This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Smacchat, ads, and other popups

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been just dealing with this problem for a while now, but recently its been getting worse. The basic gist is that for some reason while Im surfing with firefox (never bothered with IE except to dl firefox), i'm constantly bombarded by several popups (just today I had 32 show up at once, all with video playing in them, sending my computer to hades) in IE… Yep, IE popups in Firefox, been driving me nuts, so HALP PLZ ;-;
Note: Also tried using the updated version of IE (v 7.0) definitely didn't help

HiJackThis Report:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:54:20 AM, on 7/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Ideazon\ZEngine\Zboard.exe
C:\Program Files\COMODO\SafeSurf\cssurf.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Stardock\CursorFX\CursorFX.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\NETGEAR\WPN311\wlancfg5.exe
C:\Program Files\SpyCatcher\Protector.exe
C:\Program Files\SpyCatcher\Scheduler daemon.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Proxifier\Proxifier.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher\SCActiveBlock.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Zboard] C:\Program Files\Ideazon\ZEngine\Zboard.exe
O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
O4 - HKLM\..\Run: [SpyCatcher Reminder] C:\Program Files\SpyCatcher\SpyCatcher.exe reminder
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CursorFX] "C:\Program Files\Stardock\CursorFX\CursorFX.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: NETGEAR WPN311 Smart Wizard.lnk = C:\Program Files\NETGEAR\WPN311\wlancfg5.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher\Protector.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxernsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxerdrv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxerdrv.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} (Microsoft Genuine Advantage Self Support Tool) - http://go.microsoft.com/fwlink/?LinkId=82580
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - AppInit_DLLs: secuload.dll
O21 - SSODL: pizwvapw - {e0dd5662-a295-4d1d-98ab-fb0fa7d12377} - C:\Documents and Settings\All Users\Application Data\pizwvapw.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 7874 bytes
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
As I am still training, my posts to you will be checked by an Expert member. This will ensure that all advice and instructions I give you are accurate and safe. This may mean that my replies may take a little longer.

jpshortstuff
Hi

We need to make sure all hidden files are showing so please:
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.

We need to upload a file to Jotti

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

C:\Documents and Settings\All Users\Application Data\pizwvapw.dll

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.


Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt in your reply.
Thanks.
Main.txt
Deckard's System Scanner v20071014.68
Run by [removed] on 2008-07-11 17:51:07
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
49: 2008-07-11 22:51:22 UTC - RP49 - Deckard's System Scanner Restore Point
48: 2008-07-11 05:27:50 UTC - RP48 - Software Distribution Service 3.0
47: 2008-07-11 00:25:00 UTC - RP47 - System Checkpoint
46: 2008-07-09 18:20:36 UTC - RP46 - ComboFix created restore point
45: 2008-07-09 08:00:14 UTC - RP45 - Software Distribution Service 3.0


– First Restore Point –
1: 2008-06-21 04:31:33 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



– HijackThis (run as Zach.exe) ————————————————

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:51:45 PM, on 7/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Ideazon\ZEngine\Zboard.exe
C:\Program Files\COMODO\SafeSurf\cssurf.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Stardock\CursorFX\CursorFX.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\NETGEAR\WPN311\wlancfg5.exe
C:\Program Files\SpyCatcher\Protector.exe
C:\Program Files\SpyCatcher\Scheduler daemon.exe
C:\Program Files\Proxifier\Proxifier.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Zach\Desktop\dss.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Zach.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher\SCActiveBlock.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Zboard] C:\Program Files\Ideazon\ZEngine\Zboard.exe
O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
O4 - HKLM\..\Run: [SpyCatcher Reminder] C:\Program Files\SpyCatcher\SpyCatcher.exe reminder
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CursorFX] "C:\Program Files\Stardock\CursorFX\CursorFX.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: NETGEAR WPN311 Smart Wizard.lnk = C:\Program Files\NETGEAR\WPN311\wlancfg5.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher\Protector.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxernsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxerdrv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxerdrv.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} (Microsoft Genuine Advantage Self Support Tool) - http://go.microsoft.com/fwlink/?LinkId=82580
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - AppInit_DLLs: secuload.dll
O21 - SSODL: pizwvapw - {e0dd5662-a295-4d1d-98ab-fb0fa7d12377} - C:\Documents and Settings\All Users\Application Data\pizwvapw.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 7915 bytes

– File Associations ———————————————————–

.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R1 mnmddd - c:\windows\system32\drivers\mnmddd.sys
R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys
You appear to have used ComboFix recently.

1. What led you to run ComboFix, was it your own initiative or instruction from another helper?

2. Please provide me with ComboFix's log, located at C:\ComboFix.txt

Thanks.
Sorry it took so long to get back here… had a fe probelms with connections, all good now. I ran combofix because a friend of mine suggested it to clear up some rundll problems I'd been getting, cleared that up, but didn't do anything for the popups (not that it was supposed to)

Combofix log ComboFix 08-07-08.9 - Zach 2008-07-09 13:20:47.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2031 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Programs\Malware Protector 2008
C:\Documents and Settings\All Users\Start Menu\Programs\Malware Protector 2008\How to Register Malware Protector 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Malware Protector 2008\License Agreement.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Malware Protector 2008\Uninstall.lnk
C:\Documents and Settings\LocalService\Application Data\shcr64j0ej3r
C:\Documents and Settings\Zach\Application Data\shcr64j0ej3r
C:\Program Files\shcr64j0ej3r
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\cookies.ini
C:\WINDOWS\mainms.vpi
C:\WINDOWS\megavid.cdt
C:\WINDOWS\muotr.so
C:\WINDOWS\system32\blphct64j0ej3r.scr
C:\WINDOWS\system32\fglcfwgf.ini
C:\WINDOWS\system32\hljwugsf.bin
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\oVvDefhk.ini
C:\WINDOWS\system32\oVvDefhk.ini2
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\phct64j0ej3r.bmp
C:\WINDOWS\system32\winpfz33.sys
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_CMDSERVICE
——-\Legacy_MSSECURITY1.209.4
——-\Legacy_NETWORK_MONITOR
——-\Service_MsSecurity1.209.4


((((((((((((((((((((((((( Files Created from 2008-06-09 to 2008-07-09 )))))))))))))))))))))))))))))))
.

2008-07-09 13:26 . 2008-07-09 13:26 d——– C:\Temp\tn3
2008-07-09 13:12 . 2008-07-09 13:12 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-07-09 13:09 . 2008-07-09 13:10 d——– C:\Program Files\CCleaner
2008-07-09 13:04 . 2008-07-09 13:04 d——– C:\Program Files\Trend Micro
2008-07-06 19:49 . 2008-07-09 04:14 d——– C:\Program Files\Steam
2008-07-06 12:43 . 2008-07-06 12:43 d——– C:\Documents and Settings\Zach\Application Data\FastStone
2008-07-06 12:42 . 2008-07-06 12:42 d——– C:\Program Files\GlobalSCAPE
2008-07-06 12:42 . 2008-07-06 12:42 d——– C:\Documents and Settings\Zach\Application Data\GlobalSCAPE
2008-07-06 12:41 . 2008-07-06 12:41 d——– C:\Program Files\Icon Constructor 3
2008-07-06 12:40 . 2008-07-06 12:40 d——– C:\Program Files\Your Uninstaller 2008
2008-07-06 12:40 . 2008-07-06 12:40 d——– C:\Documents and Settings\Zach\Application Data\URSoft
2008-07-06 12:39 . 2008-07-06 12:39 d——– C:\Program Files\XP Codec Pack
2008-07-06 12:39 . 2008-07-06 12:39 d——– C:\Program Files\LopeSoft
2008-07-06 12:39 . 2008-07-06 12:39 d——– C:\Program Files\File Shredder
2008-07-06 12:38 . 2008-07-06 12:38 d——– C:\Program Files\PowerISO
2008-07-03 21:40 . 2008-07-03 21:40 d——– C:\Extras
2008-07-03 21:40 . 2008-07-03 21:40 d——– C:\Autorun
2008-07-01 23:14 . 2008-07-01 23:14 d——– C:\Documents and Settings\Zach\Application Data\Ventrilo
2008-07-01 23:13 . 2008-07-01 23:13 d——– C:\Program Files\Ventrilo
2008-07-01 23:13 . 2008-07-01 23:13 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-06-30 12:36 . 2007-01-03 14:16 40,960 -ra—— C:\WINDOWS\system32\psfind.dll
2008-06-28 23:46 . 2008-06-28 23:46 d——– C:\Documents and Settings\Zach\Application Data\vlc
2008-06-28 23:45 . 2008-06-28 23:45 d——– C:\Program Files\VideoLAN
2008-06-27 21:42 . 2008-06-27 21:42 d——– C:\Documents and Settings\All Users\Application Data\Last.fm
2008-06-27 21:40 . 2008-06-27 21:40 d——– C:\Program Files\Last.fm
2008-06-26 20:49 . 2008-06-26 20:49 d——– C:\Program Files\NETGEAR
2008-06-26 20:49 . 2008-06-26 20:49 d——– C:\OEMSettings
2008-06-26 19:21 . 2008-06-26 19:31 d——– C:\Netgear
2008-06-26 10:50 . 2008-06-26 20:49 17,801 –a—— C:\WINDOWS\system32\drivers\AegisP.sys
2008-06-26 10:49 . 2008-06-26 10:49 d——– C:\WINDOWS\Downloaded Installations
2008-06-24 00:00 . 2008-06-24 00:00 d——– C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-06-23 23:53 . 2008-07-09 13:10 d——– C:\Program Files\Yahoo!
2008-06-23 18:01 . 2008-06-23 18:02 d——– C:\Program Files\DAEMON Tools Lite
2008-06-23 17:58 . 2008-06-23 17:58 d——– C:\Documents and Settings\Zach\Application Data\DAEMON Tools
2008-06-23 17:58 . 2008-06-23 17:58 717,296 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2008-06-23 11:56 . 2008-06-23 11:56 d–h—– C:\Documents and Settings\All Users\Application Data\{A850D4D9-871B-4234-908D-21C457767270}
2008-06-23 11:34 . 2008-06-23 11:34 230 –a—— C:\WINDOWS\system32\spupdsvc.inf
2008-06-23 11:22 . 2007-07-11 15:06 42,672 –a—— C:\WINDOWS\system32\wbsys.dll
2008-06-23 11:21 . 2008-06-23 11:56 d——– C:\Program Files\Stardock
2008-06-23 10:47 . 2008-06-23 10:47 d——– C:\Documents and Settings\Zach\dwhelper
2008-06-23 10:44 . 2008-06-23 10:44 d——– C:\Documents and Settings\Zach\Application Data\Tenebril
2008-06-23 10:40 . 2008-06-23 10:41 d——– C:\Documents and Settings\All Users\Application Data\Tenebril
2008-06-23 10:08 . 2008-06-23 10:08 d——– C:\Program Files\Startup Inspector for Windows
2008-06-23 10:07 . 2008-06-23 10:07 d——– C:\WINDOWS\system32\tenarchlib
2008-06-23 10:07 . 2008-06-23 10:08 d——– C:\Program Files\SpyCatcher
2008-06-23 10:07 . 2007-05-07 11:39 1,103,944 –a-s—- C:\WINDOWS\system32\Protector.dll
2008-06-23 10:07 . 2005-10-12 23:10 180,224 –a-s—- C:\WINDOWS\system32\archlib.dll
2008-06-23 10:07 . 2007-05-07 11:39 169,544 –a-s—- C:\WINDOWS\system32\SecuLoad.dll
2008-06-23 10:07 . 2007-05-07 11:42 40,960 –a-s—- C:\WINDOWS\system32\ProcessKiller.dll
2008-06-23 10:06 . 2008-06-23 10:06 d——– C:\Program Files\COMODO
2008-06-23 10:06 . 2008-06-23 10:06 d——– C:\Program Files\AskSBar
2008-06-23 10:06 . 2008-06-23 10:06 d——– C:\Documents and Settings\Zach\Application Data\Comodo
2008-06-23 10:06 . 2008-06-23 10:41 d——– C:\Documents and Settings\All Users\Application Data\comodo
2008-06-23 10:06 . 2008-06-23 10:06 249,592 –a—— C:\WINDOWS\system32\cssdll32.dll
2008-06-23 10:06 . 2008-06-23 10:06 143,104 –a—— C:\WINDOWS\system32\guard32.dll
2008-06-23 10:06 . 2008-06-23 10:06 87,056 –a—— C:\WINDOWS\system32\drivers\cmdguard.sys
2008-06-23 10:06 . 2008-06-23 10:06 24,208 –a—— C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-06-22 22:42 . 2008-06-22 22:42 d——– C:\Documents and Settings\Zach\Logs
2008-06-22 17:29 . 2008-06-22 17:29 d——– C:\Documents and Settings\Zach\Application Data\Ideazon
2008-06-22 17:28 . 2008-06-22 17:28 d——– C:\Program Files\Ideazon
2008-06-22 17:09 . 2008-06-22 17:09 d——– C:\WINDOWS\RegCure
2008-06-22 17:09 . 2008-06-22 17:11 d——– C:\Program Files\RegCure
2008-06-22 17:09 . 2007-11-14 15:18 553 –a—— C:\WINDOWS\USetup.iss
2008-06-22 17:08 . 2008-06-22 17:08 315,392 –a—— C:\WINDOWS\HideWin.exe
2008-06-22 17:00 . 2008-06-22 17:00 d——– C:\Documents and Settings\Zach\Application Data\RegSweep
2008-06-22 16:55 . 2008-03-14 10:47 442,368 –a—— C:\WINDOWS\system32\nvunrm.exe
2008-06-22 16:55 . 2007-12-07 16:12 5,836 –a—— C:\WINDOWS\system32\nvnrm.nvu
2008-06-22 16:55 . 2008-03-12 12:14 3,948 –a—— C:\WINDOWS\system32\drivers\nvphy.bin
2008-06-22 16:50 . 2008-06-22 16:50 d——– C:\WINDOWS\nvidia icons
2008-06-22 16:50 . 2008-05-02 22:46 182,347 –a—— C:\WINDOWS\system32\nvapps.nvb
2008-06-22 16:34 . 2008-06-22 16:34 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2008-06-21 21:10 . 2008-06-21 21:10 107,888 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2008-06-21 16:42 . 2006-08-01 15:02 49,152 –a—— C:\WINDOWS\system32\ChCfg.exe
2008-06-21 16:41 . 2008-06-22 17:08 d——– C:\Program Files\Realtek
2008-06-21 16:41 . 2008-03-05 18:07 520,192 –a—— C:\WINDOWS\RtlExUpd.dll
2008-06-21 16:25 . 2008-06-21 16:25 d——– C:\Program Files\Warcraft III
2008-06-21 16:15 . 2008-06-30 12:39 d——– C:\Program Files\THQ
2008-06-21 16:15 . 2008-06-21 16:15 d——– C:\Program Files\Tales of Pirates Online
2008-06-21 13:16 . 2008-06-21 13:16 d——– C:\WINDOWS\system32\scripting
2008-06-21 13:16 . 2008-06-21 13:16 d——– C:\WINDOWS\system32\en
2008-06-21 13:16 . 2008-06-21 13:16 d——– C:\WINDOWS\system32\bits
2008-06-21 13:16 . 2008-06-21 13:16 d——– C:\WINDOWS\l2schemas
2008-06-21 13:14 . 2008-06-21 13:16 d——– C:\WINDOWS\ServicePackFiles
2008-06-21 13:11 . 2008-06-22 16:54 d——– C:\WINDOWS\nview
2008-06-21 13:11 . 2008-05-02 22:46 442,368 –a—— C:\WINDOWS\system32\nvudisp.exe
2008-06-21 13:11 . 2008-07-09 04:14 178,368 –a—— C:\WINDOWS\system32\nvapps.xml
2008-06-21 13:11 . 2008-05-02 22:46 18,070 –a—— C:\WINDOWS\system32\nvdisp.nvu
2008-06-21 13:09 . 2008-06-22 16:51 d——– C:\NVIDIA
2008-06-21 11:14 . 2008-06-21 11:14 d——– C:\Logs
2008-06-21 09:39 . 2008-06-22 21:42 d——– C:\Program Files\World of Warcraft
2008-06-21 09:39 . 2008-06-21 09:59 d——– C:\Program Files\Common Files\Blizzard Entertainment
2008-06-21 09:10 . 2008-06-13 06:05 272,128 —–c— C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-21 09:09 . 2008-05-08 09:02 203,136 —–c— C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-21 09:07 . 2008-06-21 09:07 d——– C:\Documents and Settings\Zach\Application Data\AdobeUM
2008-06-21 04:30 . 2001-08-17 08:48 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2008-06-21 04:30 . 2008-06-26 10:58 4,444 –a—— C:\WINDOWS\system32\pid.PNF
2008-06-21 03:32 . 2008-04-13 19:11 21,504 –a—— C:\WINDOWS\system32\hidserv.dll
2008-06-21 03:32 . 2001-08-17 08:59 3,072 –a—— C:\WINDOWS\system32\drivers\audstub.sys
2008-06-21 03:31 . 2008-04-13 13:40 57,600 –a—— C:\WINDOWS\system32\drivers\redbook.sys
2008-06-21 03:31 . 2001-08-17 08:46 6,400 –a—— C:\WINDOWS\system32\drivers\enum1394.sys
2008-06-21 03:30 . 2008-04-13 19:12 74,240 –a—— C:\WINDOWS\system32\usbui.dll
2008-06-21 03:30 . 2008-07-09 03:00 1,355 –a—— C:\WINDOWS\imsins.BAK
2008-06-21 03:29 . 2008-06-23 11:22 dr——- C:\Documents and Settings\All Users\Documents
2008-06-21 03:28 . 2007-07-27 07:00 14,573 -ra—— C:\WINDOWS\SET29.tmp
2008-06-21 01:06 . 2008-06-21 01:06 d—s—- C:\Documents and Settings\Zach\UserData
2008-06-21 01:03 . 2008-06-21 01:03 d——– C:\Program Files\Common Files\Adobe
2008-06-21 00:33 . 2008-06-23 09:57 609 –a—— C:\WINDOWS\wininit.ini
2008-06-21 00:31 . 2008-06-21 00:32 d——– C:\Documents and Settings\LocalService\Application Data\AdobeUM
2008-06-21 00:17 . 2008-06-30 12:18 d——– C:\Program Files\Spybot - Search & Destroy
2008-06-21 00:17 . 2008-06-27 22:19 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-20 23:42 . 2008-06-21 13:01 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-20 23:41 . 2008-06-20 23:41 d——– C:\Program Files\Common Files\Download Manager
2008-06-20 23:41 . 2005-09-23 07:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2008-06-20 21:50 . 2008-06-20 21:51 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-20 21:44 . 2008-06-20 21:44 d——– C:\Program Files\Avira
2008-06-20 21:44 . 2008-06-20 21:44 d——– C:\Documents and Settings\All Users\Application Data\Avira
2008-06-20 21:40 . 2008-06-20 21:46 d——– C:\WINDOWS\system32\netrax06
2008-06-20 21:40 . 2008-06-20 21:49 d——– C:\WINDOWS\system32\eb10
2008-06-20 21:40 . 2008-06-20 21:48 d——– C:\WINDOWS\system32\bgi
2008-06-20 21:40 . 2008-06-20 21:48 d——– C:\WINDOWS\system32\axc
2008-06-20 21:40 . 2008-06-20 21:48 d——– C:\WINDOWS\system32\1049a
2008-06-20 21:40 . 2008-06-21 00:08 d–hs—- C:\WINDOWS\QWtv
2008-06-20 21:40 . 2008-06-20 21:40 d——– C:\Temp\itmp4
2008-06-20 21:40 . 2008-07-09 13:26 d——– C:\Temp
2008-06-20 21:40 . 2008-06-20 21:40 d——– C:\Documents and Settings\Zach\Application Data\COWON

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-21 01:30 ——— d—–w C:\Program Files\microsoft frontpage
2008-06-20 11:51 361,600 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 22:11 4,754,944 —-a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-06-13 19:50 16,871,936 —-a-w C:\WINDOWS\RTHDCPL.exe
2008-06-13 11:05 272,128 ——w C:\WINDOWS\system32\drivers\bthport.sys
2008-04-14 00:12 69,120 —-a-w C:\WINDOWS\notepad.exe
2008-04-14 00:12 50,688 —-a-w C:\WINDOWS\twain_32.dll
2008-04-14 00:12 32,866 ——w C:\WINDOWS\slrundll.exe
2008-04-14 00:12 283,648 —-a-w C:\WINDOWS\winhlp32.exe
2008-04-14 00:12 146,432 —-a-w C:\WINDOWS\regedit.exe
2008-04-14 00:12 10,752 —-a-w C:\WINDOWS\hh.exe
2008-04-14 00:12 1,033,728 —-a-w C:\WINDOWS\explorer.exe
2008-04-14 00:11 451,072 —-a-w C:\WINDOWS\AppPatch\aclayers.dll
2008-04-14 00:11 39,424 ——w C:\WINDOWS\AppPatch\acadproc.dll
2008-04-14 00:11 245,248 —-a-w C:\WINDOWS\AppPatch\acspecfc.dll
2008-04-14 00:11 141,312 —-a-w C:\WINDOWS\AppPatch\aclua.dll
2008-04-14 00:11 116,224 —-a-w C:\WINDOWS\AppPatch\acxtrnal.dll
2008-04-14 00:11 1,852,928 —-a-w C:\WINDOWS\AppPatch\acgenral.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-06-23 10:06 66912 –a—— C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360]
"CursorFX"="C:\Program Files\Stardock\CursorFX\CursorFX.exe" [2008-02-19 17:59 418632]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 04:39 486856]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 19:12 1695232]
"Steam"="C:\Program Files\Steam\Steam.exe" [2008-07-06 19:51 1271032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2006-09-13 10:12 81920]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"Zboard"="C:\Program Files\Ideazon\ZEngine\Zboard.exe" [2007-07-25 13:25 57344]
"COMODO SafeSurf"="C:\Program Files\COMODO\SafeSurf\cssurf.exe" [2008-06-23 10:06 278264]
"SpyCatcher Reminder"="C:\Program Files\SpyCatcher\SpyCatcher.exe" [2007-10-16 12:05 103864]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-06-23 10:06 1655552]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2008-03-14 18:50 233472]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-06-13 14:50 16871936 C:\WINDOWS\RTHDCPL.exe]

C:\Documents and Settings\Zach\Start Menu\Programs\Startup\
Scheduler.lnk - C:\Program Files\SpyCatcher\Scheduler daemon.exe [2008-06-23 10:07:59 86133]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
NETGEAR WPN311 Smart Wizard.lnk - C:\Program Files\NETGEAR\WPN311\wlancfg5.exe [2006-12-04 11:57:38 1503232]
SpyCatcher Protector.lnk - C:\Program Files\SpyCatcher\Protector.exe [2008-06-23 10:07:59 91576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"pizwvapw"= {e0dd5662-a295-4d1d-98ab-fb0fa7d12377} - C:\Documents and Settings\All Users\Application Data\pizwvapw.dll [2008-06-20 21:40 122880]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2008-06-23 11:26 229376 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\THQ\\Dawn Of War\\W40k.exe"=
"C:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"C:\\Program Files\\THQ\\DarkCrusade\\DarkCrusade.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Steam\\steamapps\\akoftl\\team fortress 2\\hl2.exe"=

R0 nvgts;nvgts;C:\WINDOWS\system32\DRIVERS\nvgts.sys [2008-01-25 20:01]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-06-23 10:06]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-06-23 10:06]
R1 mnmddd;mnmddd;C:\WINDOWS\system32\drivers\mnmddd.sys [2008-06-20 21:40]
R3 Alpham1;Ideazon Merc USB Human Interface Device;C:\WINDOWS\system32\DRIVERS\Alpham1.sys [2007-07-23 10:56]
R3 Alpham2;Ideazon Merc MM USB Human Interface Device;C:\WINDOWS\system32\DRIVERS\Alpham2.sys [2007-03-20 12:49]

.
Contents of the 'Scheduled Tasks' folder
"2008-07-09 18:26:07 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-07-03 09:05:38 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
- - - - ORPHANS REMOVED - - - -

BHO-{3c6281ac-5600-2392-4452-a70fd2890640} - (no file)
BHO-{A8B11445-753D-48EE-9D4A-7A4E399C8510} - (no file)
HKLM-Run-{544cebcc-d6be-cdb5-3524-d506f614b906} - C:\WINDOWS\system32\{594ed1d5-8771-1d6a-709a-97cbbb7cb667}.dll
HKLM-Run-342946f0 - C:\WINDOWS\system32\fgwfclgf.dll
HKLM-Run-CmPCIaudio - CMICNFG3.cpl
Notify-wvUlJAQj - wvUlJAQj.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-09 13:26:15
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-07-09 13:30:08 - machine was rebooted [Zach]
ComboFix-quarantined-files.txt 2008-07-09 18:30:03

Pre-Run: 430,264,127,488 bytes free
Post-Run: 430,213,292,032 bytes free

293 — E O F — 2008-07-09 08:00:36
Hi

We need to disable your security programs.

Please navigate to the system tray on the bottom right hand corner and look for an open white umbrella on red background (looks to this: [external image: Posted Image] )
  • right click it-> untick the option AntiVir Guard enable.
  • You should now see a closed, white umbrella on a red background (looks to this: [external image: Posted Image] )
Comodo Firewall
  • Right-click the system tray icon.
  • Select Exit.
  • On the Pop up window, Click the Yes button.
You succesfully disabled Comodo Firewall.

Please disable SpyCatcher as well.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:
File::
C:\Documents and Settings\All Users\Application Data\pizwvapw.dll
C:\WINDOWS\system32\drivers\core.cache.dsk

Folder::
C:\WINDOWS\system32\netrax06
C:\WINDOWS\system32\eb10
C:\WINDOWS\system32\bgi
C:\WINDOWS\system32\axc
C:\WINDOWS\system32\1049a
C:\WINDOWS\QWtv
C:\Temp

FileLook:
C:\WINDOWS\system32\psfind.dll

DirLook::
C:\Documents and Settings\Zach\Application Data\COWON

Driver::
mnmddd

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\WINDOWS\system32\blank.htm"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\WINDOWS\system32\blank.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"pizwvapw"=-
[-HKEY_CLASSES_ROOT\CLSID\{e0dd5662-a295-4d1d-98ab-fb0fa7d12377}]
3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Please do an online scan with Kaspersky WebScanner

Follow this link in Internet Explorer (Note: You must use Internet explorer to use Kaspersky): Kaspersky WebScanner

You will be prompted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    o Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)

    o Scan Options:
    Scan Archives Scan Mail Bases

  • Click OK
  • Now under select a target to scan:
    Select My Computer
  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    o Now click on the Save as Text button:
  • Save the file to your desktop.
Please post the results of the Kaspersky scan in your next reply.

Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI