\system32\SET1A6.tmp
C:\WINDOWS\system32\SET1BF.tmp
C:\WINDOWS\system32\SET1A8.tmp
C:\WINDOWS\system32\SET1A2.tmp
C:\WINDOWS\system32\SET1DD.tmp
C:\WINDOWS\002438_.tmp
C:\WINDOWS\System32\neveoiv.dll
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\WINDOWS\cpds.exe
C:\WINDOWS\languard.exe
C:\WINDOWS\scrbmk.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\DOCUME~1\andrew\LOCALS~1\Temp\mdxgthkn.sys

Folder::
C:\Program Files\Nokia

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4C4FD08B-7411-8914-7E32-5616B183926F}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hBs4RVe9e"=-
"PcSync"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cpds"=-
"LanGuard"=-
"scrbmk"=-
"ws3Q39S"=-
"BJCFD"=-

Save this as Save this as "CFScript"


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
ok, this is my new combofix log:

ComboFix 08-06-20.4 - Owner 2008-07-01 0:51:05.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.266 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\DOCUME~1\andrew\LOCALS~1\Temp\mdxgthkn.sys
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\WINDOWS\002438_.tmp
C:\WINDOWS\cpds.exe
C:\WINDOWS\languard.exe
C:\WINDOWS\scrbmk.exe
C:\WINDOWS\System32\neveoiv.dll
C:\WINDOWS\system32\SET1262.tmp
C:\WINDOWS\system32\SET1268.tmp
C:\WINDOWS\system32\SET127A.tmp
C:\WINDOWS\system32\SET19A.tmp
C:\WINDOWS\system32\SET1A2.tmp
C:\WINDOWS\system32\SET1A6.tmp
C:\WINDOWS\system32\SET1A8.tmp
C:\WINDOWS\system32\SET1BF.tmp
C:\WINDOWS\system32\SET1C0.tmp
C:\WINDOWS\system32\SET1C7.tmp
C:\WINDOWS\system32\SET1DD.tmp
C:\WINDOWS\system32\SET1DF.tmp
C:\WINDOWS\system32\SET1EF.tmp
C:\WINDOWS\system32\SET30A.tmp
C:\WINDOWS\system32\SET4DB.tmp
C:\WINDOWS\system32\SET6EF.tmp
C:\WINDOWS\system32\SET7DF.tmp
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Nokia
C:\Program Files\Nokia\Connectivity Cable Driver\difxapi.dll
C:\Program Files\Nokia\Connectivity Cable Driver\nmwcd.cat
C:\Program Files\Nokia\Connectivity Cable Driver\nmwcd.inf
C:\Program Files\Nokia\Connectivity Cable Driver\nmwcd.sys
C:\Program Files\Nokia\Connectivity Cable Driver\nmwcdc.inf
C:\Program Files\Nokia\Connectivity Cable Driver\nmwcdc.sys
C:\Program Files\Nokia\Connectivity Cable Driver\nmwcdcj.inf
C:\Program Files\Nokia\Connectivity Cable Driver\nmwcdcj.sys
C:\Program Files\Nokia\Connectivity Cable Driver\nmwcdcls.dll
C:\Program Files\Nokia\Connectivity Cable Driver\nmwcdcm.sys
C:\Program Files\Nokia\Connectivity Cable Driver\nmwcdcocls.dll
C:\Program Files\Nokia\Connectivity Cable Driver\nmwcdm2k.inf
C:\Program Files\Nokia\Connectivity Cable Driver\setupext.exe
C:\Program Files\Nokia\Nokia PC Suite 6\ApplicationInstaller.exe
C:\Program Files\Nokia\Nokia PC Suite 6\AudioManager.exe
C:\Program Files\Nokia\Nokia PC Suite 6\cdmgr.dll
C:\Program Files\Nokia\Nokia PC Suite 6\CDSAccess.dll
C:\Program Files\Nokia\Nokia PC Suite 6\CommonDS.dll
C:\Program Files\Nokia\Nokia PC Suite 6\CommonSelectDevice.dll
C:\Program Files\Nokia\Nokia PC Suite 6\ConnectionManager-BTPlg.dll
C:\Program Files\Nokia\Nokia PC Suite 6\ConnectionManager-SerialPlg.dll
C:\Program Files\Nokia\Nokia PC Suite 6\ConnectionManager.cpl
C:\Program Files\Nokia\Nokia PC Suite 6\ConnectionManager.exe
C:\Program Files\Nokia\Nokia PC Suite 6\ContactPrinterDetailed.xsl
C:\Program Files\Nokia\Nokia PC Suite 6\ContactsEditor.exe
C:\Program Files\Nokia\Nokia PC Suite 6\ContactView.dll
C:\Program Files\Nokia\Nokia PC Suite 6\ContentCopier.exe
C:\Program Files\Nokia\Nokia PC Suite 6\data.ms
C:\Program Files\Nokia\Nokia PC Suite 6\GetConnected.exe
C:\Program Files\Nokia\Nokia PC Suite 6\Help\PCSuite_eng.CHM
C:\Program Files\Nokia\Nokia PC Suite 6\ImageConverter.exe
C:\Program Files\Nokia\Nokia PC Suite 6\ImageConverter_coc.dll
C:\Program Files\Nokia\Nokia PC Suite 6\ImageConverter_gl.dll
C:\Program Files\Nokia\Nokia PC Suite 6\ImageStore.exe
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\ApplicationInstaller_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\AudioManager_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\CommonSelectDevice_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\ConnectionManager-SerialPlg_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\ConnectionManager_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\ContactsEditor_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\ContentCopier_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\GetConnected_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\ImageConverter_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\ImageStore_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\LaunchApplication_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\MultimediaPlayer_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\OneTouchAccess_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\PCSCM_eng.nlr
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\PcSync2_eng.nlr
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\SearchEngine_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\SoundConverter_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\Lang\TextMessageEditor_eng.NLR
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Nokia\Nokia PC Suite 6\mcl.dll
C:\Program Files\Nokia\Nokia PC Suite 6\MessageView.dll
C:\Program Files\Nokia\Nokia PC Suite 6\MultimediaPlayer.exe
C:\Program Files\Nokia\Nokia PC Suite 6\namcore.dll
C:\Program Files\Nokia\Nokia PC Suite 6\NAMUI.dll
C:\Program Files\Nokia\Nokia PC Suite 6\ndlex.dll
C:\Program Files\Nokia\Nokia PC Suite 6\Nokia PC Suite.msi
C:\Program Files\Nokia\Nokia PC Suite 6\Nokia.dll
C:\Program Files\Nokia\Nokia PC Suite 6\Notes50_11.dll
C:\Program Files\Nokia\Nokia PC Suite 6\OneTouchAccess.exe
C:\Program Files\Nokia\Nokia PC Suite 6\operators.xml
C:\Program Files\Nokia\Nokia PC Suite 6\Org50.dll
C:\Program Files\Nokia\Nokia PC Suite 6\Outlook2.dll
C:\Program Files\Nokia\Nokia PC Suite 6\OutlookX.dll
C:\Program Files\Nokia\Nokia PC Suite 6\PC_Suite_eng.pdf
C:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll
C:\Program Files\Nokia\Nokia PC Suite 6\PCSL.dll
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSyncLV.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
C:\Program Files\Nokia\Nokia PC Suite 6\Progress2.dll
C:\Program Files\Nokia\Nokia PC Suite 6\Readme.htm
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\ApplicationInstaller_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\AudioManager_Nokia.ngr
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\CommonSelectDevice_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\ConnectionManager-SerialPlg_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\ConnectionManager_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\ContactsEditor_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\ContentCopier_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\GetConnected_Nokia.ngr
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\ImageConverter_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\ImageStore_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\LaunchApplication_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\MultimediaPlayer_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\OneTouchAccess_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\PCSCM_Nokia.ngr
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\PcSync2_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\SearchEngine_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\SoundConverter_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\Resource\TextMessageEditor_Nokia.NGR
C:\Program Files\Nokia\Nokia PC Suite 6\SearchEngine.dll
C:\Program Files\Nokia\Nokia PC Suite 6\SeUpdateDb.exe
C:\Program Files\Nokia\Nokia PC Suite 6\Skins\audio_player.nms
C:\Program Files\Nokia\Nokia PC Suite 6\Skins\generic.nms
C:\Program Files\Nokia\Nokia PC Suite 6\Skins\marbling.nms
C:\Program Files\Nokia\Nokia PC Suite 6\Skins\night_sky.nms
C:\Program Files\Nokia\Nokia PC Suite 6\Skins\silver.nms
C:\Program Files\Nokia\Nokia PC Suite 6\Skins\silver_star.nms
C:\Program Files\Nokia\Nokia PC Suite 6\SMSSetup.dll
C:\Program Files\Nokia\Nokia PC Suite 6\SoundConverter.exe
C:\Program Files\Nokia\Nokia PC Suite 6\SyncControl.dll
C:\Program Files\Nokia\Nokia PC Suite 6\Synch.dll
C:\Program Files\Nokia\Nokia PC Suite 6\SynchSetup.dll
C:\Program Files\Nokia\Nokia PC Suite 6\synclic.dll
C:\Program Files\Nokia\Nokia PC Suite 6\TextMessageEditor.exe
C:\Program Files\Nokia\Nokia PC Suite 6\vCard.dll
C:\Program Files\Nokia\Nokia PC Suite 6\VFSWrapper.exe
C:\Program Files\Nokia\Nokia PC Suite 6\Wadrb.dll
C:\WINDOWS\002438_.tmp
C:\WINDOWS\scrbmk.exe
C:\WINDOWS\System32\neveoiv.dll
C:\WINDOWS\system32\SET1262.tmp
C:\WINDOWS\system32\SET1268.tmp
C:\WINDOWS\system32\SET127A.tmp
C:\WINDOWS\system32\SET19A.tmp
C:\WINDOWS\system32\SET1A2.tmp
C:\WINDOWS\system32\SET1A6.tmp
C:\WINDOWS\system32\SET1A8.tmp
C:\WINDOWS\system32\SET1BF.tmp
C:\WINDOWS\system32\SET1C0.tmp
C:\WINDOWS\system32\SET1C7.tmp
C:\WINDOWS\system32\SET1DD.tmp
C:\WINDOWS\system32\SET1DF.tmp
C:\WINDOWS\system32\SET1EF.tmp
C:\WINDOWS\system32\SET30A.tmp
C:\WINDOWS\system32\SET4DB.tmp
C:\WINDOWS\system32\SET6EF.tmp
C:\WINDOWS\system32\SET7DF.tmp

.
((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-30 )))))))))))))))))))))))))))))))
.

2008-06-26 20:44 . 2008-06-26 20:44 d–h-c— C:\WINDOWS\$MSI30UninstallMSI30-KB884016$
2008-06-26 19:43 . 2004-09-01 23:27 209,280 —–c— C:\WINDOWS\system32\dllcache\update.sys
2008-06-25 20:01 . 2008-06-25 20:01 d——– C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-06-24 07:21 . 2004-08-04 00:56 678,400 –a—— C:\WINDOWS\system32\SET78F.tmp
2008-06-24 07:20 . 2004-08-03 22:19 1,351,168 –a—— C:\WINDOWS\system32\SET6EB.tmp
2008-06-24 07:19 . 2004-08-04 00:56 1,708,032 –a—— C:\WINDOWS\system32\SET65F.tmp
2008-06-24 07:18 . 2004-08-04 00:56 713,216 –a—— C:\WINDOWS\system32\SET3F1.tmp
2008-06-24 07:11 . 2003-03-04 02:44 2,951,306 –a—— C:\WINDOWS\system32\nv4_disp.dll
2008-06-24 07:10 . 2003-01-21 08:20 4,186,256 ——— C:\WINDOWS\system32\dllcache\luna.mst
2008-06-23 22:49 . 2008-06-23 22:49 d——– C:\Program Files\Trend Micro
2008-06-23 22:23 . 2008-06-23 22:28 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-06-23 22:23 . 2008-06-23 22:23 d——– C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-06-23 22:23 . 2008-06-23 22:23 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-23 22:23 . 2008-06-19 17:48 34,296 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-23 22:23 . 2008-06-19 17:47 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-06-23 22:19 . 2008-06-23 22:19 d——– C:\Program Files\Common Files\Download Manager
2008-06-23 21:58 . 2008-06-23 21:58 1,756 –a—— C:\WINDOWS\system32\WinSvc32\Adobe Reader Speed Launch.lnk
2008-06-23 21:23 . 2008-06-23 21:23 d——– C:\Program Files\Windows Installer Clean Up
2008-06-23 21:23 . 2008-06-23 21:23 d——– C:\Program Files\MSECACHE

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-25 18:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\Installations
2008-06-23 21:06 ——— d—a-w C:\Program Files\Common Files\Adobe
2008-06-23 20:59 ——— d—–w C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-06-23 20:31 ——— d—–w C:\Program Files\Java
2008-06-23 19:57 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-06-23 19:54 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-23 19:54 ——— d—–w C:\Program Files\DivX
2008-06-23 19:52 ——— d—–w C:\Program Files\Common Files\Ahead
2008-06-23 19:52 ——— d—–w C:\Program Files\Ahead
2008-06-23 19:08 ——— d—a-w C:\Program Files\Microsoft Money
2008-06-23 19:07 ——— d—–w C:\Program Files\Google
2005-03-21 11:30 85 -c–a-w C:\Documents and Settings\Owner\delsmltr.bat
.

((((((((((((((((((((((((((((( snapshot@2008-06-26_ 7.49.17.33 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-26 06:41:54 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-30 23:54:02 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-03-24 18:33:02 1,527,056 —-a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.3\FP_AX_CAB_INSTALLER.exe
+ 2008-03-24 18:33:02 1,527,056 —-a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.4\FP_AX_CAB_INSTALLER.exe
- 2008-06-26 06:42:07 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-06-30 23:54:04 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-06-26 06:42:07 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-06-30 23:54:04 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-06-26 06:42:07 278,528 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-30 23:54:04 278,528 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2005-10-21 18:58:52 49,920 —-a-w C:\WINDOWS\system32\drivers\HPZid412.sys
+ 2005-10-22 06:22:48 21,568 —-a-w C:\WINDOWS\system32\drivers\HPZius12.sys
- 2003-01-20 17:23:00 137,088 —-a-w C:\WINDOWS\system32\drivers\update.sys
+ 2004-09-01 22:27:22 209,280 —-a-w C:\WINDOWS\system32\drivers\update.sys
+ 2005-10-25 15:27:28 286,720 —-a-w C:\WINDOWS\system32\HPZc3212.dll
- 2008-05-29 23:35:11 17,486,968 —-a-w C:\WINDOWS\system32\MRT.exe
+ 2008-05-29 15:35:12 17,486,968 —-a-w C:\WINDOWS\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2005-07-19 11:14 57344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-08 00:04 52736]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-12 04:02 61440]
"SSC_UserPrompt"="C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [2004-11-02 17:59 218240]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-17 00:57 81920]
"BigDogPath"="C:\WINDOWS\VM_STI.EXE" [ ]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2005-07-19 11:06 40960]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [ ]
"DataLayer"="C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-06-07 11:31 819712]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2004-12-14 12:24 263824]

C:\WINDOWS\system32\WinSvc32\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
"VIDC.I263"= i263_32.drv
"msacm.divxa32"= DivXa32.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli scecli scecli

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIEW]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

S3 mdxgthkn;mdxgthkn;C:\DOCUME~1\andrew\LOCALS~1\Temp\mdxgthkn.sys []
S3 Smc1046;EZ Connect USB to Dual Speed Ethernet Converter;C:\WINDOWS\System32\DRIVERS\SMCUSB.sys [2002-06-21 11:36]

.
Contents of the 'Scheduled Tasks' folder
"2005-07-04 00:35:16 C:\WINDOWS\Tasks\easy Internet sign-up.job"
- C:\Program Files\Easy Internet signup\HPSdpApp.exe
"2005-09-26 13:09:14 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-01 00:54:26
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\BHROOT\BIN\NT611SVC.EXE
C:\BHROOT\BIN\MONITOR.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\BHROOT\BIN\PORTMAP.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\BHROOT\BIN\DBMANG.EXE
.
**************************************************************************
.
Completion time: 2008-07-01 1:01:28 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-01 00:00:28
ComboFix2.txt 2008-06-30 21:29:36
ComboFix3.txt 2008-06-26 06:50:27

Pre-Run: 64,822,689,792 bytes free
Post-Run: 64,749,178,880 bytes free

300 — E O F — 2008-06-12 10:16:38

and this is my new hjackrhis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:05:32, on 01/07/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\BHROOT\BIN\NT611SVC.EXE
C:\BHROOT\BIN\monitor.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\BHROOT\BIN\PORTMAP.EXE
C:\WINDOWS\System32\svchost.exe
C:\BHROOT\BIN\DBMANG.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: (no name) - {8B68564D-53FD-4293-B80C-993A9F3988EE} - (no file)
O3 - Toolbar: eBay Toolbar - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - C:\Program Files\eBay\eBay Toolbar\4.3.0.9\eBayBand.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera 301x
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global User Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: eBay Toolbar - {92D7F210-7F20-11d3-8157-0090278B20DE} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: eBay Toolbar - {92D7F210-7F20-11d3-8157-0090278B20DE} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} (Microsoft Genuine Advantage Self Support Tool) - http://go.microsoft.com/fwlink/?LinkId=82580
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1168367918046
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: bh611 - Bell& Howell - C:\BHROOT\BIN\NT611SVC.EXE
O23 - Service: Bell & Howell Monitor Service (BHMonitorService) - Bell & Howell - C:\BHROOT\BIN\monitor.exe
O23 - Service: Bell & Howell Database Manager (dbmang) - Bell & Howell - C:\BHROOT\BIN\DBMANG.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ONC/RPC Portmapper (portmapper) - Bell & Howell - C:\BHROOT\BIN\PORTMAP.EXE
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 6453 bytes

the nokia things still appear to be there, and so far pc appears to be working the same?
andy
sorry, that would help wouldnt it?
nokia still on system, under all programs and still seeing it under add/remove programs. cant see if its just a case of uninstalling them because i get the message ' error 1719. windows installer service could not be accessed. this could occur if you are runnning windows in safe mode or if windows installer is not properly installed'
i think this may be the main part of the issue because i get similar reasons why i cant do anything with the pc?
1. Go to the control panel 2. Open "Computer Management" 3. On the left there should be a tab labelled "Services and Applications", click the + to expand it 4. Highlight the "Services" subsection of "Services and Applications" 5. On the right there hsould be a long list of services, under which is "Windows Installer" 6. Right click on "Windows Installer" and go to properties 7. Make sure the start-up type is on "Automatic" 8. Press OK, close the Computer Management, close Control Panel Reboot and let me know if that solved the problem

afraid there is no change, restarted and tried again but still no good.

Was the service running?

1. Log on to your computer as an administrator or an account with administrator rights.
2. Click Start, and then click Run.
3. In the Open box, type cmd, and then click OK.
4. At the command prompt, copy/paste or type in msiexec.exe /unregister, and then press ENTER.
5. Copy/paste or type in msiexec /regserver, and then press ENTER.

Note the space c /r

Reboot
better, it got to the nokia uninstall program but stopped with message saying 'error1402. could not open key: unknown\3g2\nokia.multimedia. verify that you have access to that key or contact your support personnel' then it says rolling back action, then another message 'error: - 1603 fatal error during installation. consult windows installer help (msi.chm) or msdn for more information'
but it did get further…. :thumbup:
You can try this:


Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe




Click "Start"> "Run"> type in Regedit tap Enter Key

Make sure "My Computer" is highlighted

Click "Edit"> "Find"
Type in nokia tap Enter Key.
Right Click on the file if found and select "Delete"

Tap the "F3" Key to find the next entry of the file. Continue using the "F3" Key until it's finished searching.

Close Regedit.


Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.
Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI