This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Antivirus xp 2008

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I recently got infected by the subject malware. I have most of it removed, but my computer still is behaving strangely at times. Also, Symantec Antivirus is still getting hits for Trojan.Vundu. My Hijackthis log is copied below.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:19:03 PM, on 7/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Creative Labs Shared\Service\APLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avi Player\AviPlayer.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclIVTBTSrv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.defaulthomepage.info
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.defaulthomepage.info
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {500DBD6E-6D95-4106-B9A2-DDDCCB2B30D1} - C:\WINDOWS\system32\ljJCstsS.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {83845ECF-0E56-4BD3-873A-5E1EB5972424} - C:\WINDOWS\system32\awtULbBS.dll (file missing)
O2 - BHO: {10290128-ae8e-f869-c274-f14816746888} - {88864761-841f-472c-968f-e8ea82109201} - C:\WINDOWS\system32\miumfq.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {C1440B28-F402-40A5-8646-1CC741350E78} - C:\WINDOWS\system32\awtrRHXr.dll
O2 - BHO: (no name) - {F50DDDD0-CA9F-4DB3-A5BD-17FDFADA143C} - C:\WINDOWS\system32\hgGvutQJ.dll (file missing)

O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [lphc7l0j0en93] C:\WINDOWS\system32\lphc7l0j0en93.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BCWipeTM Startup] "C:\Program Files\Jetico\BCWipe\BCWipeTM.exe" startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Avi Player] "C:\Program Files\Avi Player\AviPlayer.exe" hmw
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1124159501783
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O20 - Winlogon Notify: ljJCstsS - C:\WINDOWS\SYSTEM32\ljJCstsS.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Audio Pack Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\APLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 10273 bytes

Any help would be appreciated.

Brian :)
Hello

If you already have Combofix, please delete this copy and download it again as it's being updated regularly.

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix


Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once Recovery Console is installed, you should see a blue screen prompt like the one below:

[external image: Posted Image]

Click Yes to allow Combofix to continue scanning for malware.

When done, a log will be produced. Please post that log and a new HijackThis log in your next reply.


1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



In your next reply post:
ComboFix.txt
New HijackThis log taken after the above scan has run
Below are the Combofix and new Hijackthis logs. Thanks

ComboFix 08-07-12.4 - bmoliver 2008-07-13 7:53:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.554 [GMT -7:00]
Running from: D:\Downloads\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\bmoliver\Application Data\macromedia\Flash Player\#SharedObjects\SQ5MQXND\www.broadcaster.com
C:\Documents and Settings\bmoliver\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\bmoliver\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\bmoliver\Application Data\rhc3l0j0en93
C:\WINDOWS\BM87b86071.txt
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\alumofhs.ini
C:\WINDOWS\system32\awtrRHXr.dll
C:\WINDOWS\system32\brgaifhf.dll
C:\WINDOWS\system32\cbXnklii.dll
C:\WINDOWS\system32\ddcBUonK.dll
C:\WINDOWS\system32\fxwwsfys.ini
C:\WINDOWS\system32\ibpwxies.dll
C:\WINDOWS\system32\iifgHArp.dll
C:\WINDOWS\system32\iilknXbc.ini
C:\WINDOWS\system32\iilknXbc.ini2
C:\WINDOWS\system32\jodoktgq.ini
C:\WINDOWS\system32\JQtuvGgh.ini
C:\WINDOWS\system32\JQtuvGgh.ini2
C:\WINDOWS\system32\ljJCstsS.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\miumfq.dll
C:\WINDOWS\system32\msshniio.ini
C:\WINDOWS\system32\onfqojrv.ini
C:\WINDOWS\system32\rqRIaWMc.dll
C:\WINDOWS\system32\rrBeLUvw.ini
C:\WINDOWS\system32\rrBeLUvw.ini2
C:\WINDOWS\system32\rXHRrtwa.ini
C:\WINDOWS\system32\rXHRrtwa.ini2
C:\WINDOWS\system32\SBbLUtwa.ini
C:\WINDOWS\system32\SBbLUtwa.ini2
C:\WINDOWS\system32\sdghaqfv.ini
C:\WINDOWS\system32\swbeykbv.ini
C:\WINDOWS\system32\UEOVCcdd.ini2
C:\WINDOWS\system32\urqNhHww.dll
C:\WINDOWS\system32\vbkyebws.dll
C:\WINDOWS\system32\wvULeBrr.dll

.
((((((((((((((((((((((((( Files Created from 2008-06-13 to 2008-07-13 )))))))))))))))))))))))))))))))
.

2008-07-13 07:36 . 2008-07-13 07:36 d——– C:\VundoFix Backups
2008-07-12 16:02 . 2008-07-12 16:02 d–hs—- C:\Documents and Settings\bmoliver\Phone Browser
2008-07-12 12:45 . 2004-08-03 23:08 25,600 –a—— C:\WINDOWS\system32\drivers\usbser.sys
2008-07-12 12:45 . 2004-08-03 23:08 25,600 –a–c— C:\WINDOWS\system32\dllcache\usbser.sys
2008-07-12 12:45 . 2008-07-12 12:45 0 –ah—– C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-07-12 12:45 . 2008-07-12 12:45 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-07-03 18:43 . 2008-07-03 09:45 1,330 –a—— C:\remove-policies-display.reg
2008-07-03 18:43 . 2008-07-03 09:48 1,330 –a—— C:\desktoptab.reg
2008-07-01 06:44 . 2008-07-01 06:44 d——– C:\Deckard
2008-07-01 06:33 . 2008-07-01 06:05 686,630 –a—— C:\dss.exe
2008-06-30 16:32 . 2008-06-30 16:32 d——– C:\Program Files\Trend Micro
2008-06-29 17:07 . 2008-07-01 17:14 211 –a—— C:\WINDOWS\wininit.ini
2008-06-29 16:18 . 2008-06-29 16:03 691,545 –a—— C:\WINDOWS\unins000.exe
2008-06-29 16:18 . 2008-06-29 16:18 2,543 –a—— C:\WINDOWS\unins000.dat
2008-06-29 09:39 . 2008-06-29 09:39 d——– C:\Documents and Settings\Administrator.BMO-1
2008-06-29 09:31 . 2008-06-26 18:27 1,396,264 –a—— C:\WindowsXP-KB948277-x86-ENU.exe
2008-06-29 09:31 . 2008-04-24 07:13 997,888 —–c— C:\WINDOWS\system32\dllcache\msgina.dll
2008-06-29 09:31 . 2008-04-24 06:17 507,392 —–c— C:\WINDOWS\system32\dllcache\winlogon.exe
2008-06-29 07:59 . 2008-06-29 07:59 d——– C:\WINDOWS\system32\Futuremark
2008-06-29 07:59 . 2008-06-29 07:59 d——– C:\Program Files\Filesweb
2008-06-29 07:59 . 2008-06-29 07:59 d——– C:\Program Files\EXIFViewer
2008-06-29 07:59 . 2008-06-29 07:59 d——– C:\Program Files\Better File Rename
2008-06-29 07:21 . 2008-07-12 10:04 110,415 –a—— C:\WINDOWS\BM87b86071.xml
2008-06-29 00:02 . 2004-08-04 00:56 10,752 –a—— C:\WINDOWS\system32\smtpapi.dll
2008-06-29 00:02 . 2004-08-04 00:56 9,728 –a—— C:\WINDOWS\system32\rwnh.dll
2008-06-28 22:56 . 2008-06-29 16:21 d——– C:\Program Files\Spyware Doctor
2008-06-28 22:56 . 2008-06-28 22:56 d——– C:\Documents and Settings\bmoliver\Application Data\PC Tools
2008-06-28 22:55 . 2008-06-28 22:56 d—s—- C:\Documents and Settings\Administrator
2008-06-28 18:35 . 2008-06-28 18:35 d——– C:\Temp\spydoc6 Folder
2008-06-28 18:34 . 2008-06-23 11:14 13,456,070 –a—— C:\Temp\sdsetup.exe
2008-06-28 18:34 . 2008-05-01 04:45 1,794,048 –a—— C:\Temp\Update.exe
2008-06-21 18:43 . 2008-06-21 18:43 d——– C:\Program Files\Reality Pump
2008-06-21 18:42 . 2008-06-21 18:42 d——– C:\WINDOWS\system32\AGEIA
2008-06-21 18:42 . 2008-06-21 18:42 d——– C:\Program Files\AGEIA Technologies
2008-06-21 18:41 . 2008-06-21 18:41 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-06-21 17:32 . 2008-06-21 17:45 d——– C:\Temp\VirtualDub-1.8.1
2008-06-20 21:21 . 2008-06-20 21:21 d——– C:\Documents and Settings\bmoliver\Application Data\Player
2008-06-20 21:00 . 2008-06-20 21:00 d——– C:\Program Files\ffdshow
2008-06-20 21:00 . 2007-02-12 19:21 10,752 –a—— C:\WINDOWS\system32\ff_vfw.dll
2008-06-20 21:00 . 2007-02-12 19:21 547 –a—— C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-06-20 20:59 . 2008-06-20 21:00 d——– C:\Program Files\Avi Player
2008-06-20 20:59 . 2008-06-20 20:59 36 –ah—– C:\WINDOWS\system32\swk.ini
2008-06-20 18:39 . 2008-06-20 18:39 50 –a—— C:\im.ini
2008-06-20 18:07 . 2008-06-20 18:07 d——– C:\Temp\IVT_BlueSoleil_6.0.227.0_for_32bit_OS
2008-06-20 17:36 . 2008-06-20 17:36 d——– C:\Program Files\Oxygen Software
2008-06-20 17:16 . 2008-06-20 18:43 d——– C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-06-20 17:11 . 2008-06-20 17:11 d——– C:\Program Files\IVT Corporation
2008-06-20 17:11 . 2008-06-20 18:41 32 –a—— C:\WINDOWS\0
2008-06-20 17:11 . 2008-06-20 17:11 0 –a—— C:\WINDOWS\system32\0
2008-06-19 22:19 . 2007-06-28 15:19 157,024 –a—— C:\WINDOWS\system32\drivers\ma730c.sys
2008-06-19 22:19 . 2007-03-05 10:42 103,680 –a—— C:\WINDOWS\system32\drivers\ma730Pt.sys
2008-06-19 22:19 . 2007-01-26 18:48 50,522 –a—— C:\WINDOWS\system32\drivers\Ma730Vad.sys
2008-06-19 22:19 . 2005-11-21 13:55 32,847 -ra—— C:\WINDOWS\system32\drivers\Ma730Hid.sys
2008-06-19 22:19 . 2006-04-13 16:08 23,160 –a—— C:\WINDOWS\system32\MA730PT.VXD
2008-06-19 22:19 . 2007-01-26 17:32 21,851 –a—— C:\WINDOWS\system32\drivers\Ma730VaA.sys
2008-06-19 18:19 . 2008-06-19 18:19 d——– C:\Temp\oxygen
2008-06-18 17:50 . 2008-06-18 17:50 d——– C:\Program Files\Common Files\PCSuite
2008-06-18 17:50 . 2008-06-18 17:50 d——– C:\Program Files\Common Files\Nokia
2008-06-18 17:50 . 2008-06-18 19:03 d——– C:\Documents and Settings\bmoliver\Application Data\PC Suite
2008-06-18 17:50 . 2008-06-18 19:04 d——– C:\Documents and Settings\bmoliver\Application Data\Nokia
2008-06-18 17:50 . 2008-06-18 17:50 d——– C:\Documents and Settings\All Users\Application Data\PC Suite
2008-06-18 17:49 . 2008-06-21 18:42 d—-c— C:\WINDOWS\system32\DRVSTORE
2008-06-18 17:49 . 2008-06-18 17:49 d——– C:\Program Files\PC Connectivity Solution
2008-06-18 17:49 . 2008-06-18 17:50 d——– C:\Program Files\Nokia
2008-06-18 17:49 . 2008-06-18 17:49 d——– C:\Program Files\DIFX
2008-06-18 17:49 . 2007-11-29 10:33 1,419,232 –a—— C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-06-18 17:49 . 2007-11-29 10:39 95,744 –a—— C:\WINDOWS\system32\nmwcdcocls.dll
2008-06-18 17:49 . 2007-11-29 10:32 48,128 –a—— C:\WINDOWS\system32\nmwcdcls.dll
2008-06-18 17:49 . 2007-09-17 15:53 21,632 –a—— C:\WINDOWS\system32\drivers\pccsmcfd.sys
2008-06-18 17:49 . 2007-11-29 10:39 19,328 –a—— C:\WINDOWS\system32\drivers\ccdcmbo.sys
2008-06-18 17:49 . 2007-11-29 10:39 16,896 –a—— C:\WINDOWS\system32\drivers\ccdcmb.sys
2008-06-18 17:49 . 2007-11-29 10:39 8,064 –a—— C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys
2008-06-18 17:49 . 2007-11-29 10:39 8,064 –a—— C:\WINDOWS\system32\drivers\usbser_lowerflt.sys
2008-06-18 17:48 . 2008-06-18 17:48 d——– C:\Documents and Settings\All Users\Application Data\Installations
2008-06-17 17:25 . 2004-08-04 00:56 152,576 –a—— C:\WINDOWS\system32\irftp.exe
2008-06-17 17:25 . 2004-08-04 00:56 152,576 –a–c— C:\WINDOWS\system32\dllcache\irftp.exe
2008-06-17 17:25 . 2004-08-04 00:56 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2008-06-17 17:25 . 2004-08-04 00:56 27,136 –a–c— C:\WINDOWS\system32\dllcache\irmon.dll
2008-06-17 17:25 . 2004-08-04 00:56 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2008-06-17 17:25 . 2004-08-04 00:56 8,192 –a–c— C:\WINDOWS\system32\dllcache\wshirda.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-13 15:03 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-07-13 14:42 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-07-13 04:15 ——— d—–w C:\Program Files\Java
2008-07-03 03:05 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-30 00:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-29 23:21 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-06-29 20:35 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-29 14:59 ——— d—–w C:\Program Files\The Witcher
2008-06-29 01:30 ——— d—–w C:\Documents and Settings\bmoliver\Application Data\uTorrent
2008-06-06 02:38 ——— d—–w C:\Documents and Settings\bmoliver\Application Data\TrueCrypt
2008-06-03 02:53 223,424 —-a-w C:\WINDOWS\system32\drivers\truecrypt.sys
2005-03-16 21:40 22,104 ——w C:\Documents and Settings\bmoliver\Application Data\GDIPFONTCACHEV1.DAT
2007-08-24 03:19 88 –sh–r C:\WINDOWS\system32\D0932FC783.sys
2007-08-24 03:21 2,516 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Avi Player"="C:\Program Files\Avi Player\AviPlayer.exe" [2007-09-05 01:38 629760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="C:\PROGRA~1\SYMANT~2\VPTray.exe" [2006-06-15 02:40 124656]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-17 22:04 185632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"RoxioEngineUtility"="C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 18:44 65536]
"RoxioDragToDisc"="C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-10-16 20:15 868352]
"RoxioAudioCentral"="C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe" [2003-07-15 12:38 319488]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 22:32 53248]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 00:11 49152]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 18:14 53408]
"BCWipeTM Startup"="C:\Program Files\Jetico\BCWipe\BCWipeTM.exe" [2004-10-27 03:13 307200]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 09:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"CARPService"="carpserv.exe" [2003-06-11 11:54 4608 C:\WINDOWS\system32\carpserv.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 110592 C:\WINDOWS\system32\bthprops.cpl]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 01:19:50 217193]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-07-18 09:09:59 113664]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-12 17:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HijackThis startup scan]
–a—— 2008-06-30 18:24 396288 C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"C:\\Program Files\\ASUS\\AsusUpdate\\Update.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\WINDOWS\\system32\\java.exe"=
"C:\\Program Files\\MUTE\\fileSharingMUTE.exe"=
"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\Reality Pump\\Two Worlds\\TwoWorlds.exe"=
"C:\\Program Files\\Reality Pump\\Two Worlds\\TwoWorlds_RADEON.exe"=

R0 BtHidBus;Bluetooth HID Bus Service;C:\WINDOWS\system32\Drivers\BtHidBus.sys [2008-01-21 19:28]
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-10-30 20:22]
R2 Creative Audio Pack Licensing Service;Creative Audio Pack Licensing Service;C:\Program Files\Common Files\Creative Labs Shared\Service\APLicensing.exe [2007-03-18 09:57]
R3 Ma730Pt;MA730 Bluetooth VCOM Driver;C:\WINDOWS\system32\DRIVERS\Ma730Pt.sys [2007-03-05 10:42]
R3 Ma730VaA;MA730 Bluetooth Advanced Audio;C:\WINDOWS\system32\DRIVERS\Ma730VaA.sys [2007-01-26 17:32]
R3 Ma730Vad;MA730 Bluetooth Audio;C:\WINDOWS\system32\DRIVERS\Ma730Vad.sys [2007-01-26 18:48]
S3 BCM42XX;Broadcom iLine10™ Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\bcm42xx5.sys [2001-08-17 05:11]
S3 IvtBtBUs;IVT Bluetooth Bus Service;C:\WINDOWS\system32\Drivers\IvtBtBus.sys [2008-01-21 19:28]
S4 BCSWAP;BCSWAP;C:\WINDOWS\system32\drivers\BCSWAP.sys [2004-10-27 23:28]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{670591bf-0bc3-11dc-87b2-000ea6a3d55d}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.pif

.
- - - - ORPHANS REMOVED - - - -

BHO-{83845ECF-0E56-4BD3-873A-5E1EB5972424} - C:\WINDOWS\system32\awtULbBS.dll
BHO-{F50DDDD0-CA9F-4DB3-A5BD-17FDFADA143C} - C:\WINDOWS\system32\hgGvutQJ.dll
HKLM-Run-lphc7l0j0en93 - C:\WINDOWS\system32\lphc7l0j0en93.exe
ShellExecuteHooks-{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll
ShellExecuteHooks-{FBF23B40-E3F0-101B-8488-00AA003E56F8} - shdocvw.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-13 08:02:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\nview.dll
.
———————— Other Running Processes ————————
.
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-07-13 8:12:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-13 15:11:54

Pre-Run: 29,909,499,904 bytes free
Post-Run: 29,802,135,552 bytes free

271 — E O F — 2008-06-11 05:25:29

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:15:57 AM, on 7/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\APLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\carpserv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Avi Player\AviPlayer.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.defaulthomepage.info
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BCWipeTM Startup] "C:\Program Files\Jetico\BCWipe\BCWipeTM.exe" startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Avi Player] "C:\Program Files\Avi Player\AviPlayer.exe" hmw
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1124159501783
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Audio Pack Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\APLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 9453 bytes

Brian :)
Hi

Did you create these reg files yourself?
C:\remove-policies-display.reg
C:\desktoptab.reg



Download Flash_Disinfector from here and save it to your desktop.
Doubleclick on Flash_Disinfector.exe to run it and follow the prompts.
Wait until it has finished scanning and then exit the program.
The utility may ask you to insert your flash drive and/or other removable drives. This may include your mobile phone.
Please do so and allow the utility to clean up those drives as well.



Remember to disconnect from the Internet before carrying out the next instruction, and to save the following script before you do.You must
also manually disable your anti-virus and anti-spyware programs. See the link below for instructions on doing this.

http://www.bleepingcomputer.com/forums/topic114351.html

Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\BM87b86071.xml
C:\WINDOWS\system32\swk.ini
C:\im.ini

Folder::
C:\Program Files\Avi Player

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Avi Player"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{670591bf-0bc3-11dc-87b2-000ea6a3d55d}]

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.


Once you have installed the Scanner, and the updated definitions, you can disconnect from the Internet and disable your anti-virus, to reduce scanning time. Re-enable the anti-virus before reconnecting to the Internet.
Instructions on disabling a variety of security programs can be found at the link below.

http://www.bleepingcomputer.com/forums/topic114351.html

In your next reply post:
ComboFix.txt
Kaspersky report
New HijackThis log taken after the above scan has run
Scan logs from ComboFix, Kaspersky, and Hijackthis are copied below:

ComboFix 08-07-12.4 - bmoliver 2008-07-13 9:04:10.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.481 [GMT -7:00]
Running from: D:\Downloads\ComboFix.exe
Command switches used :: C:\Documents and Settings\bmoliver\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\im.ini
C:\WINDOWS\BM87b86071.xml
C:\WINDOWS\system32\swk.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\im.ini
C:\Program Files\Avi Player
C:\Program Files\Avi Player\AviPlayer.exe
C:\Program Files\Avi Player\prog_ico.ico
C:\Program Files\Avi Player\soft_setup.exe
C:\Program Files\Avi Player\swk.ini
C:\Program Files\Avi Player\uninst.exe
C:\WINDOWS\BM87b86071.xml
C:\WINDOWS\system32\swk.ini

.
((((((((((((((((((((((((( Files Created from 2008-06-13 to 2008-07-13 )))))))))))))))))))))))))))))))
.

2008-07-13 07:36 . 2008-07-13 07:36 d——– C:\VundoFix Backups
2008-07-12 16:02 . 2008-07-12 16:02 d–hs—- C:\Documents and Settings\bmoliver\Phone Browser
2008-07-12 12:45 . 2004-08-03 23:08 25,600 –a—— C:\WINDOWS\system32\drivers\usbser.sys
2008-07-12 12:45 . 2004-08-03 23:08 25,600 –a–c— C:\WINDOWS\system32\dllcache\usbser.sys
2008-07-12 12:45 . 2008-07-12 12:45 0 –ah—– C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-07-12 12:45 . 2008-07-12 12:45 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-07-03 18:43 . 2008-07-03 09:45 1,330 –a—— C:\remove-policies-display.reg
2008-07-03 18:43 . 2008-07-03 09:48 1,330 –a—— C:\desktoptab.reg
2008-07-01 06:44 . 2008-07-01 06:44 d——– C:\Deckard
2008-07-01 06:33 . 2008-07-01 06:05 686,630 –a—— C:\dss.exe
2008-06-30 16:32 . 2008-06-30 16:32 d——– C:\Program Files\Trend Micro
2008-06-29 17:07 . 2008-07-01 17:14 211 –a—— C:\WINDOWS\wininit.ini
2008-06-29 16:18 . 2008-06-29 16:03 691,545 –a—— C:\WINDOWS\unins000.exe
2008-06-29 16:18 . 2008-06-29 16:18 2,543 –a—— C:\WINDOWS\unins000.dat
2008-06-29 09:39 . 2008-06-29 09:39 d——– C:\Documents and Settings\Administrator.BMO-1
2008-06-29 09:31 . 2008-06-26 18:27 1,396,264 –a—— C:\WindowsXP-KB948277-x86-ENU.exe
2008-06-29 09:31 . 2008-04-24 07:13 997,888 —–c— C:\WINDOWS\system32\dllcache\msgina.dll
2008-06-29 09:31 . 2008-04-24 06:17 507,392 —–c— C:\WINDOWS\system32\dllcache\winlogon.exe
2008-06-29 07:59 . 2008-06-29 07:59 d——– C:\WINDOWS\system32\Futuremark
2008-06-29 07:59 . 2008-06-29 07:59 d——– C:\Program Files\Filesweb
2008-06-29 07:59 . 2008-06-29 07:59 d——– C:\Program Files\EXIFViewer
2008-06-29 07:59 . 2008-06-29 07:59 d——– C:\Program Files\Better File Rename
2008-06-29 00:02 . 2004-08-04 00:56 10,752 –a—— C:\WINDOWS\system32\smtpapi.dll
2008-06-29 00:02 . 2004-08-04 00:56 9,728 –a—— C:\WINDOWS\system32\rwnh.dll
2008-06-28 22:56 . 2008-06-29 16:21 d——– C:\Program Files\Spyware Doctor
2008-06-28 22:56 . 2008-06-28 22:56 d——– C:\Documents and Settings\bmoliver\Application Data\PC Tools
2008-06-28 22:55 . 2008-06-28 22:56 d—s—- C:\Documents and Settings\Administrator
2008-06-28 18:35 . 2008-06-28 18:35 d——– C:\Temp\spydoc6 Folder
2008-06-28 18:34 . 2008-06-23 11:14 13,456,070 –a—— C:\Temp\sdsetup.exe
2008-06-28 18:34 . 2008-05-01 04:45 1,794,048 –a—— C:\Temp\Update.exe
2008-06-21 18:43 . 2008-06-21 18:43 d——– C:\Program Files\Reality Pump
2008-06-21 18:42 . 2008-06-21 18:42 d——– C:\WINDOWS\system32\AGEIA
2008-06-21 18:42 . 2008-06-21 18:42 d——– C:\Program Files\AGEIA Technologies
2008-06-21 18:41 . 2008-06-21 18:41 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-06-21 17:32 . 2008-06-21 17:45 d——– C:\Temp\VirtualDub-1.8.1
2008-06-20 21:21 . 2008-06-20 21:21 d——– C:\Documents and Settings\bmoliver\Application Data\Player
2008-06-20 21:00 . 2008-06-20 21:00 d——– C:\Program Files\ffdshow
2008-06-20 21:00 . 2007-02-12 19:21 10,752 –a—— C:\WINDOWS\system32\ff_vfw.dll
2008-06-20 21:00 . 2007-02-12 19:21 547 –a—— C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-06-20 18:07 . 2008-06-20 18:07 d——– C:\Temp\IVT_BlueSoleil_6.0.227.0_for_32bit_OS
2008-06-20 17:36 . 2008-06-20 17:36 d——– C:\Program Files\Oxygen Software
2008-06-20 17:16 . 2008-06-20 18:43 d——– C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-06-20 17:11 . 2008-06-20 17:11 d——– C:\Program Files\IVT Corporation
2008-06-20 17:11 . 2008-06-20 18:41 32 –a—— C:\WINDOWS\0
2008-06-20 17:11 . 2008-06-20 17:11 0 –a—— C:\WINDOWS\system32\0
2008-06-19 22:19 . 2007-06-28 15:19 157,024 –a—— C:\WINDOWS\system32\drivers\ma730c.sys
2008-06-19 22:19 . 2007-03-05 10:42 103,680 –a—— C:\WINDOWS\system32\drivers\ma730Pt.sys
2008-06-19 22:19 . 2007-01-26 18:48 50,522 –a—— C:\WINDOWS\system32\drivers\Ma730Vad.sys
2008-06-19 22:19 . 2005-11-21 13:55 32,847 -ra—— C:\WINDOWS\system32\drivers\Ma730Hid.sys
2008-06-19 22:19 . 2006-04-13 16:08 23,160 –a—— C:\WINDOWS\system32\MA730PT.VXD
2008-06-19 22:19 . 2007-01-26 17:32 21,851 –a—— C:\WINDOWS\system32\drivers\Ma730VaA.sys
2008-06-19 18:19 . 2008-06-19 18:19 d——– C:\Temp\oxygen
2008-06-18 17:50 . 2008-06-18 17:50 d——– C:\Program Files\Common Files\PCSuite
2008-06-18 17:50 . 2008-06-18 17:50 d——– C:\Program Files\Common Files\Nokia
2008-06-18 17:50 . 2008-06-18 19:03 d——– C:\Documents and Settings\bmoliver\Application Data\PC Suite
2008-06-18 17:50 . 2008-06-18 19:04 d——– C:\Documents and Settings\bmoliver\Application Data\Nokia
2008-06-18 17:50 . 2008-06-18 17:50 d——– C:\Documents and Settings\All Users\Application Data\PC Suite
2008-06-18 17:49 . 2008-06-21 18:42 d—-c— C:\WINDOWS\system32\DRVSTORE
2008-06-18 17:49 . 2008-06-18 17:49 d——– C:\Program Files\PC Connectivity Solution
2008-06-18 17:49 . 2008-06-18 17:50 d——– C:\Program Files\Nokia
2008-06-18 17:49 . 2008-06-18 17:49 d——– C:\Program Files\DIFX
2008-06-18 17:49 . 2007-11-29 10:33 1,419,232 –a—— C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-06-18 17:49 . 2007-11-29 10:39 95,744 –a—— C:\WINDOWS\system32\nmwcdcocls.dll
2008-06-18 17:49 . 2007-11-29 10:32 48,128 –a—— C:\WINDOWS\system32\nmwcdcls.dll
2008-06-18 17:49 . 2007-09-17 15:53 21,632 –a—— C:\WINDOWS\system32\drivers\pccsmcfd.sys
2008-06-18 17:49 . 2007-11-29 10:39 19,328 –a—— C:\WINDOWS\system32\drivers\ccdcmbo.sys
2008-06-18 17:49 . 2007-11-29 10:39 16,896 –a—— C:\WINDOWS\system32\drivers\ccdcmb.sys
2008-06-18 17:49 . 2007-11-29 10:39 8,064 –a—— C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys
2008-06-18 17:49 . 2007-11-29 10:39 8,064 –a—— C:\WINDOWS\system32\drivers\usbser_lowerflt.sys
2008-06-18 17:48 . 2008-06-18 17:48 d——– C:\Documents and Settings\All Users\Application Data\Installations
2008-06-17 17:25 . 2004-08-04 00:56 152,576 –a—— C:\WINDOWS\system32\irftp.exe
2008-06-17 17:25 . 2004-08-04 00:56 152,576 –a–c— C:\WINDOWS\system32\dllcache\irftp.exe
2008-06-17 17:25 . 2004-08-04 00:56 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2008-06-17 17:25 . 2004-08-04 00:56 27,136 –a–c— C:\WINDOWS\system32\dllcache\irmon.dll
2008-06-17 17:25 . 2004-08-04 00:56 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2008-06-17 17:25 . 2004-08-04 00:56 8,192 –a–c— C:\WINDOWS\system32\dllcache\wshirda.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-13 16:02 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-07-13 15:57 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-07-13 04:15 ——— d—–w C:\Program Files\Java
2008-07-03 03:05 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-30 00:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-29 23:21 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-06-29 20:35 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-29 14:59 ——— d—–w C:\Program Files\The Witcher
2008-06-29 01:30 ——— d—–w C:\Documents and Settings\bmoliver\Application Data\uTorrent
2008-06-06 02:38 ——— d—–w C:\Documents and Settings\bmoliver\Application Data\TrueCrypt
2008-06-03 02:53 223,424 —-a-w C:\WINDOWS\system32\drivers\truecrypt.sys
2008-05-07 05:18 1,287,680 ——w C:\WINDOWS\system32\quartz.dll
2008-05-01 00:27 442,368 —-a-w C:\WINDOWS\system32\NVUNINST.EXE
2008-04-25 02:43 423,936 —-a-w C:\WINDOWS\system32\licdll.dll
2008-04-24 14:13 997,888 —-a-w C:\WINDOWS\system32\msgina.dll
2008-04-24 13:17 507,392 —-a-w C:\WINDOWS\system32\winlogon.exe
2008-04-21 07:04 659,456 —-a-w C:\WINDOWS\system32\wininet.dll
2005-03-16 21:40 22,104 ——w C:\Documents and Settings\bmoliver\Application Data\GDIPFONTCACHEV1.DAT
2007-08-24 03:19 88 –sh–r C:\WINDOWS\system32\D0932FC783.sys
2007-08-24 03:21 2,516 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2008-07-13_ 8.11.34.43 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-13 15:01:14 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-13 15:39:17 2,048 –s-a-w C:\WINDOWS\bootstat.dat
- 2004-07-17 18:36:38 27,440 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
+ 2007-11-13 10:25:53 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="C:\PROGRA~1\SYMANT~2\VPTray.exe" [2006-06-15 02:40 124656]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-17 22:04 185632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"RoxioEngineUtility"="C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 18:44 65536]
"RoxioDragToDisc"="C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-10-16 20:15 868352]
"RoxioAudioCentral"="C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe" [2003-07-15 12:38 319488]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 22:32 53248]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 00:11 49152]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 18:14 53408]
"BCWipeTM Startup"="C:\Program Files\Jetico\BCWipe\BCWipeTM.exe" [2004-10-27 03:13 307200]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 09:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"CARPService"="carpserv.exe" [2003-06-11 11:54 4608 C:\WINDOWS\system32\carpserv.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 110592 C:\WINDOWS\system32\bthprops.cpl]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 01:19:50 217193]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-07-18 09:09:59 113664]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-12 17:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HijackThis startup scan]
–a—— 2008-06-30 18:24 396288 C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"C:\\Program Files\\ASUS\\AsusUpdate\\Update.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\WINDOWS\\system32\\java.exe"=
"C:\\Program Files\\MUTE\\fileSharingMUTE.exe"=
"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\Reality Pump\\Two Worlds\\TwoWorlds.exe"=
"C:\\Program Files\\Reality Pump\\Two Worlds\\TwoWorlds_RADEON.exe"=

R0 BtHidBus;Bluetooth HID Bus Service;C:\WINDOWS\system32\Drivers\BtHidBus.sys [2008-01-21 19:28]
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-10-30 20:22]
R2 Creative Audio Pack Licensing Service;Creative Audio Pack Licensing Service;C:\Program Files\Common Files\Creative Labs Shared\Service\APLicensing.exe [2007-03-18 09:57]
R3 Ma730Pt;MA730 Bluetooth VCOM Driver;C:\WINDOWS\system32\DRIVERS\Ma730Pt.sys [2007-03-05 10:42]
R3 Ma730VaA;MA730 Bluetooth Advanced Audio;C:\WINDOWS\system32\DRIVERS\Ma730VaA.sys [2007-01-26 17:32]
R3 Ma730Vad;MA730 Bluetooth Audio;C:\WINDOWS\system32\DRIVERS\Ma730Vad.sys [2007-01-26 18:48]
S3 BCM42XX;Broadcom iLine10™ Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\bcm42xx5.sys [2001-08-17 05:11]
S3 IvtBtBUs;IVT Bluetooth Bus Service;C:\WINDOWS\system32\Drivers\IvtBtBus.sys [2008-01-21 19:28]
S4 BCSWAP;BCSWAP;C:\WINDOWS\system32\drivers\BCSWAP.sys [2004-10-27 23:28]

*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-13 09:08:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-07-13 9:10:47
ComboFix-quarantined-files.txt 2008-07-13 16:10:14
ComboFix2.txt 2008-07-13 15:12:08

Pre-Run: 29,748,224,000 bytes free
Post-Run: 29,729,251,328 bytes free

224 — E O F — 2008-07-13 15:32:04

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Sunday, July 13, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Sunday, July 13, 2008 15:35:17
Records in database: 948998
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
F:\
G:\
J:\
K:\
L:\
M:\
O:\
P:\

Scan statistics:
Files scanned: 165327
Threat name: 16
Infected objects: 40
Suspicious objects: 2
Duration of the scan: 05:32:21


File name / Threat name / Threats count
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02B00000\47B13F4D.VBN Infected: Virus.Win32.Virut.n 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\040C0000.VBN Suspicious: Packed.Win32.PePatch.dk 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\040C0008.VBN Infected: Virus.Win32.Virut.n 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\040C0009.VBN Infected: Virus.Win32.Virut.n 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80000\48BAA378.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.pae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80000\48BAA378.VBN Infected: Trojan-Downloader.Win32.Small.ury 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80000\48BAA378.VBN Infected: Trojan-Downloader.Win32.Small.ujl 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80001\48BAA390.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.pae 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80001\48BAA390.VBN Infected: Trojan-Downloader.Win32.Small.ury 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80001\48BAA390.VBN Infected: Trojan-Downloader.Win32.Small.ujl 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09700000\4978E405.VBN Infected: Trojan.Win32.Monderc.gen 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09700001\4978E6DA.VBN Infected: Trojan.Win32.Monderc.gen 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09700002\4978E6EF.VBN Infected: Trojan.Win32.Monderc.gen 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09700003\4978F263.VBN Infected: Trojan.Win32.Monderc.gen 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09F80000.VBN Infected: Trojan-Downloader.Java.OpenStream.w 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0E400000\4ED4C21A.VBN Infected: Constructor.Win32.MicroJoiner.17 1
C:\QooBox\Quarantine\C\WINDOWS\system32\awtrRHXr.dll.vir Infected: Trojan.Win32.Monderc.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\brgaifhf.dll.vir Infected: Trojan.Win32.Monderc.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\cbXnklii.dll.vir Infected: Trojan.Win32.Monderc.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\ddcBUonK.dll.vir Infected: Trojan.Win32.Pakes.den 1
C:\QooBox\Quarantine\C\WINDOWS\system32\ibpwxies.dll.vir Infected: Trojan.Win32.Monderc.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\iifgHArp.dll.vir Infected: Trojan.Win32.Pakes.den 1
C:\QooBox\Quarantine\C\WINDOWS\system32\ljJCstsS.dll.vir Infected: Trojan.Win32.Pakes.den 1
C:\QooBox\Quarantine\C\WINDOWS\system32\miumfq.dll.vir Infected: Trojan.Win32.Monderc.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\rqRIaWMc.dll.vir Infected: Trojan.Win32.Pakes.den 1
C:\QooBox\Quarantine\C\WINDOWS\system32\urqNhHww.dll.vir Infected: Trojan.Win32.Pakes.den 1
C:\QooBox\Quarantine\C\WINDOWS\system32\vbkyebws.dll.vir Infected: Trojan.Win32.Monderc.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\wvULeBrr.dll.vir Infected: Trojan.Win32.Monderc.gen 1
C:\Temp\sdsetup.exe Infected: Trojan.Win32.Pakes.den 1
C:\Temp\spydoc6 Folder\sdsetup.exe Infected: Trojan.Win32.Pakes.den 1
D:\Downloads\BS241.exe Infected: not-a-virus:AdWare.Win32.180Solutions.d 1
D:\Downloads\BS241.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
D:\Downloads\BS241.exe Infected: not-a-virus:AdWare.Win32.SaveNow.av 1
D:\Downloads\BS241.exe Infected: not-a-virus:AdWare.Win32.SaveNow.au 1
D:\Downloads\dev-tep2.rar Infected: Trojan.Win32.Agent.ref 1
D:\Downloads\Diablo2_106_eng_nocd.zip Suspicious: Packed.Win32.PePatch.dk 1
D:\Downloads\install_asm_en.exe Infected: not-a-virus:FraudTool.Win32.AntiSpywareExpert.s 1
D:\Downloads\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
D:\Downloads\SmitfraudFix.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
D:\My Documents\Downloads\spydoc6 Folder.rar Infected: Trojan.Win32.Pakes.den 1
O:\Second Copy\BMO Files\My Documents\Downloads\QuickTax 2007 Standard.rar Infected: Virus.Win32.Virut.n 1
O:\Second Copy\BMO Files\My Documents\Downloads\spydoc6 Folder.rar Infected: Trojan.Win32.Pakes.den 1

The selected area was scanned.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:19:02 PM, on 7/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\APLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Documents and Settings\bmoliver\Local Settings\temp\jkos-bmoliver\binaries\ScanningProcess.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclIVTBTSrv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.defaulthomepage.info
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BCWipeTM Startup] "C:\Program Files\Jetico\BCWipe\BCWipeTM.exe" startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1124159501783
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Audio Pack Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\APLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 9325 bytes

Thanks,

Brian
Hi

Remember to disconnect from the Internet before carrying out the next instruction, and to save the following script before you do.You must
also manually disable your anti-virus and anti-spyware programs. See the link below for instructions on doing this.

http://www.bleepingcomputer.com/forums/topic114351.html

Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02B00000\47B13F4D.VBN
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\040C0000.VBN 
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\040C0008.VBN 
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\040C0009.VBN 
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80000\48BAA378.VBN 
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80000\48BAA378.VBN 
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80000\48BAA378.VBN 
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80001\48BAA390.VBN 
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80001\48BAA390.VBN 
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80001\48BAA390.VBN 
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09700000\4978E405.VBN 
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09700001\4978E6DA.VBN 
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09700002\4978E6EF.VBN 
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09700003\4978F263.VBN 
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09F80000.VBN 
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0E400000\4ED4C21A.VBN
C:\Temp\sdsetup.exe
C:\Temp\Update.exe
C:\WINDOWS\0
C:\WINDOWS\system32\0
D:\Downloads\BS241.exe
D:\Downloads\install_asm_en.exe
D:\Downloads\SmitfraudFix.exe

Folder::
C:\Temp\spydoc6 Folder
C:\VundoFix Backups

D:\Downloads\dev-tep2.rar 
D:\Downloads\Diablo2_106_eng_nocd.zip
D:\Downloads\SmitfraudFix
D:\My Documents\Downloads\spydoc6 Folder.rar 
O:\Second Copy\BMO Files\My Documents\Downloads\QuickTax 2007 Standard.rar
O:\Second Copy\BMO Files\My Documents\Downloads\spydoc6 Folder.rar

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe


Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Post that log back here.

In your next reply post:
ComboFix.txt
MBAM log
New HijackThis log taken after the above scan has run
Most recent log files are attached.

ComboFix 08-07-12.4 - bmoliver 2008-07-14 17:01:58.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.455 [GMT -7:00]
Running from: D:\Downloads\ComboFix.exe
Command switches used :: C:\Documents and Settings\bmoliver\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02B00000\47B13F4D.VBN
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\040C0000.VBN
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\040C0008.VBN
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\040C0009.VBN
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80000\48BAA378.VBN
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80001\48BAA390.VBN
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09700000\4978E405.VBN
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09700001\4978E6DA.VBN
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09700002\4978E6EF.VBN
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09700003\4978F263.VBN
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09F80000.VBN
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0E400000\4ED4C21A.VBN
C:\Temp\sdsetup.exe
C:\Temp\Update.exe
C:\WINDOWS\0
C:\WINDOWS\system32\0
D:\Downloads\BS241.exe
D:\Downloads\install_asm_en.exe
D:\Downloads\SmitfraudFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Temp\sdsetup.exe
C:\Temp\spydoc6 Folder
C:\Temp\spydoc6 Folder\Instructions.txt
C:\Temp\spydoc6 Folder\sdsetup.exe
C:\Temp\spydoc6 Folder\Update.exe
C:\Temp\Update.exe
C:\VundoFix Backups
C:\WINDOWS\0
C:\WINDOWS\system32\0
D:\Downloads\BS241.exe
D:\Downloads\dev-tep2.rar\
D:\Downloads\Diablo2_106_eng_nocd.zip\
D:\Downloads\install_asm_en.exe
D:\Downloads\SmitfraudFix
D:\Downloads\SmitfraudFix.exe
D:\Downloads\SmitfraudFix\dumphive.exe
D:\Downloads\SmitfraudFix\GenericRenosFix.exe
D:\Downloads\SmitfraudFix\Process.exe
D:\Downloads\SmitfraudFix\Reboot.exe
D:\Downloads\SmitfraudFix\restart.exe
D:\Downloads\SmitfraudFix\SmitfraudFix.cmd
D:\Downloads\SmitfraudFix\SmiUpdate.exe
D:\Downloads\SmitfraudFix\SrchSTS.exe
D:\Downloads\SmitfraudFix\swreg.exe
D:\Downloads\SmitfraudFix\swsc.exe
D:\Downloads\SmitfraudFix\swxcacls.exe
D:\Downloads\SmitfraudFix\unzip.exe
D:\My Documents\Downloads\spydoc6 Folder.rar\
O:\Second Copy\BMO Files\My Documents\Downloads\spydoc6 Folder.rar\

.
((((((((((((((((((((((((( Files Created from 2008-06-15 to 2008-07-15 )))))))))))))))))))))))))))))))
.

2008-07-12 16:02 . 2008-07-12 16:02 d–hs—- C:\Documents and Settings\bmoliver\Phone Browser
2008-07-12 12:45 . 2004-08-03 23:08 25,600 –a—— C:\WINDOWS\system32\drivers\usbser.sys
2008-07-12 12:45 . 2004-08-03 23:08 25,600 –a–c— C:\WINDOWS\system32\dllcache\usbser.sys
2008-07-12 12:45 . 2008-07-12 12:45 0 –ah—– C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-07-12 12:45 . 2008-07-12 12:45 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-07-03 18:43 . 2008-07-03 09:45 1,330 –a—— C:\remove-policies-display.reg
2008-07-03 18:43 . 2008-07-03 09:48 1,330 –a—— C:\desktoptab.reg
2008-07-01 06:44 . 2008-07-01 06:44 d——– C:\Deckard
2008-07-01 06:33 . 2008-07-01 06:05 686,630 –a—— C:\dss.exe
2008-06-30 16:32 . 2008-06-30 16:32 d——– C:\Program Files\Trend Micro
2008-06-29 17:07 . 2008-07-01 17:14 211 –a—— C:\WINDOWS\wininit.ini
2008-06-29 16:18 . 2008-06-29 16:03 691,545 –a—— C:\WINDOWS\unins000.exe
2008-06-29 16:18 . 2008-06-29 16:18 2,543 –a—— C:\WINDOWS\unins000.dat
2008-06-29 09:39 . 2008-06-29 09:39 d——– C:\Documents and Settings\Administrator.BMO-1
2008-06-29 09:31 . 2008-06-26 18:27 1,396,264 –a—— C:\WindowsXP-KB948277-x86-ENU.exe
2008-06-29 09:31 . 2008-04-24 07:13 997,888 —–c— C:\WINDOWS\system32\dllcache\msgina.dll
2008-06-29 09:31 . 2008-04-24 06:17 507,392 —–c— C:\WINDOWS\system32\dllcache\winlogon.exe
2008-06-29 07:59 . 2008-06-29 07:59 d——– C:\WINDOWS\system32\Futuremark
2008-06-29 07:59 . 2008-06-29 07:59 d——– C:\Program Files\Filesweb
2008-06-29 07:59 . 2008-06-29 07:59 d——– C:\Program Files\EXIFViewer
2008-06-29 07:59 . 2008-06-29 07:59 d——– C:\Program Files\Better File Rename
2008-06-28 22:56 . 2008-06-29 16:21 d——– C:\Program Files\Spyware Doctor
2008-06-28 22:56 . 2008-06-28 22:56 d——– C:\Documents and Settings\bmoliver\Application Data\PC Tools
2008-06-28 22:55 . 2008-06-28 22:56 d—s—- C:\Documents and Settings\Administrator
2008-06-21 18:43 . 2008-06-21 18:43 d——– C:\Program Files\Reality Pump
2008-06-21 18:42 . 2008-06-21 18:42 d——– C:\WINDOWS\system32\AGEIA
2008-06-21 18:42 . 2008-06-21 18:42 d——– C:\Program Files\AGEIA Technologies
2008-06-21 18:41 . 2008-06-21 18:41 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-06-21 17:32 . 2008-06-21 17:45 d——– C:\Temp\VirtualDub-1.8.1
2008-06-20 21:21 . 2008-06-20 21:21 d——– C:\Documents and Settings\bmoliver\Application Data\Player
2008-06-20 21:00 . 2008-06-20 21:00 d——– C:\Program Files\ffdshow
2008-06-20 21:00 . 2007-02-12 19:21 10,752 –a—— C:\WINDOWS\system32\ff_vfw.dll
2008-06-20 21:00 . 2007-02-12 19:21 547 –a—— C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-06-20 18:07 . 2008-06-20 18:07 d——– C:\Temp\IVT_BlueSoleil_6.0.227.0_for_32bit_OS
2008-06-20 17:36 . 2008-06-20 17:36 d——– C:\Program Files\Oxygen Software
2008-06-20 17:16 . 2008-06-20 18:43 d——– C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-06-20 17:11 . 2008-06-20 17:11 d——– C:\Program Files\IVT Corporation
2008-06-19 22:19 . 2007-06-28 15:19 157,024 –a—— C:\WINDOWS\system32\drivers\ma730c.sys
2008-06-19 22:19 . 2007-03-05 10:42 103,680 –a—— C:\WINDOWS\system32\drivers\ma730Pt.sys
2008-06-19 22:19 . 2007-01-26 18:48 50,522 –a—— C:\WINDOWS\system32\drivers\Ma730Vad.sys
2008-06-19 22:19 . 2005-11-21 13:55 32,847 -ra—— C:\WINDOWS\system32\drivers\Ma730Hid.sys
2008-06-19 22:19 . 2006-04-13 16:08 23,160 –a—— C:\WINDOWS\system32\MA730PT.VXD
2008-06-19 22:19 . 2007-01-26 17:32 21,851 –a—— C:\WINDOWS\system32\drivers\Ma730VaA.sys
2008-06-19 18:19 . 2008-06-19 18:19 d——– C:\Temp\oxygen
2008-06-18 17:50 . 2008-06-18 17:50 d——– C:\Program Files\Common Files\PCSuite
2008-06-18 17:50 . 2008-06-18 17:50 d——– C:\Program Files\Common Files\Nokia
2008-06-18 17:50 . 2008-06-18 19:03 d——– C:\Documents and Settings\bmoliver\Application Data\PC Suite
2008-06-18 17:50 . 2008-06-18 19:04 d——– C:\Documents and Settings\bmoliver\Application Data\Nokia
2008-06-18 17:50 . 2008-06-18 17:50 d——– C:\Documents and Settings\All Users\Application Data\PC Suite
2008-06-18 17:49 . 2008-06-21 18:42 d—-c— C:\WINDOWS\system32\DRVSTORE
2008-06-18 17:49 . 2008-06-18 17:49 d——– C:\Program Files\PC Connectivity Solution
2008-06-18 17:49 . 2008-06-18 17:50 d——– C:\Program Files\Nokia
2008-06-18 17:49 . 2008-06-18 17:49 d——– C:\Program Files\DIFX
2008-06-18 17:49 . 2007-11-29 10:33 1,419,232 –a—— C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-06-18 17:49 . 2007-11-29 10:39 95,744 –a—— C:\WINDOWS\system32\nmwcdcocls.dll
2008-06-18 17:49 . 2007-11-29 10:32 48,128 –a—— C:\WINDOWS\system32\nmwcdcls.dll
2008-06-18 17:49 . 2007-09-17 15:53 21,632 –a—— C:\WINDOWS\system32\drivers\pccsmcfd.sys
2008-06-18 17:49 . 2007-11-29 10:39 19,328 –a—— C:\WINDOWS\system32\drivers\ccdcmbo.sys
2008-06-18 17:49 . 2007-11-29 10:39 16,896 –a—— C:\WINDOWS\system32\drivers\ccdcmb.sys
2008-06-18 17:49 . 2007-11-29 10:39 8,064 –a—— C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys
2008-06-18 17:49 . 2007-11-29 10:39 8,064 –a—— C:\WINDOWS\system32\drivers\usbser_lowerflt.sys
2008-06-18 17:48 . 2008-06-18 17:48 d——– C:\Documents and Settings\All Users\Application Data\Installations
2008-06-17 17:25 . 2004-08-04 00:56 152,576 –a—— C:\WINDOWS\system32\irftp.exe
2008-06-17 17:25 . 2004-08-04 00:56 152,576 –a–c— C:\WINDOWS\system32\dllcache\irftp.exe
2008-06-17 17:25 . 2004-08-04 00:56 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2008-06-17 17:25 . 2004-08-04 00:56 27,136 –a–c— C:\WINDOWS\system32\dllcache\irmon.dll
2008-06-17 17:25 . 2004-08-04 00:56 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2008-06-17 17:25 . 2004-08-04 00:56 8,192 –a–c— C:\WINDOWS\system32\dllcache\wshirda.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-15 00:01 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-07-14 23:50 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-07-13 04:15 ——— d—–w C:\Program Files\Java
2008-07-03 03:05 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-30 00:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-29 23:21 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-06-29 20:35 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-29 14:59 ——— d—–w C:\Program Files\The Witcher
2008-06-29 01:30 ——— d—–w C:\Documents and Settings\bmoliver\Application Data\uTorrent
2008-06-06 02:38 ——— d—–w C:\Documents and Settings\bmoliver\Application Data\TrueCrypt
2008-06-03 02:53 223,424 —-a-w C:\WINDOWS\system32\drivers\truecrypt.sys
2008-05-07 05:18 1,287,680 ——w C:\WINDOWS\system32\quartz.dll
2008-05-01 00:27 442,368 —-a-w C:\WINDOWS\system32\NVUNINST.EXE
2008-04-25 02:43 423,936 —-a-w C:\WINDOWS\system32\licdll.dll
2008-04-24 14:13 997,888 —-a-w C:\WINDOWS\system32\msgina.dll
2008-04-24 13:17 507,392 —-a-w C:\WINDOWS\system32\winlogon.exe
2008-04-21 07:04 659,456 —-a-w C:\WINDOWS\system32\wininet.dll
2005-03-16 21:40 22,104 ——w C:\Documents and Settings\bmoliver\Application Data\GDIPFONTCACHEV1.DAT
2007-08-24 03:19 88 –sh–r C:\WINDOWS\system32\D0932FC783.sys
2007-08-24 03:21 2,516 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2008-07-13_ 8.11.34.43 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-13 15:01:14 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-14 23:48:30 2,048 –s-a-w C:\WINDOWS\bootstat.dat
- 2004-07-17 18:36:38 27,440 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
+ 2007-11-13 10:25:53 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
- 2008-06-29 14:21:30 74,460 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-07-13 22:25:04 74,460 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-06-29 14:21:30 431,200 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-07-13 22:25:04 431,200 —-a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="C:\PROGRA~1\SYMANT~2\VPTray.exe" [2006-06-15 02:40 124656]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-17 22:04 185632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"RoxioEngineUtility"="C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 18:44 65536]
"RoxioDragToDisc"="C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-10-16 20:15 868352]
"RoxioAudioCentral"="C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe" [2003-07-15 12:38 319488]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 22:32 53248]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 00:11 49152]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 18:14 53408]
"BCWipeTM Startup"="C:\Program Files\Jetico\BCWipe\BCWipeTM.exe" [2004-10-27 03:13 307200]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 09:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"CARPService"="carpserv.exe" [2003-06-11 11:54 4608 C:\WINDOWS\system32\carpserv.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 110592 C:\WINDOWS\system32\bthprops.cpl]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 01:19:50 217193]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-07-18 09:09:59 113664]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-12 17:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HijackThis startup scan]
–a—— 2008-06-30 18:24 396288 C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"C:\\Program Files\\ASUS\\AsusUpdate\\Update.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\WINDOWS\\system32\\java.exe"=
"C:\\Program Files\\MUTE\\fileSharingMUTE.exe"=
"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\Reality Pump\\Two Worlds\\TwoWorlds.exe"=
"C:\\Program Files\\Reality Pump\\Two Worlds\\TwoWorlds_RADEON.exe"=

R0 BtHidBus;Bluetooth HID Bus Service;C:\WINDOWS\system32\Drivers\BtHidBus.sys [2008-01-21 19:28]
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-10-30 20:22]
R2 Creative Audio Pack Licensing Service;Creative Audio Pack Licensing Service;C:\Program Files\Common Files\Creative Labs Shared\Service\APLicensing.exe [2007-03-18 09:57]
R3 Ma730Pt;MA730 Bluetooth VCOM Driver;C:\WINDOWS\system32\DRIVERS\Ma730Pt.sys [2007-03-05 10:42]
R3 Ma730VaA;MA730 Bluetooth Advanced Audio;C:\WINDOWS\system32\DRIVERS\Ma730VaA.sys [2007-01-26 17:32]
R3 Ma730Vad;MA730 Bluetooth Audio;C:\WINDOWS\system32\DRIVERS\Ma730Vad.sys [2007-01-26 18:48]
S3 BCM42XX;Broadcom iLine10™ Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\bcm42xx5.sys [2001-08-17 05:11]
S3 IvtBtBUs;IVT Bluetooth Bus Service;C:\WINDOWS\system32\Drivers\IvtBtBus.sys [2008-01-21 19:28]
S4 BCSWAP;BCSWAP;C:\WINDOWS\system32\drivers\BCSWAP.sys [2004-10-27 23:28]

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-14 17:06:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-07-14 17:08:33
ComboFix-quarantined-files.txt 2008-07-15 00:08:07
ComboFix2.txt 2008-07-13 16:10:48
ComboFix3.txt 2008-07-13 15:12:08

Pre-Run: 29,376,012,288 bytes free
Post-Run: 29,393,821,696 bytes free

256 — E O F — 2008-07-13 15:32:04


Malwarebytes' Anti-Malware 1.20
Database version: 950
Windows 5.1.2600 Service Pack 2

7:14:11 PM 7/14/2008
mbam-log-7-14-2008 (19-14-11).txt

Scan type: Full Scan (C:\|D:\|O:\|)
Objects scanned: 200224
Time elapsed: 1 hour(s), 57 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 12

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\QooBox\Quarantine\C\WINDOWS\system32\ddcBUonK.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\iifgHArp.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\ljJCstsS.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\rqRIaWMc.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\urqNhHww.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\wvULeBrr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{298090D0-7793-4C4E-8F27-CCF2F80CD237}\RP2\A0000010.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{298090D0-7793-4C4E-8F27-CCF2F80CD237}\RP2\A0000012.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{298090D0-7793-4C4E-8F27-CCF2F80CD237}\RP2\A0000013.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{298090D0-7793-4C4E-8F27-CCF2F80CD237}\RP2\A0000015.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{298090D0-7793-4C4E-8F27-CCF2F80CD237}\RP2\A0000016.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{298090D0-7793-4C4E-8F27-CCF2F80CD237}\RP2\A0000018.dll (Trojan.Vundo) -> Quarantined and deleted successfully.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:15:10 PM, on 7/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\APLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\carpserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\System32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.defaulthomepage.info
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BCWipeTM Startup] "C:\Program Files\Jetico\BCWipe\BCWipeTM.exe" startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1124159501783
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Audio Pack Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\APLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 8853 bytes


Thanks,

Brian :)
Hi

Congratulations, you appear to be malware free. :woot:

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the x and the /u, it needs to be there.

    [external image: Posted Image]


Malwarebytes Anti-Malware is a good program to keep. If you wish to keep it, use it to do a quick scan once a week and keep it updated.
Remember, only the paid for version offers real-time protection

Here is another couple of free programs I recommend.

Winpatrol
Winpatrol is heuristic protection program, meaning it looks for patterns in codes that work like malware. It also takes a snapshot of your system's critical resources and alerts you to any changes that may occur without you knowing. You can read more about Winpatrol's features here.

You can get a free copy of Winpatrol or use the Plus version for more features.

You can read Winpatrol's FAQ if you run into problems.

Spyware Blaster
SpywareBlaster is a program that is used to secure Internet Explorer by making it harder for ActiveX programs to run on your computer. It does this by disabling known offending ActiveX programs from running at all.

You can download SpywareBlaster from Javacool.

If you need help in using SpywareBlaster, you can read SpywareBlaster's tutorial at Bleeping Computer.


Hosts File
A Hosts file is like a phone book. You look up someone's name in the phone book before calling him/her. Similarly, your PC will look up the website's IP address before you can view the website.

Hosts file will replace your current Hosts file with another one containing well-known advertisement sites, spyware sites and other bad sites. This new Hosts file will protect you by re-directing these bad sites to 127.0.0.1.

Here is a good Hosts file:

MVPS Hosts File

A tutorial about Hosts File can be found at Malware Removal.


Make sure your Windows is ALWAYS up to date!

An unpatched Windows is vulnerable and even with the "best" Antivirus and Firewall installed, malware will find its way through.
So visit http://windowsupdate.microsoft.com/ to download and install the latest updates.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.


Here is some great information from experts in this field that will help you stay clean and safe online.
http://forum.malwareremoval.com/viewtopic.php?t=14

Follow this list and your potential for being infected again will reduce dramatically.

I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can be closed.
Scotty, Thanks very much for all your help. BTW, my wife's computer was also affected, so I reinstalled XP on her machine (without re-formatting). I will keep scanning hers to make sure the Trojan.Vundu is gone. I noticed that you deleted "AVI Player". Do you think this was the source of the infection, or were you just being conservative. The reason I ask is that I have AVI Player installed on one of my flash drives. Scanning that drive does not show any problems, however. Brian :woot:
Hi

AVI Player is considered by many as dubious but may not have been the source. I take it you will be needing a replacement avi player? I use this media player on both Windows and Linux.
VLC Media Player
VLC plays just about anything.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI