This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] All Sorts of Problems

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok so I have McAffee, AVG, and spybot on my computer, I run AVG and Spybot regularly for viruses and spyware. Recently I updated Spybot Search and Destrpy and it came with something called Tea Timer(which I cant seem to find now) which I ran and programs came up which I assumed to be bad so I "fixed them", im not sure if they were deleted or it made it so certain programs cant run or what. Now I contantly get pop ups that say Rundll.exe cant open "blank" memory can not be read, or access is denied click ok to termininare or end process/program or something along those lines. I left my computer on overnight and int he morning there were 273 of these messages. I also have a type of spyware I think called virtumonde which I think is causing me to get system messsages and pop ups, which I get alot when im in my computer or my documents. My computer also runs noticeably slower at times and I have to reatart it and such. Also windows security updates have been turned off and it wont let me turnt hem back on. Now recently explorer.exe has been getting turned off I have no idea what to do and ahve little technical knowledge about computers so any help would be greatly apreciated
Hello and Welcome to the forum.

Looks like you're running 2 anti-virus programs.

Never install more than one Antivirus and Firewall! Rather than giving you extra protection, it will decrease the reliability of it seriously!
The reason for this is that if both products have their automatic (Real-Time) protection switched on, your system may lock up due to both software products attempting to access the same file at the same time.
Also because more than one Antivirus and Firewall installed are not compatible with each other, it can cause system performance problems and a serious system slowdown.

Please do not delete anything unless instructed to.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove either:
McAffee
AVG

After the above:



Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
I just realized that Mcaffee is my firewall and AVG is only virus protection (its the free version), but I also have SpybotS&D which seemed to casue these problmes when i upgraded it and got Tea Timer so do i still need to get rid of one of these?

I just realized that Mcaffee is my firewall and AVG is only virus protection (its the free version), but I also have SpybotS&D which seemed to casue these problmes when i upgraded it and got Tea Timer so do i still need to get rid of one of these?

No. If you're running just 1 AVG and 1 firewall leave them alone.

Do the rest of my suggested fix.
I did everything up to running Hijack this, I save it to my desktop and when I try to open it it asks what program I want to use to open it Also here is everything from malwarebyte Log Malwarebytes' Anti-Malware 1.20 Database version: 962 Windows 5.1.2600 Service Pack 2 3:39:59 PM 7/17/2008 mbam-log-7-17-2008 (15-39-59).txt Scan type: Quick Scan Objects scanned: 86044 Time elapsed: 13 minute(s), 45 second(s) Memory Processes Infected: 0 Memory Modules Infected: 2 Registry Keys Infected: 11 Registry Values Infected: 8 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 30 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\winadg32.dll (Dialer) -> Unloaded module successfully. C:\WINDOWS\system32\ddcAspnm.dll (Trojan.Vundo) -> Unloaded module successfully. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winadg32 (Dialer) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{0e64e841-2463-47c9-8797-daf2810bbf61} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0e64e841-2463-47c9-8797-daf2810bbf61} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcaspnm (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{0e64e841-2463-47c9-8797-daf2810bbf61} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bm5faaa544 (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bm5faaa544 (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\5c9996d8 (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\edrlwsmu.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\umswlrde.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\hlyrompw.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wpmorylh.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\lpkgmgjv.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\vjgmgkpl.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mlxnxsex.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\xesxnxlm.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\muqxwxin.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\nixwxqum.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\newysqkm.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mkqsywen.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\qafwkhxq.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\qxhkwfaq.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\xfeusord.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\drosuefx.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\xfxumemh.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\hmemuxfx.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\winadg32.dll (Dialer) -> Delete on reboot. C:\WINDOWS\system32\ddcAspnm.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\avhyombh.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ayqkmz.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\btdevrmm.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\vpiqur.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\Dustin\Local Settings\Temporary Internet Files\Content.IE5\L6FUMV85\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\system32\imnrpbgj.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\igusxbwg.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\BM5faaa544.xml (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\BM5faaa544.txt (Trojan.Vundo) -> Quarantined and deleted successfully. Ialso havent had any popups or rundll errors since ive done all this, and should I get rid of spybot S&D?
Download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Give it atleast 20-30 minutes to finish
I ran combofix and it logged me out, when i logged back in it said it was doing something with the log and to start any programs, but whneever I log in there are some programs that automaticaly start so im not sure if this effected the results at all

ComboFix 08-07-22.4 - Dustin 2008-07-23 11:58:14.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.184 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Dustin\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Program Files\Common Files\{5C999~1
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aKmUCcdd.ini
C:\WINDOWS\system32\aKmUCcdd.ini2
C:\WINDOWS\system32\anadjtnx.ini
C:\WINDOWS\system32\auwkofqm.dll
C:\WINDOWS\system32\aygwuv.dll
C:\WINDOWS\system32\boqzxl.dll
C:\WINDOWS\system32\bpiodpdc.dll
C:\WINDOWS\system32\cagioc.dll
C:\WINDOWS\system32\cgysmy.dll
C:\WINDOWS\system32\curhingx.ini
C:\WINDOWS\system32\dcLnUBIi.ini
C:\WINDOWS\system32\dcLnUBIi.ini2
C:\WINDOWS\system32\dgQBIkkj.ini
C:\WINDOWS\system32\dgQBIkkj.ini2
C:\WINDOWS\system32\edwhnugq.ini
C:\WINDOWS\system32\eftqyrdx.dll
C:\WINDOWS\system32\ehjwkgwy.ini
C:\WINDOWS\system32\ekgjnrwj.dll
C:\WINDOWS\system32\eNTuCfhk.ini
C:\WINDOWS\system32\eNTuCfhk.ini2
C:\WINDOWS\system32\ENWaGfhk.ini
C:\WINDOWS\system32\ENWaGfhk.ini2
C:\WINDOWS\system32\EOVyJkkj.ini
C:\WINDOWS\system32\EOVyJkkj.ini2
C:\WINDOWS\system32\ezgrti.dll
C:\WINDOWS\system32\fatamaql.ini
C:\WINDOWS\system32\fwxwulvw.dll
C:\WINDOWS\system32\gdfgfosv.ini
C:\WINDOWS\system32\gejlrrjc.dll
C:\WINDOWS\system32\ggutluwh.ini
C:\WINDOWS\system32\gNXFgfii.ini
C:\WINDOWS\system32\gNXFgfii.ini2
C:\WINDOWS\system32\GPXGgfii.ini
C:\WINDOWS\system32\GPXGgfii.ini2
C:\WINDOWS\system32\grgfjngy.ini
C:\WINDOWS\system32\hkQAcfii.ini
C:\WINDOWS\system32\hkQAcfii.ini2
C:\WINDOWS\system32\hOVEOqss.ini
C:\WINDOWS\system32\hOVEOqss.ini2
C:\WINDOWS\system32\ieftntvt.ini
C:\WINDOWS\system32\IjTsrBeg.ini
C:\WINDOWS\system32\IjTsrBeg.ini2
C:\WINDOWS\system32\iktjttmy.dll
C:\WINDOWS\system32\imqizh.dll
C:\WINDOWS\system32\indsttef.ini
C:\WINDOWS\system32\inepblph.ini
C:\WINDOWS\system32\inpikkup.ini
C:\WINDOWS\system32\itfsynhh.ini
C:\WINDOWS\system32\iwtrxnlp.ini
C:\WINDOWS\system32\jcnechgc.ini
C:\WINDOWS\system32\JlkUxyxx.ini
C:\WINDOWS\system32\JlkUxyxx.ini2
C:\WINDOWS\system32\jowcahye.dll
C:\WINDOWS\system32\jridhnco.dll
C:\WINDOWS\system32\kuiufn.dll
C:\WINDOWS\system32\kujigxag.ini
C:\WINDOWS\system32\lcptrcjb.ini
C:\WINDOWS\system32\lvhrkora.dll
C:\WINDOWS\system32\maiaysra.ini
C:\WINDOWS\system32\malbmdlc.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mdopmw.dll
C:\WINDOWS\system32\mppVDcfe.ini
C:\WINDOWS\system32\mppVDcfe.ini2
C:\WINDOWS\system32\muxuty.dll
C:\WINDOWS\system32\mxaqpb.dll
C:\WINDOWS\system32\nkclgo.dll
C:\WINDOWS\system32\nkeevsig.ini
C:\WINDOWS\system32\nppYJRqr.ini
C:\WINDOWS\system32\nppYJRqr.ini2
C:\WINDOWS\system32\nxggivqa.ini
C:\WINDOWS\system32\oieyugxl.ini
C:\WINDOWS\system32\olitro.dll
C:\WINDOWS\system32\opWaccfe.ini
C:\WINDOWS\system32\opWaccfe.ini2
C:\WINDOWS\system32\otsamjcr.dll
C:\WINDOWS\system32\ouaqttvn.dll
C:\WINDOWS\system32\oxbpgz.dll
C:\WINDOWS\system32\oXHNmUtv.ini
C:\WINDOWS\system32\oXHNmUtv.ini2
C:\WINDOWS\system32\pbtoochh.dll
C:\WINDOWS\system32\psfhqg.dll
C:\WINDOWS\system32\pvcwyvim.dll
C:\WINDOWS\system32\PVFeefii.ini
C:\WINDOWS\system32\PVFeefii.ini2
C:\WINDOWS\system32\qbktaaqr.ini
C:\WINDOWS\system32\qkgoccfu.ini
C:\WINDOWS\system32\qnbqyxai.ini
C:\WINDOWS\system32\qzzlat.dll
C:\WINDOWS\system32\ranptbwm.ini
C:\WINDOWS\system32\rbxohq.dll
C:\WINDOWS\system32\rkbecieg.ini
C:\WINDOWS\system32\spibfoxu.dll
C:\WINDOWS\system32\sxpesh.dll
C:\WINDOWS\system32\tAdeNXbc.ini
C:\WINDOWS\system32\tAdeNXbc.ini2
C:\WINDOWS\system32\tdmrvhuu.ini
C:\WINDOWS\system32\tfxohjee.dll
C:\WINDOWS\system32\uaxomimj.ini
C:\WINDOWS\system32\ubaeqnsh.dll
C:\WINDOWS\system32\unqgvhxt.dll
C:\WINDOWS\system32\uodehjqp.dll
C:\WINDOWS\system32\uvrereqg.ini
C:\WINDOWS\system32\uxGjQqru.ini
C:\WINDOWS\system32\uxGjQqru.ini2
C:\WINDOWS\system32\viiwkunn.ini
C:\WINDOWS\system32\vpksaufr.dll
C:\WINDOWS\system32\vulhfrmp.dll
C:\WINDOWS\system32\wesqfpkb.ini
C:\WINDOWS\system32\WHPpAJlm.ini
C:\WINDOWS\system32\WHPpAJlm.ini2
C:\WINDOWS\system32\wiakbowx.dll
C:\WINDOWS\system32\wmoatjme.dll
C:\WINDOWS\system32\wvvieqnw.ini
C:\WINDOWS\system32\XaIjTvut.ini
C:\WINDOWS\system32\XaIjTvut.ini2
C:\WINDOWS\system32\xgeiwg.dll
C:\WINDOWS\system32\xjnidtva.ini
C:\WINDOWS\system32\yaaacMoq.ini
C:\WINDOWS\system32\yaaacMoq.ini2
C:\WINDOWS\system32\yeoune.dll
C:\WINDOWS\system32\yIkjPqss.ini
C:\WINDOWS\system32\yIkjPqss.ini2
C:\WINDOWS\system32\yjlhwmod.dll
C:\WINDOWS\system32\yjpixd.dll
C:\WINDOWS\system32\yrotiu.dll
C:\WINDOWS\system32\yyqdnyfn.ini

.
((((((((((((((((((((((((( Files Created from 2008-06-23 to 2008-07-23 )))))))))))))))))))))))))))))))
.

2100-02-16 15:09 . 2001-02-16 14:37 62 –a—— C:\WINDOWS\system32\LXBOUSCI.INI
2008-07-17 14:58 . 2008-07-17 14:58 d——– C:\Malwarebytes' Anti-Malware
2008-07-17 14:58 . 2008-07-17 14:58 d——– C:\Documents and Settings\Dustin\Application Data\Malwarebytes
2008-07-17 14:58 . 2008-07-17 14:58 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-17 14:58 . 2008-07-07 17:35 34,296 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-17 14:58 . 2008-07-07 17:35 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-07-16 19:26 . 2008-07-16 19:26 d——– C:\Program Files\Common Files\Adobe AIR
2008-07-16 19:26 . 2008-07-16 19:26 d——– C:\Program Files\Adobe Media Player
2008-07-10 21:14 . 2008-07-10 21:14 d——– C:\Program Files\iTunes
2008-07-10 21:14 . 2008-07-10 21:14 d——– C:\Program Files\iPod
2008-07-10 21:09 . 2008-07-10 21:09 d——– C:\Program Files\Bonjour
2008-06-29 22:37 . 2008-06-29 22:37 d——– C:\Documents and Settings\Dustin\Application Data\Uniblue
2008-06-29 21:34 . 2008-07-09 23:27 152 –a—— C:\WINDOWS\wininit.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-23 17:06 ——— d—–w C:\Documents and Settings\Dustin\Application Data\DNA
2008-07-23 16:44 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-07-22 08:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-07-21 04:59 ——— d—–w C:\Documents and Settings\Dustin\Application Data\BitTorrent
2008-07-20 23:00 ——— d—–w C:\Program Files\Norton Security Scan
2008-07-11 02:07 ——— d—–w C:\Program Files\QuickTime
2008-07-09 23:31 ——— d—–w C:\Documents and Settings\Dustin\Application Data\AVG7
2008-07-09 19:06 ——— d—–w C:\Program Files\Safari
2008-07-09 19:04 ——— d—–w C:\Program Files\Apple Software Update
2008-07-03 01:07 ——— d—–w C:\Program Files\McAfee
2008-06-30 15:31 ——— d—–w C:\Program Files\Google
2008-06-29 17:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-29 17:30 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-06-13 13:10 272,128 —-a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-07-11 21:10 88,576 —ha-w C:\Documents and Settings\Dustin\Application Data\rbap550.dll
2007-07-11 21:10 74,240 —ha-w C:\Documents and Settings\Dustin\Application Data\rbqt550.DLL
2007-07-11 21:10 59,392 —ha-w C:\Documents and Settings\Dustin\Application Data\MBSQTImporterPlugin8680.dll
2007-07-11 21:10 48,640 —ha-w C:\Documents and Settings\Dustin\Application Data\eSelleratePlugin.DLL
2007-07-11 21:10 44,032 —ha-w C:\Documents and Settings\Dustin\Application Data\MBSMainPlugin8841.dll
2007-07-11 21:10 38,912 —ha-w C:\Documents and Settings\Dustin\Application Data\RBShell550.dll
2007-07-11 21:10 35,840 —ha-w C:\Documents and Settings\Dustin\Application Data\MBSFolderitemsPlugin8606.dll
2007-07-11 21:10 29,184 —ha-w C:\Documents and Settings\Dustin\Application Data\RBInternetEncodings550.dll
2007-07-11 21:10 27,136 —ha-w C:\Documents and Settings\Dustin\Application Data\MBSMacTTPlugin8835.dll
2007-07-11 21:10 26,624 —ha-w C:\Documents and Settings\Dustin\Application Data\MBSRegistrationPlugin8816.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-07 14:08 4670968]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 10:29 50736]
"AIM"="C:\Program Files\AIM\aim.exe" [2005-08-05 15:08 67160]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 11:37 2321600]
"Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2008-01-07 15:02 495616]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-08 14:42 289088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="C:\Program Files\Common Files\AOL\1150774939\ee\AOLSoftware.exe" [2006-04-20 12:10 50792]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 11:59 124520]
"Lexmark X84-X85 Button Monitor"="C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe" [2002-08-01 13:20 40960]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2002-09-18 22:52 36864]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 16:07 49263]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 09:59 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-19 09:59 126976]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-04-19 23:08 579584]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-04 02:33 582992]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-25 11:52 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
CreataCard Gold 3 Forget Me Not Reminders Tray Icon.lnk - C:\Program Files\CreataCard\Gold\FMRemind.exe [2006-07-11 16:58:32 189952]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 09:05:56 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Time]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\1150774939\\ee\\aolservicehost.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 16:38]
R2 W32Time;Windows Time;C:\WINDOWS\System32\svchost.exe [2004-08-04 07:00]
S2 epssuiejyeiwo5o;Print Spooler Service;C:\WINDOWS\system32\psmvc.exe []
S2 HODSrv;HID Output Service;C:\WINDOWS\system32\hpsvc.exe []
S2 Time;Time Service;C:\WINDOWS\system32\nlkfev7xejlnprtw.exe []
S3 WTime;WTime;C:\WINDOWS\system32\timedrv26.sys []
.
Contents of the 'Scheduled Tasks' folder
"2008-07-18 01:27:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-07-15 06:00:00 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-06-01 06:00:00 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-07-20 23:49:28 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
- - - - ORPHANS REMOVED - - - -

BHO-{0F19FFC4-34A2-4D93-874A-9D0F5DB7463F} - C:\WINDOWS\system32\khfCuTNe.dll
BHO-{2503BAE3-FA6C-4AA0-B95B-C75D57FDA38D} - C:\WINDOWS\system32\ssqPjkIy.dll
BHO-{2A0F4177-C452-47BF-BFDE-FE90D1E9C746} - C:\WINDOWS\system32\cbXNedAt.dll
BHO-{330B8778-108D-41DD-B12F-13621E0019F1} - C:\WINDOWS\system32\tuvTjIaX.dll
BHO-{3AE7231F-038F-42C5-99E4-26B19DE806B3} - C:\WINDOWS\system32\iifgGXPG.dll
BHO-{466A68BB-25DE-41F9-91A9-75C1E136E8A0} - C:\WINDOWS\system32\ddcCUmKa.dll
BHO-{91EC679B-71E3-40DE-BDBF-E5535342ABA0} - C:\WINDOWS\system32\iIBUnLcd.dll
BHO-{B51E4C55-734F-4E92-8895-A056DE0C6E14} - C:\WINDOWS\system32\atmf.dll
BHO-{B5621E81-2BB9-4602-92AE-C03642E45771} - C:\WINDOWS\system32\qoMcaaay.dll
BHO-{E61BF5A5-0687-4440-86BD-3E113090ACC2} - C:\WINDOWS\system32\iifgFXNg.dll
BHO-{E6449CBB-6081-4000-B281-D734B9235838} - C:\WINDOWS\system32\atmf.dll
BHO-{F5FE6D77-6A81-4080-954A-E1A96A5DB99A} - C:\WINDOWS\system32\vtUmNHXo.dll
BHO-{FA22BD03-2B28-4194-AB35-CB3202641372} - C:\WINDOWS\system32\iifeeFVP.dll
HKCU-Run-Uniblue RegistryBooster 2 - C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
HKU-Default-Explorer_Run-{5C999677-0702-1033-0826-020409200001} - C:\Program Files\Common Files\{5C999677-0702-1033-0826-020409200001}\Update.exe


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://www.aol.com/
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O8 -: &Search - ?p=ZJ


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-23 13:01:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2008-07-23 13:08:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-23 18:08:29

Pre-Run: 7,629,082,624 bytes free

Post-Run: 9,647,452,160 bytes free

309 — E O F — 2008-07-20 22:39:14

I also still can not run hijack this, it asks me what program I want to open it with
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\psmvc.exe
C:\WINDOWS\system32\nlkfev7xejlnprtw.exe
C:\WINDOWS\system32\hpsvc.exe
C:\WINDOWS\system32\timedrv26.sys

Folder::
C:\Program Files\Bonjour
C:\Program Files\Viewpoint


Save this as CFScript.txt


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.

If you still can't use HijackThis:

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
THis is my new combofix log

ComboFix 08-07-22.4 - Dustin 2008-07-28 12:16:04.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.188 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Dustin\Desktop\cfscript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\hpsvc.exe
C:\WINDOWS\system32\nlkfev7xejlnprtw.exe
C:\WINDOWS\system32\psmvc.exe
C:\WINDOWS\system32\timedrv26.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Bonjour
C:\Program Files\Bonjour\About Bonjour.rtf
C:\Program Files\Bonjour\mdnsNSP.dll
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Viewpoint
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Common\VistaBoot.sdll
C:\Program Files\Viewpoint\Viewpoint Manager\CPtask.xml
C:\Program Files\Viewpoint\Viewpoint Manager\VETScriptInterpreter.dll
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCP.cpl
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\s.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_av.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_cp.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_up.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bg.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bottom.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab_bg.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_off.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_on.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_off.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_on.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vwpt_logo.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\options.ini
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\viewpoint.ico
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPexe.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgrCore.dll
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream_.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream_0302021C.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream_0305000D.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\ClassIDs.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\ComponentMgr_0305000D.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\ComponentRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\AOLUserShell.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\Cursors.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\JpegReader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\Mts3Reader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SceneComponent.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SreeDMMX.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SWFView.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMgr.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPSpeech.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPVideo.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPVideo2.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\WaveletReader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\DownLoadHist.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\HostRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MetaStreamConfig.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
C:\Program Files\Viewpoint\Viewpoint Media Player\MTSDownloadSites.txt

.
((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-28 )))))))))))))))))))))))))))))))
.

2100-02-16 15:09 . 2001-02-16 14:37 62 –a—— C:\WINDOWS\system32\LXBOUSCI.INI
2008-07-17 14:58 . 2008-07-17 14:58 d——– C:\Malwarebytes' Anti-Malware
2008-07-17 14:58 . 2008-07-17 14:58 d——– C:\Documents and Settings\Dustin\Application Data\Malwarebytes
2008-07-17 14:58 . 2008-07-17 14:58 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-17 14:58 . 2008-07-07 17:35 34,296 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-17 14:58 . 2008-07-07 17:35 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-07-16 19:26 . 2008-07-16 19:26 d——– C:\Program Files\Common Files\Adobe AIR
2008-07-16 19:26 . 2008-07-16 19:26 d——– C:\Program Files\Adobe Media Player
2008-07-10 21:14 . 2008-07-10 21:14 d——– C:\Program Files\iTunes
2008-07-10 21:14 . 2008-07-10 21:14 d——– C:\Program Files\iPod
2008-06-29 22:37 . 2008-06-29 22:37 d——– C:\Documents and Settings\Dustin\Application Data\Uniblue
2008-06-29 21:34 . 2008-07-09 23:27 152 –a—— C:\WINDOWS\wininit.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-28 17:19 ——— d—–w C:\Documents and Settings\Dustin\Application Data\DNA
2008-07-27 23:00 ——— d—–w C:\Program Files\Norton Security Scan
2008-07-27 08:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-07-25 07:01 ——— d—–w C:\Documents and Settings\Dustin\Application Data\BitTorrent
2008-07-23 16:44 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-07-11 02:07 ——— d—–w C:\Program Files\QuickTime
2008-07-09 23:31 ——— d—–w C:\Documents and Settings\Dustin\Application Data\AVG7
2008-07-09 19:06 ——— d—–w C:\Program Files\Safari
2008-07-09 19:04 ——— d—–w C:\Program Files\Apple Software Update
2008-07-03 01:07 ——— d—–w C:\Program Files\McAfee
2008-06-30 15:31 ——— d—–w C:\Program Files\Google
2008-06-29 17:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-29 17:30 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10 272,128 —-a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
.

((((((((((((((((((((((((((((( snapshot@2008-07-23_13.08.05.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-08-16 12:08:32 100,352 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\6to4svc.dll
+ 2008-06-20 10:44:08 138,368 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\afd.sys
+ 2008-06-20 17:36:11 147,968 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\dnsapi.dll
+ 2008-06-20 17:36:11 245,248 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\mswsock.dll
+ 2008-06-20 10:44:42 360,960 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
+ 2008-06-20 09:32:39 225,920 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip6.sys
+ 2008-06-20 11:40:08 138,496 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\afd.sys
+ 2008-06-20 17:46:57 147,968 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\dnsapi.dll
+ 2008-06-20 17:46:57 245,248 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\mswsock.dll
+ 2008-06-20 11:51:12 361,600 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
+ 2008-06-20 11:08:27 225,856 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip6.sys
+ 2008-06-20 11:48:03 138,496 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\afd.sys
+ 2008-06-20 17:43:05 147,968 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\dnsapi.dll
+ 2008-06-20 17:43:05 245,248 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\mswsock.dll
+ 2008-06-20 11:59:02 361,600 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
+ 2008-06-20 11:16:44 225,856 —-a-w C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip6.sys
+ 2007-11-30 12:39:22 17,272 —-a-w C:\WINDOWS\$hf_mig$\KB951748\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w C:\WINDOWS\$hf_mig$\KB951748\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w C:\WINDOWS\$hf_mig$\KB951748\update\spcustom.dll
+ 2007-11-30 12:39:18 755,576 —-a-w C:\WINDOWS\$hf_mig$\KB951748\update\update.exe
+ 2007-11-30 12:39:19 382,840 —-a-w C:\WINDOWS\$hf_mig$\KB951748\update\updspapi.dll
- 2008-07-23 16:50:16 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-07-28 16:22:39 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-07-23 16:50:16 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-07-28 16:22:39 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-07-23 16:50:16 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-07-28 16:22:39 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-08-04 12:00:00 138,496 -c–a-w C:\WINDOWS\system32\dllcache\afd.sys
+ 2008-06-20 10:44:38 138,368 -c–a-w C:\WINDOWS\system32\dllcache\afd.sys
- 2008-02-20 05:32:43 148,992 -c–a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
+ 2008-06-20 17:41:10 148,992 -c–a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
- 2004-08-04 12:00:00 245,248 -c–a-w C:\WINDOWS\system32\dllcache\mswsock.dll
+ 2008-06-20 17:41:10 245,248 -c–a-w C:\WINDOWS\system32\dllcache\mswsock.dll
- 2007-10-30 17:20:55 360,064 -c–a-w C:\WINDOWS\system32\dllcache\tcpip.sys
+ 2008-06-20 10:45:13 360,320 -c–a-w C:\WINDOWS\system32\dllcache\tcpip.sys
- 2006-08-16 09:37:30 225,664 -c–a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
+ 2008-06-20 09:52:06 225,920 -c–a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
- 2008-02-20 05:32:43 148,992 —-a-w C:\WINDOWS\system32\dnsapi.dll
+ 2008-06-20 17:41:10 148,992 —-a-w C:\WINDOWS\system32\dnsapi.dll
- 2007-11-30 11:18:51 17,272 —-a-w C:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 12:39:22 17,272 ——w C:\WINDOWS\system32\spmsg.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-07 14:08 4670968]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 10:29 50736]
"AIM"="C:\Program Files\AIM\aim.exe" [2005-08-05 15:08 67160]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 11:37 2321600]
"Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2008-01-07 15:02 495616]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-08 14:42 289088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="C:\Program Files\Common Files\AOL\1150774939\ee\AOLSoftware.exe" [2006-04-20 12:10 50792]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 11:59 124520]
"Lexmark X84-X85 Button Monitor"="C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe" [2002-08-01 13:20 40960]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2002-09-18 22:52 36864]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 16:07 49263]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 09:59 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-19 09:59 126976]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-04-19 23:08 579584]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-04 02:33 582992]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-25 11:52 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
CreataCard Gold 3 Forget Me Not Reminders Tray Icon.lnk - C:\Program Files\CreataCard\Gold\FMRemind.exe [2006-07-11 16:58:32 189952]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 09:05:56 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Time]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\1150774939\\ee\\aolservicehost.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=

R2 W32Time;Windows Time;C:\WINDOWS\System32\svchost.exe [2004-08-04 07:00]
S2 epssuiejyeiwo5o;Print Spooler Service;C:\WINDOWS\system32\psmvc.exe []
S2 HODSrv;HID Output Service;C:\WINDOWS\system32\hpsvc.exe []
S2 Time;Time Service;C:\WINDOWS\system32\nlkfev7xejlnprtw.exe []
S2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe []
S3 WTime;WTime;C:\WINDOWS\system32\timedrv26.sys []
.
Contents of the 'Scheduled Tasks' folder
"2008-07-25 01:27:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-07-15 06:00:00 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-06-01 06:00:00 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-07-27 23:00:24 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-28 12:22:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2008-07-28 12:29:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-28 17:29:05
ComboFix2.txt 2008-07-23 18:08:38

Pre-Run: 8,864,690,176 bytes free
Post-Run: 9,061,244,928 bytes free

250 — E O F — 2008-07-25 05:18:01




and the reason hijack this wasnt working is because ther was no .exe at the end of the set up program so I just added it myself, here is the log

Logfile of HijackThis v1.99.1
Scan saved at 2:02:31 PM, on 7/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\AOL\1150774939\ee\AOLSoftware.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\CreataCard\Gold\FMRemind.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AIM\aim.exe
C:\Hijackthis\HijackThis.exe
c:\program files\common files\aol\1150774939\ee\aexplore.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…ER}&ar=home
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1150774939\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Lexmark X84-X85 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - Global Startup: CreataCard Gold 3 Forget Me Not Reminders Tray Icon.lnk = C:\Program Files\CreataCard\Gold\FMRemind.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O8 - Extra context menu item: &Search - ?p=ZJ
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Print Spooler Service (epssuiejyeiwo5o) - Unknown owner - C:\WINDOWS\system32\psmvc.exe (file missing)
O23 - Service: HID Output Service (HODSrv) - Unknown owner - C:\WINDOWS\system32\hpsvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Time Service (Time) - Unknown owner - C:\WINDOWS\system32\nlkfev7xejlnprtw.exe (file missing)
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)
Are you also running the McAfee anti-virus?



We have noticed that most people seeking help from us are coming with infections contracted from the use of P2P programs.

Because of this, we felt we needed to change our policy on the use of P2P file sharing programs.

You have the following P-2-P program(s) installed
BitTorrent

This is how you uninstall it/them:

  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for the following (if present):

  • BitTorrent


    After the above:

    Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
    O4 - Global Startup: CreataCard Gold 3 Forget Me Not Reminders Tray Icon.lnk = C:\Program Files\CreataCard\Gold\FMRemind.exe
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
    O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
    O23 - Service: Print Spooler Service (epssuiejyeiwo5o) - Unknown owner - C:\WINDOWS\system32\psmvc.exe (file missing)
    O23 - Service: Time Service (Time) - Unknown owner - C:\WINDOWS\system32\nlkfev7xejlnprtw.exe (file missing)
    O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)

    Close ALL windows and browsers except HijackThis and click "Fix checked"



    Reboot and "copy/paste" a new HijackThis log file into this thread.

    Also please describe how your computer behaves at the moment.
I did what you said but no log popped out after my coputer restarted, and Adobe flash player hasnt been working good, when I try to watch videos it either doesnt load at all or will only go a little bit and then stop and if i try to go further into the video it only buffers a few econds and stops ot doesnt buffer at all

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI