This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

help with kavo.exe. tavo.exe. tt.exe 2.exe

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Norton never dealt with these files (bsv.dll, jxsfsf.dll, and 98hgb.dll) until after the flashdrives were inserted to see if they were clean. The virus alerts of these files popped up whenever…didn't correlated with tavo and ckvo.exe. I did the system restore and there wasn't any more tavo and ckvo exe error msgs but bsv.dll, jxsfsf.dll, and 98hgb.dll files of Norton virus alerts showed up. I didn't know if this is important but when I was following your steps of running the Flash_Disinfector file Norton virus alert popped up saying the Flash_Disinfector was dangerous and asked me if I wanted to continue performing the task. I continued the task because I thought Norton might not know about the flash disinfector program. Today when I turned the PC on. Norton virus alerts had p.dll and zb5ok.dll popped up when windows started. bsv.dll, jxsfsf.dll, and 98hgb.dll virus alerts didn't show up during start up. The fonts on websites are different now…this site, facebook, gmail…. Thanks for all the help. I do hope this gets fixed.
My dad had avast! scan on his dell laptop. He just scanned the flashdrives during safe mode. The flashdrive that infected my laptop had cm0.com and lsfjg.com trojan vrius and my flashdrive had lsfjg.com virus. Even thought we deleted the viruses the scan result still popped up lsfjg.com for several times. I googled lsfjg.com and I saw another thread on this forum site that someone else also got lsfijg file on their flashdrive. The tech that helped in the thread didn't help to clean but advised to get a new flashdrive. If lsfjg.com-infected flashdrives have no alternative ways to get rid of it…we can invest new flashdrives and never have to deal with these old ones. My PC still have those Norton pop ups so I'm wondering if I should system restore my PC back to the point before I messed with flashdrives on my PC? Also, what would you recommend to scan the external hd? Thanks!
Alright, kavo and 2.exe pop ups came back when I turned on the PC just now. Past two times PC didn't have any error pop ups and only had Norton virus alert pop ups. I tried to system restore back to the point before I used the flashdrive but the PC couldn't restore back to that point becase no changes have been made since then. I'm wondering if I need to go through hijackthis, ATF cleaner, combofix, and mbam programs to clean my PC again.
Update MBAM, then insert your flashdrive and run a Full Scan. Make you sure you also select the drive letter of your flashdrive as well as you HDD letter before you start the scan. I'll have the log and a fresh HJT one once it's done. Also let me know how the PC is behaving.
So far PC has a lot of Norton virus pop ups with a lot more of file names that I haven't seen before. Sometimes Kavo, Tavo, 2.exe. pops up during windows starts but sometimes not. PC is running a little slow…i guess it's about the same as before when I asked for help on this site. Anyway, here's my MBAM log: Malwarebytes' Anti-Malware 1.20 Database version: 944 Windows 5.1.2600 Service Pack 2 1:42:28 AM 7/13/2008 mbam-log-7-13-2008 (01-42-23).txt Scan type: Full Scan (C:\|F:\|) Objects scanned: 96513 Time elapsed: 16 minute(s), 52 second(s) Memory Processes Infected: 0 Memory Modules Infected: 2 Registry Keys Infected: 0 Registry Values Infected: 2 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 13 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\kavo1.dll (Rootkit.Agent) -> No action taken. C:\WINDOWS\system32\tavo0.dll (Rootkit.Agent) -> No action taken. Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kava (Rootkit.Agent) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tava (Rootkit.Agent) -> No action taken. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> No action taken. Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\kavo0.dll (Rootkit.Agent) -> No action taken. C:\WINDOWS\system32\kavo1.dll (Rootkit.Agent) -> No action taken. C:\WINDOWS\system32\tavo0.dll (Rootkit.Agent) -> No action taken. C:\WINDOWS\system32\tavo1.dll (Rootkit.Agent) -> No action taken. C:\WINDOWS\system32\kavo.exe (Rootkit.Agent) -> No action taken. C:\WINDOWS\system32\tavo.exe (Rootkit.Agent) -> No action taken. C:\Documents and Settings\Cindy Lin\Local Settings\Temp\tru1.tmp (Trojan.Agent) -> No action taken. C:\Documents and Settings\Cindy Lin\Local Settings\Temp\tru2.tmp (Trojan.Agent) -> No action taken. C:\Documents and Settings\Cindy Lin\Local Settings\Temp\tru3.tmp (Trojan.Agent) -> No action taken. C:\Documents and Settings\Cindy Lin\Local Settings\Temp\tru4.tmp (Trojan.Agent) -> No action taken. C:\Documents and Settings\Cindy Lin\Local Settings\Temp\tru5.tmp (Trojan.Agent) -> No action taken. C:\Documents and Settings\Cindy Lin\Local Settings\Temp\tru6.tmp (Trojan.Agent) -> No action taken. C:\Documents and Settings\Cindy Lin\Local Settings\Temp\tru7.tmp (Trojan.Agent) -> No action taken.
I honestly hope the stuffs I got now are the same I got before…and can get rid of those like last time.

Here's HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:44:31 AM, on 7/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AOL Search Enhancement - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PartSeal] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD42/JSCDL/jre/6u…ows-i586-jc.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

–
End of file - 10449 bytes
I guess I did because here's another log from the same scan…. I think I gave you the log it produced right after the scan, and it updated the log after I looked at the results and deleted the files. PC still has kavo.exe. error msg popped up but those annoying Norton virus pop ups are nowhere to be seen. Malwarebytes' Anti-Malware 1.20 Database version: 944 Windows 5.1.2600 Service Pack 2 1:42:45 AM 7/13/2008 mbam-log-7-13-2008 (01-42-45).txt Scan type: Full Scan (C:\|F:\|) Objects scanned: 96513 Time elapsed: 16 minute(s), 52 second(s) Memory Processes Infected: 0 Memory Modules Infected: 2 Registry Keys Infected: 0 Registry Values Infected: 2 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 13 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\kavo1.dll (Rootkit.Agent) -> Unloaded module successfully. C:\WINDOWS\system32\tavo0.dll (Rootkit.Agent) -> Unloaded module successfully. Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kava (Rootkit.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tava (Rootkit.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\kavo0.dll (Rootkit.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\kavo1.dll (Rootkit.Agent) -> Delete on reboot. C:\WINDOWS\system32\tavo0.dll (Rootkit.Agent) -> Delete on reboot. C:\WINDOWS\system32\tavo1.dll (Rootkit.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\kavo.exe (Rootkit.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tavo.exe (Rootkit.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Cindy Lin\Local Settings\Temp\tru1.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Cindy Lin\Local Settings\Temp\tru2.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Cindy Lin\Local Settings\Temp\tru3.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Cindy Lin\Local Settings\Temp\tru4.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Cindy Lin\Local Settings\Temp\tru5.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Cindy Lin\Local Settings\Temp\tru6.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Cindy Lin\Local Settings\Temp\tru7.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
hey, actually I kinda forgot because I have been getting those error msgs so many times that I don't notice what they are anymore. Sometimes i get those msgs but sometimes not, like earlier I didn't see any pop ups when I turned the PC on…didn't see any either when I restarted the PC, which is weird cuz before (before when we did all this stuffs to PC and when i still had those thing infected) i get pop ups everytime i turned PC on. I'm guessing MBAM sorta took caresome of the malware…but I do get pop ups once in a while. However, I think it's malware created because the pop up would have kavo.exe., ckvo.exe., tavo.exe. or 2.exe. as the error title and it would read something like this: "memory cannot be read at "00xxo2ih124" and cannot be performed". and you can only click ok or the xed out button. The message is something along those lines. If there's a pop up shows up I'll print screen and show it to you. Do you have any idea what's going right now? Should I run combofix again…?

Should I run combofix again…?

Get hold of a fresh copy as sUBs updates regularly. You can skip the Recovery Console step as per the original link as you've already done that and once is sufficient for that.
Let me have the CF log, a fresh HJT log and PC description as always.
I didn't know how to update the sUBs so I just redownload the CF program. I have the pop up in print screen! It popped up when I started PC earlier.

Here's Combofix log:

ComboFix 08-07-14.2 - Cindy Lin 2008-07-14 18:02:46.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.575 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
C:\DOCUME~1\CINDYL~1\LOCALS~1\Temp\p.dll
C:\DOCUME~1\CINDYL~1\LOCALS~1\Temp\zb5ok.dll
C:\ffojc.com
C:\hgu.bat
C:\nqgcd.com
C:\WINDOWS\system32\ckvo.exe
C:\WINDOWS\system32\ckvo0.dll

.
((((((((((((((((((((((((( Files Created from 2008-06-14 to 2008-07-14 )))))))))))))))))))))))))))))))
.

2008-07-14 02:21 . 2008-07-14 13:31 118,512 -r-hs—- C:\fi.cmd
2008-07-09 22:21 . 2008-07-14 13:31 77,312 -r-hs—- C:\WINDOWS\system32\ckvo1.dll
2008-07-09 21:29 . 2008-07-09 21:51 132,540 -r-hs—- C:\lsfjg.com
2008-07-09 18:43 . 2002-06-21 15:09 160,217 –a—— C:\WINDOWS\system32\PowerToysLicense.rtf
2008-07-09 18:25 . 2008-07-09 18:25 d——– C:\Documents and Settings\Cindy Lin\Contacts
2008-07-09 18:22 . 2008-07-09 18:22 d——– C:\Program Files\MSN Messenger
2008-07-08 23:17 . 2008-07-08 23:18 d——– C:\Documents and Settings\Cindy Lin\Application Data\wsInspector
2008-07-08 23:10 . 2008-07-08 23:14 d——– C:\Program Files\Startup Inspector for Windows
2008-07-06 13:49 . 2008-07-13 01:07 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-07-06 13:49 . 2008-07-06 13:49 d——– C:\Documents and Settings\Cindy Lin\Application Data\Malwarebytes
2008-07-06 13:49 . 2008-07-06 13:49 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-06 13:49 . 2008-07-07 17:35 34,296 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-06 13:49 . 2008-07-07 17:35 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-07-04 19:24 . 2008-07-05 18:32 127,171 -r-hs—- C:\8uot.exe
2008-07-04 03:38 . 2008-07-04 03:38 d——– C:\Documents and Settings\Cindy Lin\Application Data\Uniblue
2008-07-04 00:32 . 2008-07-04 00:32 d——– C:\WINDOWS\F4C9398FB6C64A4B8B6D795CD86F915D.TMP
2008-07-03 22:59 . 2002-08-15 19:59 123,619 –a—— C:\WINDOWS\system32\SYMEVNT.386
2008-07-03 22:59 . 2002-08-15 19:59 83,672 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2008-07-03 22:59 . 2002-08-15 19:59 73,224 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-07-03 22:59 . 2002-08-14 06:03 34,578 –a—— C:\WINDOWS\system32\drivers\NPDRIVER.SYS
2008-07-03 22:59 . 2008-07-03 22:59 272 –a—— C:\WINDOWS\_delis32.ini
2008-07-03 22:59 . 2008-07-03 22:59 32 –ahs—- C:\WINDOWS\system32\{444EB6FB-0905-4C7A-B99F-49345407597B}.dat
2008-07-03 22:59 . 2008-07-03 22:59 32 –ahs—- C:\WINDOWS\{FC48DBCB-77BE-4A5B-9118-DBDA3A0010E8}.dat
2008-07-03 22:59 . 2008-07-03 22:59 14 –a—— C:\WINDOWS\system32\SR2.dat
2008-07-03 22:58 . 2008-07-03 23:09 d——– C:\Program Files\Norton AntiVirus
2008-07-03 22:58 . 2008-07-03 22:58 d——– C:\Documents and Settings\Cindy Lin\Application Data\Symantec
2008-06-22 15:39 . 2004-08-10 07:00 811,064 –a—— C:\WINDOWS\system32\imjp81k.dll
2008-06-15 19:16 . 2008-06-16 20:14 d——– C:\Documents and Settings\Cindy Lin\Application Data\DivX
2008-06-15 19:12 . 2008-06-15 19:12 d——– C:\Program Files\DivX
2008-06-15 19:12 . 2008-05-22 17:22 129,784 ——— C:\WINDOWS\system32\pxafs.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-14 22:55 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-07-08 06:02 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-07-05 09:40 ——— d—–w C:\Program Files\Trend Micro
2008-07-04 03:59 ——— d—–w C:\Program Files\Symantec
2008-07-04 03:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-04 20:37 ——— d—–w C:\Program Files\Quicken
2008-06-04 20:19 ——— d—–w C:\Program Files\Google
2008-06-04 05:14 ——— d—–w C:\Program Files\Java
2008-06-04 05:09 ——— d—–w C:\Program Files\Windows Media Connect 2
2008-06-04 05:06 ——— d—–w C:\Program Files\Windows Media Connect
2008-06-04 05:04 ——— d—–w C:\Program Files\Common Files\Adobe
2008-06-04 04:36 ——— d—–w C:\Documents and Settings\Cindy Lin\Application Data\acccore
2008-06-04 04:28 ——— d—–w C:\Program Files\AIM6
2008-06-04 04:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-06-04 04:10 ——— d—–w C:\Program Files\Common Files\AOL
2008-06-03 06:51 0 —ha-r C:\WINDOWS\system32\drivers\Sony_VGN-FE670G.mrk
2008-06-03 06:43 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-03 06:43 ——— d—–w C:\Program Files\InterVideo
2008-06-03 06:43 ——— d—–w C:\Program Files\Common Files\InterVideo
2008-06-03 06:42 ——— d—–w C:\Program Files\Sony
2008-06-03 06:42 ——— d—–w C:\Program Files\Microsoft Digital Image 2006
2008-06-03 06:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-06-03 06:40 ——— d—–w C:\Program Files\Netscape
2008-06-03 06:33 ——— d—–w C:\Program Files\Common Files\Sony Shared
2008-06-03 06:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\VAIO Media Platform
2008-06-03 06:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sony Corporation
2008-06-03 06:31 ——— d—–w C:\WINDOWS\system32\config\systemprofile\Application Data\Intuit
2008-06-03 06:31 ——— d—–w C:\Documents and Settings\Cindy Lin\Application Data\Intuit
2008-06-03 06:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Intuit
2008-06-03 06:31 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Intuit
2008-06-03 06:26 ——— d—–w C:\Program Files\Microsoft Works
2008-06-03 06:25 ——— d—–w C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
2008-06-03 06:15 ——— d—–w C:\WINDOWS\system32\config\systemprofile\Application Data\Sony Corporation
2008-06-03 06:15 ——— d—–w C:\Documents and Settings\Cindy Lin\Application Data\Sony Corporation
2008-06-03 06:15 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Sony Corporation
2008-05-30 23:22 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-05-30 23:22 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2008-05-30 23:22 815,104 —-a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-05-30 23:22 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2008-05-30 23:22 683,520 —-a-w C:\WINDOWS\system32\DivX.dll
2008-05-30 23:22 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-05-30 23:22 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2008-05-30 23:22 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-05-30 23:22 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2008-05-30 23:22 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2008-05-30 23:22 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
2008-05-22 22:22 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2008-05-22 22:22 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-05-22 22:22 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:22 120,056 ——w C:\WINDOWS\system32\pxcpyi64.exe
2008-05-22 22:22 118,520 ——w C:\WINDOWS\system32\pxinsi64.exe
2008-05-22 22:20 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2008-05-22 22:20 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2008-05-22 22:19 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2008-05-22 22:19 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2008-05-22 22:19 161,096 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-22 22:18 12,288 —-a-w C:\WINDOWS\system32\DivXWMPExtType.dll
.

((((((((((((((((((((((((((((( snapshot@2008-07-05_19.29.19.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-09 23:23:08 29,926 —-a-r C:\WINDOWS\Installer\{571700F0-DB9D-4B3A-B03D-35A14BB5939F}\MsblIco.Exe
+ 2001-05-22 06:00:00 22,016 –s-a-w C:\WINDOWS\system32\borlndmm.dll
+ 2005-07-26 04:39:43 498,688 -c–a-w C:\WINDOWS\system32\dllcache\clbcatq.dll
+ 2004-08-10 12:00:00 792,064 -c–a-w C:\WINDOWS\system32\dllcache\comres.dll
+ 2004-08-10 12:00:00 55,632 -c–a-w C:\WINDOWS\system32\dllcache\dwil1033.dll
+ 2004-08-10 12:00:00 22,016 -c–a-w C:\WINDOWS\system32\dllcache\lpk.dll
+ 2004-08-10 12:00:00 159,232 -c–a-w C:\WINDOWS\system32\dllcache\msimtf.dll
+ 2004-08-10 12:00:00 431,616 -c–a-w C:\WINDOWS\system32\dllcache\riched20.dll
+ 2004-08-10 12:00:00 152,576 -c–a-w C:\WINDOWS\system32\dllcache\rsaenh.dll
+ 2005-09-23 03:05:29 8,450,560 -c–a-w C:\WINDOWS\system32\dllcache\shell32.dll
+ 2004-08-13 23:01:19 502,784 -c–a-w C:\WINDOWS\system32\dllcache\winlogon.exe
- 2008-06-23 18:13:23 163,528 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-07-08 06:09:33 160,344 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-07-12 18:31:29 1,701,924 —-a-w C:\WINDOWS\system32\Restore\rstrlog.dat
+ 2007-01-19 17:53:04 51,056 —-a-w C:\WINDOWS\system32\sirenacm.dll
+ 2004-07-10 23:55:38 252,416 —-a-w C:\WINDOWS\system32\wsiShared.dll
+ 2008-07-14 22:55:23 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_d0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-29 04:35 68856]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-17 14:08 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-17 14:08 77824]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-11-17 22:47 118784]
"VAIO Recovery"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-19 23:08 28672]
"SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [2005-12-14 01:43 217088]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-06 20:33 7557120]
"PartSeal"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-19 23:08 28672]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2002-08-19 22:22 50880]
"ccRegVfy"="C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-08-19 22:23 34504]
"Advanced Tools Check"="C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE" [2002-08-26 22:35 79480]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2002-08-07 09:04 54936]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-20 20:42 73728 C:\WINDOWS\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-03-25 04:28 144784 C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Switcher.exe]
–a—— 2005-11-24 13:47 167936 C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Update 2]
–a—— 2005-10-12 00:36 151552 C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIOCameraUtility]
–a—— 2005-12-01 04:20 69632 C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIOSurvey]
–a—— 2005-06-13 17:42 258048 c:\Program Files\Sony\VAIO Survey\SurveySA.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"aspnet_state"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=

R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 20:26]
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2005-12-27 18:22]
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys [2006-02-21 21:32]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Program Files\Sony\Image Converter 2\IcVzMon.exe [2005-07-14 21:10]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 20:23]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3b540bcc-4876-11dd-9ad8-0013026a44f1}]
\Shell\AutoRun\command - F:\lsfjg.com
\Shell\explore\Command - F:\lsfjg.com
\Shell\open\Command - F:\lsfjg.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc3d06ae-4e27-11dd-9af3-0013026a44f1}]
\Shell\AutoRun\command - F:\lsfjg.com
\Shell\explore\Command - F:\lsfjg.com
\Shell\open\Command - F:\lsfjg.com

.
Contents of the 'Scheduled Tasks' folder
"2008-07-14 23:00:16 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-kamsoft - C:\WINDOWS\system32\ckvo.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-14 18:05:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-07-14 18:06:09
ComboFix-quarantined-files.txt 2008-07-14 23:05:59
ComboFix2.txt 2008-07-10 02:45:28
ComboFix3.txt 2008-07-06 00:29:35

Pre-Run: 76,680,241,152 bytes free
Post-Run: 77,293,154,304 bytes free

220
Somehow I cannot upload attachment onto this site…tried at least 3 times. Anyway, I had to make a new account on photobucket to upload the picture. Here's the link http://i348.photobucket.com/albums/q333/ci…7/ckvoerror.jpg

Do the logs look alright?

Here' HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:07:10 PM, on 7/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AOL Search Enhancement - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PartSeal] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD42/JSCDL/jre/6u…ows-i586-jc.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

–
End of file - 10141 bytes

I didn't know how to update the sUBs so I just redownload the CF program.

Sorry, should have made that clear. :blush:

Somehow I cannot upload attachment onto this site…tried at least 3 times. Anyway, I had to make a new account on photobucket to upload the picture.

Good call - did the trick.

Copy and paste the following into Notepad (Start > All Programs > Accessories > Notepad):

KillAll::

File::
C:\fi.cmd
C:\WINDOWS\system32\ckvo1.dll
C:\lsfjg.com
C:\8uot.exe

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3b540bcc-4876-11dd-9ad8-0013026a44f1}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc3d06ae-4e27-11dd-9af3-0013026a44f1}]


Save it to your Desktop with the following filename: CFScript
Drag and drop CFScript.txt onto your copy of Combofix and let it do it's thing.
Let me have the log produced, as before, as well as a fresh HJT log and a description of how the PC is behaving.
Haha It's alright. Hope the error print screen helped.

PC is running fine. Didn't have any error msg popped up when I turned on the PC.

So…after this turn, everything should be cleared now right? Do you still have any ideas about the flashdrives? What about the external hhd?

Here's Combofix:

ComboFix 08-07-14.2 - Cindy Lin 2008-07-15 17:38:13.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.664 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Cindy Lin\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\8uot.exe
C:\fi.cmd
C:\lsfjg.com
C:\WINDOWS\system32\ckvo1.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\8uot.exe
C:\fi.cmd
C:\lsfjg.com
C:\WINDOWS\system32\ckvo1.dll

.
((((((((((((((((((((((((( Files Created from 2008-06-15 to 2008-07-15 )))))))))))))))))))))))))))))))
.

2008-07-09 18:43 . 2002-06-21 15:09 160,217 –a—— C:\WINDOWS\system32\PowerToysLicense.rtf
2008-07-09 18:25 . 2008-07-09 18:25 d——– C:\Documents and Settings\Cindy Lin\Contacts
2008-07-09 18:22 . 2008-07-09 18:22 d——– C:\Program Files\MSN Messenger
2008-07-08 23:17 . 2008-07-08 23:18 d——– C:\Documents and Settings\Cindy Lin\Application Data\wsInspector
2008-07-08 23:10 . 2008-07-08 23:14 d——– C:\Program Files\Startup Inspector for Windows
2008-07-06 13:49 . 2008-07-13 01:07 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-07-06 13:49 . 2008-07-06 13:49 d——– C:\Documents and Settings\Cindy Lin\Application Data\Malwarebytes
2008-07-06 13:49 . 2008-07-06 13:49 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-06 13:49 . 2008-07-07 17:35 34,296 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-06 13:49 . 2008-07-07 17:35 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-07-04 03:38 . 2008-07-04 03:38 d——– C:\Documents and Settings\Cindy Lin\Application Data\Uniblue
2008-07-04 00:32 . 2008-07-04 00:32 d——– C:\WINDOWS\F4C9398FB6C64A4B8B6D795CD86F915D.TMP
2008-07-03 22:59 . 2002-08-15 19:59 123,619 –a—— C:\WINDOWS\system32\SYMEVNT.386
2008-07-03 22:59 . 2002-08-15 19:59 83,672 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2008-07-03 22:59 . 2002-08-15 19:59 73,224 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-07-03 22:59 . 2002-08-14 06:03 34,578 –a—— C:\WINDOWS\system32\drivers\NPDRIVER.SYS
2008-07-03 22:59 . 2008-07-03 22:59 272 –a—— C:\WINDOWS\_delis32.ini
2008-07-03 22:59 . 2008-07-03 22:59 32 –ahs—- C:\WINDOWS\system32\{444EB6FB-0905-4C7A-B99F-49345407597B}.dat
2008-07-03 22:59 . 2008-07-03 22:59 32 –ahs—- C:\WINDOWS\{FC48DBCB-77BE-4A5B-9118-DBDA3A0010E8}.dat
2008-07-03 22:59 . 2008-07-03 22:59 14 –a—— C:\WINDOWS\system32\SR2.dat
2008-07-03 22:58 . 2008-07-03 23:09 d——– C:\Program Files\Norton AntiVirus
2008-07-03 22:58 . 2008-07-03 22:58 d——– C:\Documents and Settings\Cindy Lin\Application Data\Symantec
2008-06-22 15:39 . 2004-08-10 07:00 811,064 –a—— C:\WINDOWS\system32\imjp81k.dll
2008-06-15 19:16 . 2008-06-16 20:14 d——– C:\Documents and Settings\Cindy Lin\Application Data\DivX
2008-06-15 19:12 . 2008-06-15 19:12 d——– C:\Program Files\DivX
2008-06-15 19:12 . 2008-05-22 17:22 129,784 ——— C:\WINDOWS\system32\pxafs.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-15 22:43 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-07-08 06:02 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-07-05 09:40 ——— d—–w C:\Program Files\Trend Micro
2008-07-04 03:59 ——— d—–w C:\Program Files\Symantec
2008-07-04 03:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-04 20:37 ——— d—–w C:\Program Files\Quicken
2008-06-04 20:19 ——— d—–w C:\Program Files\Google
2008-06-04 05:14 ——— d—–w C:\Program Files\Java
2008-06-04 05:09 ——— d—–w C:\Program Files\Windows Media Connect 2
2008-06-04 05:06 ——— d—–w C:\Program Files\Windows Media Connect
2008-06-04 05:04 ——— d—–w C:\Program Files\Common Files\Adobe
2008-06-04 04:36 ——— d—–w C:\Documents and Settings\Cindy Lin\Application Data\acccore
2008-06-04 04:28 ——— d—–w C:\Program Files\AIM6
2008-06-04 04:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-06-04 04:10 ——— d—–w C:\Program Files\Common Files\AOL
2008-06-03 06:51 0 —ha-r C:\WINDOWS\system32\drivers\Sony_VGN-FE670G.mrk
2008-06-03 06:43 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-03 06:43 ——— d—–w C:\Program Files\InterVideo
2008-06-03 06:43 ——— d—–w C:\Program Files\Common Files\InterVideo
2008-06-03 06:42 ——— d—–w C:\Program Files\Sony
2008-06-03 06:42 ——— d—–w C:\Program Files\Microsoft Digital Image 2006
2008-06-03 06:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-06-03 06:40 ——— d—–w C:\Program Files\Netscape
2008-06-03 06:33 ——— d—–w C:\Program Files\Common Files\Sony Shared
2008-06-03 06:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\VAIO Media Platform
2008-06-03 06:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sony Corporation
2008-06-03 06:31 ——— d—–w C:\WINDOWS\system32\config\systemprofile\Application Data\Intuit
2008-06-03 06:31 ——— d—–w C:\Documents and Settings\Cindy Lin\Application Data\Intuit
2008-06-03 06:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Intuit
2008-06-03 06:31 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Intuit
2008-06-03 06:26 ——— d—–w C:\Program Files\Microsoft Works
2008-06-03 06:25 ——— d—–w C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
2008-06-03 06:15 ——— d—–w C:\WINDOWS\system32\config\systemprofile\Application Data\Sony Corporation
2008-06-03 06:15 ——— d—–w C:\Documents and Settings\Cindy Lin\Application Data\Sony Corporation
2008-06-03 06:15 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Sony Corporation
2008-05-30 23:22 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-05-30 23:22 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2008-05-30 23:22 815,104 —-a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-05-30 23:22 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2008-05-30 23:22 683,520 —-a-w C:\WINDOWS\system32\DivX.dll
2008-05-30 23:22 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-05-30 23:22 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2008-05-30 23:22 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-05-30 23:22 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2008-05-30 23:22 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2008-05-30 23:22 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
2008-05-22 22:22 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2008-05-22 22:22 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-05-22 22:22 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:22 120,056 ——w C:\WINDOWS\system32\pxcpyi64.exe
2008-05-22 22:22 118,520 ——w C:\WINDOWS\system32\pxinsi64.exe
2008-05-22 22:20 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2008-05-22 22:20 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2008-05-22 22:19 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2008-05-22 22:19 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2008-05-22 22:19 161,096 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-22 22:18 12,288 —-a-w C:\WINDOWS\system32\DivXWMPExtType.dll
.

((((((((((((((((((((((((((((( snapshot@2008-07-05_19.29.19.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-09 23:23:08 29,926 —-a-r C:\WINDOWS\Installer\{571700F0-DB9D-4B3A-B03D-35A14BB5939F}\MsblIco.Exe
+ 2001-05-22 06:00:00 22,016 –s-a-w C:\WINDOWS\system32\borlndmm.dll
+ 2005-07-26 04:39:43 498,688 -c–a-w C:\WINDOWS\system32\dllcache\clbcatq.dll
+ 2004-08-10 12:00:00 792,064 -c–a-w C:\WINDOWS\system32\dllcache\comres.dll
+ 2004-08-10 12:00:00 55,632 -c–a-w C:\WINDOWS\system32\dllcache\dwil1033.dll
+ 2004-08-10 12:00:00 22,016 -c–a-w C:\WINDOWS\system32\dllcache\lpk.dll
+ 2004-08-10 12:00:00 159,232 -c–a-w C:\WINDOWS\system32\dllcache\msimtf.dll
+ 2004-08-10 12:00:00 431,616 -c–a-w C:\WINDOWS\system32\dllcache\riched20.dll
+ 2004-08-10 12:00:00 152,576 -c–a-w C:\WINDOWS\system32\dllcache\rsaenh.dll
+ 2005-09-23 03:05:29 8,450,560 -c–a-w C:\WINDOWS\system32\dllcache\shell32.dll
+ 2004-08-13 23:01:19 502,784 -c—-w C:\WINDOWS\system32\dllcache\winlogon.exe
+ 2004-08-13 23:01:19 502,784 -c–a-w C:\WINDOWS\system32\dllcache\winlogon.exe.new
- 2008-06-23 18:13:23 163,528 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-07-08 06:09:33 160,344 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-07-12 18:31:29 1,701,924 —-a-w C:\WINDOWS\system32\Restore\rstrlog.dat
+ 2007-01-19 17:53:04 51,056 —-a-w C:\WINDOWS\system32\sirenacm.dll
+ 2004-07-10 23:55:38 252,416 —-a-w C:\WINDOWS\system32\wsiShared.dll
+ 2008-07-15 22:41:46 16,384 —-atw C:\WINDOWS\TEMP\Perflib_Perfdata_1f4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-29 04:35 68856]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-17 14:08 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-17 14:08 77824]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-11-17 22:47 118784]
"VAIO Recovery"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-19 23:08 28672]
"SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [2005-12-14 01:43 217088]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-06 20:33 7557120]
"PartSeal"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-19 23:08 28672]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2002-08-19 22:22 50880]
"ccRegVfy"="C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-08-19 22:23 34504]
"Advanced Tools Check"="C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE" [2002-08-26 22:35 79480]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2002-08-07 09:04 54936]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-20 20:42 73728 C:\WINDOWS\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-03-25 04:28 144784 C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Switcher.exe]
–a—— 2005-11-24 13:47 167936 C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Update 2]
–a—— 2005-10-12 00:36 151552 C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIOCameraUtility]
–a—— 2005-12-01 04:20 69632 C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIOSurvey]
–a—— 2005-06-13 17:42 258048 c:\Program Files\Sony\VAIO Survey\SurveySA.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"aspnet_state"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=

R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 20:26]
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2005-12-27 18:22]
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys [2006-02-21 21:32]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Program Files\Sony\Image Converter 2\IcVzMon.exe [2005-07-14 21:10]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 20:23]

.
Contents of the 'Scheduled Tasks' folder
"2008-07-15 22:41:45 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-15 17:42:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\sessmgr.exe
C:\Program Files\Apoint\ApntEx.exe
C:\Program Files\Messenger\msmsgs.exe
.
**************************************************************************
.
Completion time: 2008-07-15 17:44:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-15 22:44:46
ComboFix2.txt 2008-07-14 23:06:10
ComboFix3.txt 2008-07-10 02:45:28
ComboFix4.txt 2008-07-06 00:29:35

Pre-Run: 76,879,171,584 bytes free
Post-Run: 77,213,749,248 bytes free

238

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI