This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Hijacked with Numersous popups

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Cannot find where any of this is coming from. Everything is up to date in my system.
Here is my HiJack Log:

Logfile of HijackThis v1.99.1
Scan saved at 9:36:13 PM, on 8/5/08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
H:\Program Files\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\UPSMON\UPSMON_Service.Exe
C:\Program Files\UPSMON\UPSInt2.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\WINDOWS\system32\Ati2evxx.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragMonitorService.exe
C:\WINDOWS\Explorer.EXE
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\Program Files\a-squared Anti-Malware\a2guard.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\MSGTAG Status\MSGTAGStatus.exe
C:\Program Files\RealPopup\RealPopup.exe
C:\WINDOWS\system32\ctfmon.exe
H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\Documents and Settings\Carey Mumford.KEYGOLF\Desktop\Unused Desktop Shortcuts\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80
O1 - Hosts: HP001F297584D1 HP001F297584D1
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\PROGRA~1\TEXTAL~1\TAForIE.dll
O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DefragTaskBar] "H:\Program Files\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKCU\..\Run: [MSGTAG] "C:\Program Files\MSGTAG Status\MSGTAGStatus.exe" /startup
O4 - HKCU\..\Run: [RealPopup] "C:\Program Files\RealPopup\RealPopup.exe" BOOT
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Search - ?p=ZUfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support2.charter.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://38.114.50.171/activex/AMC.cab
O20 - Winlogon Notify: urqNDwxw - urqNDwxw.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - H:\Program Files\aawservice.exe
O23 - Service: Ashampoo Defrag Service (AshampooDefragService) - - H:\Program Files\Ashampoo Magical Defrag 2\bin\aDefragService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: UPSMONService - Unknown owner - C:\Program Files\UPSMON\UPSMON_Service.Exe
Thanx shelf life. In fact I got interruptedLogfile of HijackThis v1.99.1
Scan saved at 5:05:01 PM, on 8/7/08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
H:\Program Files\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\UPSMON\UPSMON_Service.Exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\UPSMON\UPSInt2.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\a-squared Anti-Malware\a2guard.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\MSGTAG Status\MSGTAGStatus.exe
C:\Program Files\RealPopup\RealPopup.exe
C:\WINDOWS\system32\ctfmon.exe
H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Carey Mumford.KEYGOLF\Desktop\Unused Desktop Shortcuts\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80
O1 - Hosts: HP001F297584D1 HP001F297584D1
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\PROGRA~1\TEXTAL~1\TAForIE.dll
O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DefragTaskBar] "H:\Program Files\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKCU\..\Run: [MSGTAG] "C:\Program Files\MSGTAG Status\MSGTAGStatus.exe" /startup
O4 - HKCU\..\Run: [RealPopup] "C:\Program Files\RealPopup\RealPopup.exe" BOOT
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Search - ?p=ZUfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support2.charter.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://38.114.50.171/activex/AMC.cab
O20 - Winlogon Notify: urqNDwxw - urqNDwxw.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - H:\Program Files\aawservice.exe
O23 - Service: Ashampoo Defrag Service (AshampooDefragService) - - H:\Program Files\Ashampoo Magical Defrag 2\bin\aDefragService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: UPSMONService - Unknown owner - C:\Program Files\UPSMON\UPSMON_Service.Exe

by one trying to do this: New Log:
hi,

not much in the log to go on. we will start with malwarebytes and go from there, post the log it generates. link and directions:

Please download Malwarebytes' Anti-Malware to your desktop:

http://www.besttechie.net/tools/mbam-setup.exe

* Double-click mbam-setup.exe and follow the prompts to install the program.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform FULL SCAN, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Thanx again, shelf life. Here's the log, though still have one continuing popup. Don't know about others yet. Malwarebytes' Anti-Malware 1.24 Database version: 1031 Windows 5.1.2600 Service Pack 2 1:43:02 AM 8/8/08 mbam-log-8-8-2008 (01-43-02).txt Scan type: Full Scan (C:\|F:\|G:\|H:\|I:\|K:\|) Objects scanned: 1114578 Time elapsed: 3 hour(s), 15 minute(s), 1 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 20 Registry Values Infected: 2 Registry Data Items Infected: 0 Folders Infected: 6 Files Infected: 8 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR (Trojan.DNSChanger) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{a6c54318-5ac7-477d-b0a7-49af5189300c} (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\WINDOWS\system32\pnVes01 (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\hn3 (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\pb1 (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system\sounds (Backdoor.Bot) -> Quarantined and deleted successfully. C:\WINDOWS\system\logs (Backdoor.Bot) -> Quarantined and deleted successfully. C:\WINDOWS\system\download (Backdoor.Bot) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\drivers\emStreamm.sys (Rootkit.Agent) -> Delete on reboot. K:\KeyGolf BckUp\Drive_C_BkUp\Documents and Settings\Carey Mumford.KEYGOLF\Local Settings\Temp\ginstall.dll (Adware.WebHancer) -> Quarantined and deleted successfully. C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\BMbba093df.xml (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\BMbba093df.txt (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\drivers\core.cache.dsk (Rootkit.Agent) -> Delete on reboot.
hi keygolf,

ok good so far. we will get one more download to use. only runs in safe mode. link and directions:

Download SDFix and save it to your Desktop.

http://downloads.andymanchesta.com/RemovalTools/SDFix.exe


Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, the Advanced Options Menu should appear;
* Select the first option, to run Windows in Safe Mode, then press Enter.
* Choose your usual account.

* Open the extracted SDFix folder and double click RunThis.bat to start the script.
* Type Y to begin the cleanup process.
* It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
* Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
* Finally paste the contents of the Report.txt back in your reply
Here's the latest, though I got the same popup as I was trying to enter this info.

SDFix: Version 1.214
Run by [removed] on Sat 08/09/08 at 08:45 AM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\Temp\1cb\syscheck.log - Deleted
C:\WINDOWS\system32\drivers\core.cache(2).dsk - Deleted
C:\WINDOWS\system32\drivers\core.cache(3).dsk - Deleted
C:\WINDOWS\system32\drivers\core.cache(4).dsk - Deleted
C:\WINDOWS\system32\drivers\core.cache(5).dsk - Deleted


Could Not Remove C:\WINDOWS\system32\drivers\core.cache.dsk

Folder C:\Temp\1cb - Removed
Folder C:\Temp\tn3 - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-09 08:53:47
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\GIANT Company Software\\Spam Inspector\\siMailProxyServer.exe"="C:\\Program Files\\GIANT Company Software\\Spam Inspector\\siMailProxyServer.exe:*:Enabled:siMailProxyServer"
"C:\\Program Files\\FTP Commander\\Ftpcomm.exe"="C:\\Program Files\\FTP Commander\\Ftpcomm.exe:*:Enabled:Ftpcomm"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Disabled:Windows Messenger"
"C:\\Program Files\\Common Files\\Desktop Weather Authority\\TrueWeather.exe"="C:\\Program Files\\Common Files\\Desktop Weather Authority\\TrueWeather.exe:*:Enabled:TrueWeather"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\WINDOWS\\system\\svchost.exe"="C:\\WINDOWS\\system\\svchost.exe:*:Disabled:mIRC"
"C:\\Program Files\\Resounding\\Roger Wilco\\roger.exe"="C:\\Program Files\\Resounding\\Roger Wilco\\roger.exe:*:Enabled:roger"
"C:\\Program Files\\MSGTAG\\MSGTAG.exe"="C:\\Program Files\\MSGTAG\\MSGTAG.exe:*:Enabled:MSGTAG"
"C:\\Program Files\\Sygate\\SHN\\SyGate.exe"="C:\\Program Files\\Sygate\\SHN\\SyGate.exe:*:Disabled:Sygate - Internet Sharing Software"
"C:\\Program Files\\Hewlett-Packard\\HP Install Network Printer Wizard\\hpjsi.exe"="C:\\Program Files\\Hewlett-Packard\\HP Install Network Printer Wizard\\hpjsi.exe:*:Enabled:HP Jetdirect Wireless Setup Wizard"
"C:\\Program Files\\Text-To-Audio\\TexttoAudio.exe"="C:\\Program Files\\Text-To-Audio\\TexttoAudio.exe:*:Enabled:TexttoAudio"
"C:\\Program Files\\Cepstral\\bin\\swifttalker.exe"="C:\\Program Files\\Cepstral\\bin\\swifttalker.exe:*:Enabled:swifttalker WCE"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Cobian Backup 7\\cobui.exe"="C:\\Program Files\\Cobian Backup 7\\cobui.exe:*:Enabled:Cobian Backup 7 Interface"
"C:\\Program Files\\Cobian Backup 7\\CobBU.exe"="C:\\Program Files\\Cobian Backup 7\\CobBU.exe:*:Enabled:Cobian Backup 7 Application"
"C:\\Documents and Settings\\Carey Mumford.KEYGOLF\\Local Settings\\Temp\\Temporary Directory 1 for static-website.zip\\website.exe"="C:\\Documents and Settings\\Carey Mumford.KEYGOLF\\Local Settings\\Temp\\Temporary Directory 1 for static-website.zip\\website.exe:*:Enabled:website"
"C:\\Documents and Settings\\Carey Mumford.KEYGOLF\\Local Settings\\Temp\\Temporary Directory 2 for static-website.zip\\website.exe"="C:\\Documents and Settings\\Carey Mumford.KEYGOLF\\Local Settings\\Temp\\Temporary Directory 2 for static-website.zip\\website.exe:*:Enabled:website"
"C:\\Documents and Settings\\Carey Mumford.KEYGOLF\\Desktop\\CDBK.exe"="C:\\Documents and Settings\\Carey Mumford.KEYGOLF\\Desktop\\CDBK.exe:*:Enabled:CDBK"
"C:\\Program Files\\im4cam Enterprise\\im4cam.exe"="C:\\Program Files\\im4cam Enterprise\\im4cam.exe:*:Enabled:im4cam"
"C:\\Program Files\\TopNet Solutions\\V2F\\V2Swf.exe"="C:\\Program Files\\TopNet Solutions\\V2F\\V2Swf.exe:*:Enabled:V2F"
"C:\\Program Files\\PTDD Group\\PTDD Partition Table Doctor 3.5 Demo\\PtdWin.exe"="C:\\Program Files\\PTDD Group\\PTDD Partition Table Doctor 3.5 Demo\\PtdWin.exe:*:Enabled:Partition Table Doctor 3.5 Demo"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Mozilla Firefox\\FIREFOX.EXE"="C:\\Program Files\\Mozilla Firefox\\FIREFOX.EXE:*:Enabled:Firefox"
"H:\\Program Files\\GoFTP\\GoFTP.exe"="H:\\Program Files\\GoFTP\\GoFTP.exe:*:Enabled:GoFTP"
"C:\\WINDOWS\\System32\\mmc.exe"="C:\\WINDOWS\\System32\\mmc.exe:*:Enabled:Microsoft Management Console"
"E:\\setup\\HPZNET01.EXE"="E:\\setup\\HPZNET01.EXE:*:Enabled:hpznet01.exe"
"E:\\setup\\HPONICIFS01.EXE"="E:\\setup\\HPONICIFS01.EXE:*:Enabled:hponicifs01.exe"
"C:\\WINDOWS\\System32\\SPOOLSV.EXE"="C:\\WINDOWS\\System32\\SPOOLSV.EXE:*:Enabled:Spooler SubSystem App"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqtra08.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqste08.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpofxm08.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hposfx08.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hposid01.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqscnvw.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqkygrp.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqCopy.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpfccopy.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpzwiz01.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpoews01.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqnrs08.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :

C:\WINDOWS\system32\drivers\core.cache.dsk Found

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Mon 22 Jan 2007 4,263 ..SH. — "C:\WINDOWS\windllreg1c.sys"
Wed 22 Jun 2005 45,568 A.SHR — "C:\Program Files\Replay AV 8\cygz.dll"
Mon 23 Jun 2008 27,136 …H. — "C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\Microsoft\Templates\~WRL2647.tmp"
Sun 8 Jun 2008 132,608 …H. — "C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\Microsoft\Word\~WRL1097.tmp"
Sat 12 Jul 2008 27,648 …H. — "C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\Microsoft\Word\~WRL0417.tmp"
Wed 14 Aug 2002 48,491 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Xircom RE10BT\Ce3ndis.exe"
Wed 14 Aug 2002 50,175 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Xircom Re-100Btx + Ce3B-100Btx\Ce3ndis.exe"
Wed 14 Aug 2002 50,405 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Xircom RE10 - RE100 Packet\Ce3pd.com"
Wed 14 Aug 2002 33,860 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Xircom PE3-10Bx\Pe3ndis.exe"
Wed 14 Aug 2002 49,015 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Xircom Ethernet II PS Packet\Xpspd.com"
Wed 14 Aug 2002 48,641 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Xircom Ethernet II PS\Xpsndis.exe"
Wed 14 Aug 2002 52,225 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Xircom Ethernet 10-100 + Modem\Cbendis.exe"
Wed 14 Aug 2002 48,223 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Xircom CBE10-100BTX Packet\Cbepd.com"
Wed 14 Aug 2002 50,795 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Xircom CBE10-100BTX\Cbendis.exe"
Wed 14 Aug 2002 32,484 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\WaveLAN Packet\Wvlan42.com"
Wed 14 Aug 2002 9,537 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\SN 2000p Packet\PNPPD.COM"
Wed 14 Aug 2002 9,692 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\PXE Packet Driver\Undipd.com"
Wed 14 Aug 2002 56,896 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\Rtspkt.com"
Wed 14 Aug 2002 44,640 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\FETPKT.COM"
Wed 14 Aug 2002 44,640 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Planex FNW9x00T - ENW8300T Packet\fetpkt.com"
Wed 14 Aug 2002 12,567 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Melco LPC2-T\Lpchkat2.com"
Wed 14 Aug 2002 9,190 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Laneed LD-PCI2TL Packet\Ldpcil.com"
Wed 14 Aug 2002 13,360 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Laneed LD-CDF Packet\Ldcdt.com"
Wed 14 Aug 2002 48,224 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Laneed LD 10-100AL Packet\L100al.com"
Wed 14 Aug 2002 18,300 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\Kingston EtheRx KNE110TX Packet\Ktc110p.com"
Wed 14 Aug 2002 11,786 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\IBM Crystal LAN Packet\Epktisa.com"
Wed 14 Aug 2002 17,791 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\DLink DT620 Packet\Dt620pd.com"
Wed 14 Aug 2002 11,491 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\DLink DMF560-TX Packet\Lmpd.com"
Wed 14 Aug 2002 17,043 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\DLink DE400 Packet\De400pd.com"
Wed 14 Aug 2002 11,854 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\DEC EtherWorks ISA (DE305) Packet\DE305.COM"
Wed 14 Aug 2002 62,391 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\DEC EtherWORKS DE500 Packet\DE500.COM"
Wed 14 Aug 2002 52,715 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\DEC EtherWORKS DE450 Packet\DE450.COM"
Wed 14 Aug 2002 130,980 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\UHCI.EXE"
Wed 14 Aug 2002 13,770 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\PROTMAN.EXE"
Wed 14 Aug 2002 28,439 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\Paralink.com"
Wed 14 Aug 2002 129,240 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\OHCI.EXE"
Wed 14 Aug 2002 41,302 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\OAKCDROM.SYS"
Wed 14 Aug 2002 8,513 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\NETBIND.COM"
Wed 14 Aug 2002 354,263 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\Net.exe"
Wed 14 Aug 2002 21,180 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\MSCDEX.EXE"
Wed 14 Aug 2002 354,304 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\msbootsrv16.sys"
Wed 14 Aug 2002 37,681 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\MOUSE.COM"
Wed 14 Aug 2002 15,777 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\MODE.COM"
Wed 14 Aug 2002 53,556 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\KEYBOARD.SYS"
Wed 14 Aug 2002 10,898 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\KEYB.COM"
Wed 14 Aug 2002 14,160 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\HIMEM.SYS"
Wed 14 Aug 2002 32,396 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\GUEST.EXE"
Wed 14 Aug 2002 64,425 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\FLASHPT.SYS"
Wed 14 Aug 2002 56,821 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\E.EXE"
Wed 14 Aug 2002 7,840 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\DLSHELP.SYS"
Wed 14 Aug 2002 15,345 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\DISPLAY.SYS"
Wed 14 Aug 2002 1,608 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\DEVICE.COM"
Wed 14 Aug 2002 22,158 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\COUNTRY.SYS"
Wed 14 Aug 2002 374,038 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\CMDS16.EXE"
Wed 14 Aug 2002 202,517 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\CMDS.EXE"
Wed 14 Aug 2002 30,955 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\BTDOSM.SYS"
Wed 14 Aug 2002 21,971 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\BTCDROM.SYS"
Wed 14 Aug 2002 174,080 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\bootsrv16.sys"
Wed 14 Aug 2002 161,792 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\BOOTSRV.SYS"
Wed 14 Aug 2002 50,606 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\ASPIUHCI.SYS"
Wed 14 Aug 2002 49,242 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\ASPIOHCI.SYS"
Wed 28 May 2003 52,106 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\ASPIEHCI.SYS"
Wed 14 Aug 2002 29,628 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\ASPICD.SYS"
Wed 14 Aug 2002 44,828 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\ASPI8U2.SYS"
Wed 14 Aug 2002 37,984 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\ASPI8DOS.SYS"
Wed 14 Aug 2002 14,378 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\ASPI4DOS.SYS"
Wed 14 Aug 2002 35,340 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\ASPI2DOS.SYS"
Wed 28 May 2003 51,150 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\ASPI1394.SYS"
Wed 14 Aug 2002 33,149 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\CATC USB Ethernet\Usbd.sys"
Wed 14 Aug 2002 8,544 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\CATC USB Ethernet\Elndis.sys"
Wed 14 Aug 2002 28,866 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN2320 Packet\EN5251PD.COM"
Wed 14 Aug 2002 10,286 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN2228 Packet\PCMPD.COM"
Wed 14 Aug 2002 25,460 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN2218 Packet\PCMPD.COM"
Wed 14 Aug 2002 24,767 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN2216 Packet\PCMPD.COM"
Wed 14 Aug 2002 7,825 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN166X Packet\NWPD.COM"
Wed 14 Aug 2002 14,438 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1658 Packet\NWPD.COM"
Wed 14 Aug 2002 14,438 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1657 Packet\NWPD.COM"
Wed 14 Aug 2002 7,825 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1656 Packet\NWPD.COM"
Wed 14 Aug 2002 7,243 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1653 Packet\NE2PD.COM"
Wed 14 Aug 2002 7,825 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1652 Packet\NWPD.COM"
Wed 14 Aug 2002 7,825 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1651 Packet\NWPD.COM"
Wed 14 Aug 2002 7,825 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1650 Packet\NWPD.COM"
Wed 14 Aug 2002 13,673 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1640 Packet\NWPD.COM"
Wed 14 Aug 2002 7,463 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1625 Packet\NEPD.COM"
Wed 14 Aug 2002 9,424 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1208 Packet\1208PD.COM"
Wed 14 Aug 2002 10,257 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1207TX Packet\PCIPD.COM"
Wed 14 Aug 2002 28,062 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1207F Packet\EN5251PD.COM"
Wed 14 Aug 2002 10,083 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1207D Packet\ACCPKT.COM"
Wed 14 Aug 2002 10,710 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1207C Packet\PCIPD.COM"
Wed 14 Aug 2002 11,031 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1207 Packet\PCIPD.COM"
Wed 14 Aug 2002 12,660 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1204 Packet\VLNWPD.COM"
Wed 14 Aug 2002 29,499 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1203 Packet\PCIPD.COM"
Wed 14 Aug 2002 17,952 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\ACCTON EN1200 Packet\EC32PD.COM"
Wed 14 Aug 2002 26,424 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\3COM 3c59x Packet\3C59XPD.COM"
Wed 14 Aug 2002 65,088 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\3COM 3c556 Packet\3C556.COM"
Wed 14 Aug 2002 12,732 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\3COM 3c509 Packet\3C5X9PD.COM"
Wed 14 Aug 2002 42,550 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\pcdos\IBMDOS.COM"
Wed 14 Aug 2002 44,240 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\pcdos\IBMBIO.COM"
Wed 14 Aug 2002 53,786 A..H. — "C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Ghost\Template\common\pcdos\command.com"

Finished!
The last log, again interrupted by the popup as I try to post it. Thanks for your continued help Malwarebytes' Anti-Malware 1.24 Database version: 1031 Windows 5.1.2600 Service Pack 2 1:10:57 AM 8/10/08 mbam-log-8-10-2008 (01-10-57).txt Scan type: Full Scan (C:\|K:\|) Objects scanned: 802309 Time elapsed: 4 hour(s), 37 minute(s), 21 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\drivers\emStreamm.sys (Rootkit.Agent) -> Delete on reboot. C:\WINDOWS\system32\drivers\core.cache.dsk (Rootkit.Agent) -> Delete on reboot.
hi,

ok thanks for the info. we will get one more download to use. link and directions below:

Download combofix from one of these links and save it to your Desktop:

http://subs.geekstogo.com/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
Still getting the popup - worse this time. Almost could not get back here.

ComboFix 08-08-10.01 - Carey Mumford 2008-08-10 15:39:32.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.360 [GMT -5:00]
Running from: H:\My Downloads\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\macromedia\Flash Player\#SharedObjects\9CX8QKVW\interclick.com
C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\macromedia\Flash Player\#SharedObjects\9CX8QKVW\interclick.com\ud.sol
C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Program Files\Common Files\racle~1
C:\temp\tn3
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\crosof~1.net
C:\WINDOWS\system32\hnlwjsox.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\rCMVFfhk.ini
C:\WINDOWS\system32\rCMVFfhk.ini2
C:\WINDOWS\system32\REGOBJ.DLL
C:\WINDOWS\system32\vvwaGfhk.ini
C:\WINDOWS\system32\vvwaGfhk.ini2
K:\Autorun.inf
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-07-10 to 2008-08-10 )))))))))))))))))))))))))))))))
.

2008-08-09 08:49 . 2008-08-09 08:49 167,976 ——— C:\WINDOWS\system32\drivers\core.cache.dsk
2008-08-09 08:42 . 2008-08-09 08:42 d——– C:\WINDOWS\ERUNT
2008-08-09 08:34 . 2008-08-07 16:28 d——– C:\SDFix
2008-08-07 21:37 . 2008-08-07 21:37 d——– C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\Malwarebytes
2008-08-07 21:36 . 2008-08-07 21:36 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-07 21:36 . 2008-08-07 21:36 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-08-07 21:36 . 2008-07-30 20:07 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-07 21:36 . 2008-07-30 20:07 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-07-31 13:18 . 2008-07-31 13:36 250 –a—— C:\WINDOWS\gmer.ini
2008-07-29 08:56 . 2008-07-29 08:56 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-07-29 08:50 . 2008-07-29 08:50 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-07-28 08:39 . 2008-07-25 09:39 117,417 ——— C:\WINDOWS\hpoins11.dat.temp
2008-07-28 08:39 . 2007-04-19 18:14 11,634 ——— C:\WINDOWS\hpomdl11.dat.temp
2008-07-25 09:08 . 2008-07-25 09:08 d——– C:\Program Files\Common Files\Sonic Shared
2008-07-25 08:53 . 2008-07-25 08:53 d——– C:\Program Files\Common Files\Hewlett-Packard
2008-07-25 08:52 . 2006-04-10 14:03 38,400 –a—— C:\WINDOWS\system32\hpz3l054.dll
2008-07-25 08:51 . 2006-04-12 19:02 827,392 -ra—— C:\WINDOWS\system32\hpotiop2.dll
2008-07-25 08:51 . 2006-04-12 19:02 659,456 -ra—— C:\WINDOWS\system32\HPOWIAX2.DLL
2008-07-25 08:51 . 2006-04-12 19:02 659,456 –a—— C:\WINDOWS\system32\HPOWIAX2(3).DLL
2008-07-25 08:51 . 2006-04-12 19:02 659,456 –a—— C:\WINDOWS\system32\HPOWIAX2(2).DLL
2008-07-25 08:51 . 2006-04-12 19:02 254,026 -ra—— C:\WINDOWS\system32\hpovst09.dll
2008-07-25 08:51 . 2006-04-12 19:02 254,026 –a—— C:\WINDOWS\system32\hpovst09(2).dll
2008-07-25 08:51 . 2001-08-17 13:53 6,784 –a—— C:\WINDOWS\system32\drivers\serscan.sys
2008-07-25 08:51 . 2001-08-17 13:53 6,784 –a—— C:\WINDOWS\system32\dllcache\serscan.sys
2008-07-25 08:51 . 2008-07-25 08:51 732 –a—— C:\WINDOWS\hpntwksetup.ini
2008-07-25 08:51 . 2008-07-25 08:51 164 –a—— C:\WINDOWS\system32\AddPort.ini
2008-07-25 08:44 . 2008-07-28 08:57 116,864 –a—— C:\WINDOWS\hpoins11.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-09 13:34 40,960 —-a-w C:\WINDOWS\system32\PingIPscan307.exe
2008-06-30 01:47 2,235 —-a-w C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\SAS7_000.DAT
2008-06-30 01:34 ——— d—–w C:\Program Files\Common Files\ScanSoft Shared
2008-06-30 01:34 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\ScanSoft
2008-06-27 16:09 ——— d—–w C:\Program Files\Nuance
2008-06-26 17:54 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip
2008-06-26 16:47 ——— d—–w C:\Program Files\Sun
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 —-a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:45 360,320 ——w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 10:44 138,368 ——w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-20 09:52 225,920 ——w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10 272,128 —-a-w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 01:43 ——— d—–w C:\Program Files\activePDF
2008-05-16 16:58 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2007-03-09 22:29 87,608 —-a-w C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\ezpinst.exe
2007-03-09 22:29 47,360 —-a-w C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\pcouffin.sys
2005-01-01 14:26 0 —-a-w C:\Program Files\All_Sorted_dedup.txt
2004-04-18 12:02 560 —-a-w C:\Documents and Settings\Carey Mumford\PCDOC.BAT
2003-10-28 23:56 208,360 —-a-w C:\Program Files\INSTALL.LOG
2001-05-24 18:59 162,304 —-a-w C:\Program Files\UNWISE.EXE
2004-09-08 10:57 32 –sha-w C:\WINDOWS\{4887AAC7-C120-4D58-9A59-CF1DF497F9E4}.dat
2007-01-22 21:52 4,263 –sh–w C:\WINDOWS\windllreg1c.sys
2005-07-29 21:24 472 –sha-r C:\WINDOWS\Q2FyZXkgTXVtZm9yZA\kZIVtr40nrpQtA6VtE.vbs
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSGTAG"="C:\Program Files\MSGTAG Status\MSGTAGStatus.exe" [2007-07-10 21:38 1820160]
"RealPopup"="C:\Program Files\RealPopup\RealPopup.exe" [2005-02-24 00:50 237568]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"SpybotSD TeaTimer"="H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2008-07-31 06:19 2131600]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 16:48 1443072]
"DefragTaskBar"="H:\Program Files\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe" [2008-04-18 09:11 173408]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 16:15 221184]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 09:03 210472]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 14:03 106544 C:\WINDOWS\system32\TWEAKUI.CPL]

C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\
Camio Viewer.lnk - C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe [2004-09-08 19:14:22 102912]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"= DrvTrNTm.dll
"wave"= DrvTrNTm.dll
"VIDC.CSCD"= camcodec.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Desktop Weather Authority.lnk]
backup=C:\WINDOWS\pss\Desktop Weather Authority.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Energizer FileSaver.lnk]
backup=C:\WINDOWS\pss\Energizer FileSaver.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Carey Mumford.KEYGOLF^Start Menu^Programs^Startup^Camio Viewer.lnk]
backup=C:\WINDOWS\pss\Camio Viewer.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GhostStartTrayApp]
–a—— 2002-08-14 15:21 94208 C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2005-08-19 19:34 3084288 C:\Program Files\Yahoo!\Messenger\YPager.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\FTP Commander\\Ftpcomm.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MSGTAG\\MSGTAG.exe"=
"C:\\Program Files\\Hewlett-Packard\\HP Install Network Printer Wizard\\hpjsi.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\FIREFOX.EXE"=
"C:\\WINDOWS\\System32\\mmc.exe"=
"C:\\WINDOWS\\System32\\SPOOLSV.EXE"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqtra08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqste08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpofxm08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hposfx08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hposid01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqscnvw.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqkygrp.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqCopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpfccopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpzwiz01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpoews01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqnrs08.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"86:TCP"= 86:TCP:BroadCam Web Server

R1 emStreamm;emStreamm;C:\WINDOWS\system32\drivers\emStreamm.sys [2008-04-23 13:36]
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-03-13 16:52]
R1 GhPciScan;GhostPciScanner;C:\Program Files\Norton SystemWorks\Norton Ghost\ghpciscan.sys [2002-08-14 15:11]
R2 WG1N;SyGate for NT, WG1N;C:\WINDOWS\system32\Drivers\WG1N.sys [2001-10-29 18:44]
R2 WG2N;SyGate for NT, WG2N;C:\WINDOWS\system32\Drivers\WG2N.sys [2001-10-29 18:44]
R3 CCCP106;CIF USB Camera (2110A);C:\WINDOWS\system32\DRIVERS\cccp106.sys [2003-04-28 06:03]
S3 s3legacy;s3legacy;C:\WINDOWS\system32\DRIVERS\s3legacy.sys [2001-08-17 08:57]
S3 SiSV;SiSV;C:\WINDOWS\system32\DRIVERS\SiSV.sys [2001-08-17 12:50]
S3 USB28xxBGA;USB 2820 Device;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2006-09-12 21:21]
S3 USB28xxOEM;USB 28xx OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2006-08-21 23:38]
S3 VNUSB;VN Series Device;C:\WINDOWS\system32\DRIVERS\VNUSB.sys [2006-04-07 17:06]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\DCBook.exe
.
Contents of the 'Scheduled Tasks' folder

2008-08-08 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job
- C:\Program Files\Norton SystemWorks\OBC.exe [2002-09-29 21:57]

2008-08-10 C:\WINDOWS\Tasks\HP Usg Login.job
- C:\Program Files\HP Photosmart 11\Printer\Hphusg04.exe []

2007-12-09 C:\WINDOWS\Tasks\RegCure.job
- H:\RegCure\RegCure.exe [2007-08-02 10:20]

2008-08-10 C:\WINDOWS\Tasks\RegCure Program Check.job
- H:\RegCure\RegCure.exe [2007-08-02 10:20]
.
- - - - ORPHANS REMOVED - - - -

Notify-urqNDwxw - urqNDwxw.dll


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\Mozilla\Firefox\Profiles\kr48nxvf.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - google.com


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-10 15:49:27
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
H:\Program Files\aawservice.exe
C:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\A2SERVICE.EXE
H:\Program Files\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\PROGRAM FILES\ESET\ESET NOD32 ANTIVIRUS\EKRN.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON GHOST\GHOSTS~2.EXE
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LSSRVC.EXE
C:\WINDOWS\SYSTEM32\HPZIPM12.EXE
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\PROGRAM FILES\UPSMON\UPSMON_SERVICE.EXE
C:\PROGRAM FILES\UPSMON\UPSINT2.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPQNRS08.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZinw12.exe
.
**************************************************************************
.
Completion time: 2008-08-10 15:54:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-10 20:54:22

Pre-Run: 13,482,655,744 bytes free
Post-Run: 14,105,640,960 bytes free

229 — E O F — 2008-07-09 11:00:01


Logfile of HijackThis v1.99.1
Scan saved at 3:56:49 PM, on 8/10/08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
H:\Program Files\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UPSMON\UPSMON_Service.Exe
C:\Program Files\UPSMON\UPSInt2.exe
C:\WINDOWS\system32\Ati2evxx.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\Program Files\a-squared Anti-Malware\a2guard.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\MSGTAG Status\MSGTAGStatus.exe
C:\Program Files\RealPopup\RealPopup.exe
C:\WINDOWS\system32\ctfmon.exe
H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Carey Mumford.KEYGOLF\Desktop\Unused Desktop Shortcuts\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\PROGRA~1\TEXTAL~1\TAForIE.dll
O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DefragTaskBar] "H:\Program Files\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKCU\..\Run: [MSGTAG] "C:\Program Files\MSGTAG Status\MSGTAGStatus.exe" /startup
O4 - HKCU\..\Run: [RealPopup] "C:\Program Files\RealPopup\RealPopup.exe" BOOT
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Search - ?p=ZUfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support2.charter.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://38.114.50.171/activex/AMC.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - H:\Program Files\aawservice.exe
O23 - Service: Ashampoo Defrag Service (AshampooDefragService) - - H:\Program Files\Ashampoo Magical Defrag 2\bin\aDefragService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: UPSMONService - Unknown owner - C:\Program Files\UPSMON\UPSMON_Service.Exe
hi,

ok thanks for the info. we will use combofix.

Click Start, then Run and type Notepad and click OK.
Copy/paste the text in the code box below into notepad:



File:
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\windllreg1c.sys
C:\WINDOWS\Q2FyZXkgTXVtZm9yZA\kZIVtr40nrpQtA6VtE.vbs
C:\WINDOWS\{4887AAC7-C120-4D58-9A59-CF1DF497F9E4}.dat



Name the Notepad file CFScript.txt and Save it to your desktop.
now locate the file you just saved and the combofix icon, both on your desktop
using your mouse drag the CFScript right on top of the combofix icon and release, combofix will run and produce a new log
please post the new combofix log and a new hjt log.
Here's the newest…

ComboFix 08-08-10.01 - Carey Mumford 2008-08-10 17:28:50.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.321 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Carey Mumford.KEYGOLF\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\temp\tn3
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-07-10 to 2008-08-10 )))))))))))))))))))))))))))))))
.

2008-08-10 17:37 . 2008-08-10 17:37 d——– C:\temp\tn3
2008-08-09 08:49 . 2008-08-09 08:49 167,976 ——— C:\WINDOWS\system32\drivers\core.cache.dsk
2008-08-09 08:42 . 2008-08-09 08:42 d——– C:\WINDOWS\ERUNT
2008-08-09 08:34 . 2008-08-07 16:28 d——– C:\SDFix
2008-08-07 21:37 . 2008-08-07 21:37 d——– C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\Malwarebytes
2008-08-07 21:36 . 2008-08-07 21:36 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-07 21:36 . 2008-08-07 21:36 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-08-07 21:36 . 2008-07-30 20:07 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-07 21:36 . 2008-07-30 20:07 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-07-31 13:18 . 2008-07-31 13:36 250 –a—— C:\WINDOWS\gmer.ini
2008-07-29 08:56 . 2008-07-29 08:56 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-07-29 08:50 . 2008-07-29 08:50 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-07-28 08:39 . 2008-07-25 09:39 117,417 ——— C:\WINDOWS\hpoins11.dat.temp
2008-07-28 08:39 . 2007-04-19 18:14 11,634 ——— C:\WINDOWS\hpomdl11.dat.temp
2008-07-25 09:08 . 2008-07-25 09:08 d——– C:\Program Files\Common Files\Sonic Shared
2008-07-25 08:53 . 2008-07-25 08:53 d——– C:\Program Files\Common Files\Hewlett-Packard
2008-07-25 08:52 . 2006-04-10 14:03 38,400 –a—— C:\WINDOWS\system32\hpz3l054.dll
2008-07-25 08:51 . 2006-04-12 19:02 827,392 -ra—— C:\WINDOWS\system32\hpotiop2.dll
2008-07-25 08:51 . 2006-04-12 19:02 659,456 -ra—— C:\WINDOWS\system32\HPOWIAX2.DLL
2008-07-25 08:51 . 2006-04-12 19:02 659,456 –a—— C:\WINDOWS\system32\HPOWIAX2(3).DLL
2008-07-25 08:51 . 2006-04-12 19:02 659,456 –a—— C:\WINDOWS\system32\HPOWIAX2(2).DLL
2008-07-25 08:51 . 2006-04-12 19:02 254,026 -ra—— C:\WINDOWS\system32\hpovst09.dll
2008-07-25 08:51 . 2006-04-12 19:02 254,026 –a—— C:\WINDOWS\system32\hpovst09(2).dll
2008-07-25 08:51 . 2001-08-17 13:53 6,784 –a—— C:\WINDOWS\system32\drivers\serscan.sys
2008-07-25 08:51 . 2001-08-17 13:53 6,784 –a—— C:\WINDOWS\system32\dllcache\serscan.sys
2008-07-25 08:51 . 2008-07-25 08:51 732 –a—— C:\WINDOWS\hpntwksetup.ini
2008-07-25 08:51 . 2008-07-25 08:51 164 –a—— C:\WINDOWS\system32\AddPort.ini
2008-07-25 08:44 . 2008-07-28 08:57 116,864 –a—— C:\WINDOWS\hpoins11.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-09 13:34 40,960 —-a-w C:\WINDOWS\system32\PingIPscan307.exe
2008-06-30 01:47 2,235 —-a-w C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\SAS7_000.DAT
2008-06-30 01:34 ——— d—–w C:\Program Files\Common Files\ScanSoft Shared
2008-06-30 01:34 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\ScanSoft
2008-06-27 16:09 ——— d—–w C:\Program Files\Nuance
2008-06-26 17:54 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip
2008-06-26 16:47 ——— d—–w C:\Program Files\Sun
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 —-a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:45 360,320 ——w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 10:44 138,368 ——w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-20 09:52 225,920 ——w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10 272,128 —-a-w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 01:43 ——— d—–w C:\Program Files\activePDF
2008-05-16 16:58 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2007-03-09 22:29 87,608 —-a-w C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\ezpinst.exe
2007-03-09 22:29 47,360 —-a-w C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\pcouffin.sys
2005-01-01 14:26 0 —-a-w C:\Program Files\All_Sorted_dedup.txt
2004-04-18 12:02 560 —-a-w C:\Documents and Settings\Carey Mumford\PCDOC.BAT
2003-10-28 23:56 208,360 —-a-w C:\Program Files\INSTALL.LOG
2001-05-24 18:59 162,304 —-a-w C:\Program Files\UNWISE.EXE
2004-09-08 10:57 32 –sha-w C:\WINDOWS\{4887AAC7-C120-4D58-9A59-CF1DF497F9E4}.dat
2007-01-22 21:52 4,263 –sh–w C:\WINDOWS\windllreg1c.sys
2005-07-29 21:24 472 –sha-r C:\WINDOWS\Q2FyZXkgTXVtZm9yZA\kZIVtr40nrpQtA6VtE.vbs
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSGTAG"="C:\Program Files\MSGTAG Status\MSGTAGStatus.exe" [2007-07-10 21:38 1820160]
"RealPopup"="C:\Program Files\RealPopup\RealPopup.exe" [2005-02-24 00:50 237568]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"SpybotSD TeaTimer"="H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2008-07-31 06:19 2131600]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 16:48 1443072]
"DefragTaskBar"="H:\Program Files\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe" [2008-04-18 09:11 173408]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 16:15 221184]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 09:03 210472]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 14:03 106544 C:\WINDOWS\system32\TWEAKUI.CPL]

C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\
Camio Viewer.lnk - C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe [2004-09-08 19:14:22 102912]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"= DrvTrNTm.dll
"wave"= DrvTrNTm.dll
"VIDC.CSCD"= camcodec.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Desktop Weather Authority.lnk]
backup=C:\WINDOWS\pss\Desktop Weather Authority.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Energizer FileSaver.lnk]
backup=C:\WINDOWS\pss\Energizer FileSaver.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Carey Mumford.KEYGOLF^Start Menu^Programs^Startup^Camio Viewer.lnk]
backup=C:\WINDOWS\pss\Camio Viewer.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GhostStartTrayApp]
–a—— 2002-08-14 15:21 94208 C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2005-08-19 19:34 3084288 C:\Program Files\Yahoo!\Messenger\YPager.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\FTP Commander\\Ftpcomm.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MSGTAG\\MSGTAG.exe"=
"C:\\Program Files\\Hewlett-Packard\\HP Install Network Printer Wizard\\hpjsi.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\FIREFOX.EXE"=
"C:\\WINDOWS\\System32\\mmc.exe"=
"C:\\WINDOWS\\System32\\SPOOLSV.EXE"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqtra08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqste08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpofxm08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hposfx08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hposid01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqscnvw.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqkygrp.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqCopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpfccopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpzwiz01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpoews01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqnrs08.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"86:TCP"= 86:TCP:BroadCam Web Server

R1 emStreamm;emStreamm;C:\WINDOWS\system32\drivers\emStreamm.sys [2008-04-23 13:36]
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-03-13 16:52]
R1 GhPciScan;GhostPciScanner;C:\Program Files\Norton SystemWorks\Norton Ghost\ghpciscan.sys [2002-08-14 15:11]
R2 WG1N;SyGate for NT, WG1N;C:\WINDOWS\system32\Drivers\WG1N.sys [2001-10-29 18:44]
R2 WG2N;SyGate for NT, WG2N;C:\WINDOWS\system32\Drivers\WG2N.sys [2001-10-29 18:44]
R3 CCCP106;CIF USB Camera (2110A);C:\WINDOWS\system32\DRIVERS\cccp106.sys [2003-04-28 06:03]
S3 s3legacy;s3legacy;C:\WINDOWS\system32\DRIVERS\s3legacy.sys [2001-08-17 08:57]
S3 SiSV;SiSV;C:\WINDOWS\system32\DRIVERS\SiSV.sys [2001-08-17 12:50]
S3 USB28xxBGA;USB 2820 Device;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2006-09-12 21:21]
S3 USB28xxOEM;USB 28xx OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2006-08-21 23:38]
S3 VNUSB;VN Series Device;C:\WINDOWS\system32\DRIVERS\VNUSB.sys [2006-04-07 17:06]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\DCBook.exe
.
Contents of the 'Scheduled Tasks' folder

2008-08-08 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job
- C:\Program Files\Norton SystemWorks\OBC.exe [2002-09-29 21:57]

2008-08-10 C:\WINDOWS\Tasks\HP Usg Login.job
- C:\Program Files\HP Photosmart 11\Printer\Hphusg04.exe []

2007-12-09 C:\WINDOWS\Tasks\RegCure.job
- H:\RegCure\RegCure.exe [2007-08-02 10:20]

2008-08-10 C:\WINDOWS\Tasks\RegCure Program Check.job
- H:\RegCure\RegCure.exe [2007-08-02 10:20]
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-10 17:37:25
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
H:\Program Files\aawservice.exe
C:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\A2SERVICE.EXE
H:\Program Files\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\PROGRAM FILES\ESET\ESET NOD32 ANTIVIRUS\EKRN.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON GHOST\GHOSTS~2.EXE
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LSSRVC.EXE
C:\WINDOWS\SYSTEM32\HPZIPM12.EXE
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\PROGRAM FILES\UPSMON\UPSMON_SERVICE.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\PROGRAM FILES\UPSMON\UPSINT2.EXE
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragMonitorService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZinw12.exe
.
**************************************************************************
.
Completion time: 2008-08-10 17:45:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-10 22:45:02
ComboFix2.txt 2008-08-10 20:54:46

Pre-Run: 14,283,538,432 bytes free
Post-Run: 14,269,579,264 bytes free

211 — E O F — 2008-07-09 11:00:01

Logfile of HijackThis v1.99.1
Scan saved at 6:00:58 PM, on 8/10/08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
H:\Program Files\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UPSMON\UPSMON_Service.Exe
C:\Program Files\UPSMON\UPSInt2.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragMonitorService.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\Program Files\a-squared Anti-Malware\a2guard.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\MSGTAG Status\MSGTAGStatus.exe
C:\Program Files\RealPopup\RealPopup.exe
C:\WINDOWS\system32\ctfmon.exe
H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\Documents and Settings\Carey Mumford.KEYGOLF\Desktop\Unused Desktop Shortcuts\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\PROGRA~1\TEXTAL~1\TAForIE.dll
O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DefragTaskBar] "H:\Program Files\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKCU\..\Run: [MSGTAG] "C:\Program Files\MSGTAG Status\MSGTAGStatus.exe" /startup
O4 - HKCU\..\Run: [RealPopup] "C:\Program Files\RealPopup\RealPopup.exe" BOOT
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Search - ?p=ZUfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support2.charter.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://38.114.50.171/activex/AMC.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - H:\Program Files\aawservice.exe
O23 - Service: Ashampoo Defrag Service (AshampooDefragService) - - H:\Program Files\Ashampoo Magical Defrag 2\bin\aDefragService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: UPSMONService - Unknown owner - C:\Program Files\UPSMON\UPSMON_Service.Exe
hi,

ok thanks for the info. that didnt work, i picked the wrong file– we will use hjt again like last time:

Click Start, then Run and type Notepad and click OK.
Copy/paste the text in the code box below into notepad:



File:
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\emStreamm.sys
C:\WINDOWS\system32\PingIPscan307.exe
Name the Notepad file CFScript.txt and Save it to your desktop.
now locate the file you just saved and the combofix icon, both on your desktop
using your mouse drag the CFScript right on top of the combofix icon and release, combofix will run and produce a new log
please post the new combofix log and a new hjt log.
Once more. Hope you are not getting tired of this!

ComboFix 08-08-10.01 - Carey Mumford 2008-08-10 21:48:21.3 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.338 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Carey Mumford.KEYGOLF\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\temp\tn3
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-07-11 to 2008-08-11 )))))))))))))))))))))))))))))))
.

2008-08-10 21:55 . 2008-08-10 21:55 d——– C:\temp\tn3
2008-08-10 21:35 . 2008-08-10 21:35 d–hs—- C:\FOUND.002
2008-08-10 17:53 . 2008-08-10 17:53 d–hs—- C:\FOUND.001
2008-08-09 08:49 . 2008-08-09 08:49 167,976 ——— C:\WINDOWS\system32\drivers\core.cache.dsk
2008-08-09 08:42 . 2008-08-09 08:42 d——– C:\WINDOWS\ERUNT
2008-08-09 08:34 . 2008-08-07 16:28 d——– C:\SDFix
2008-08-07 21:37 . 2008-08-07 21:37 d——– C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\Malwarebytes
2008-08-07 21:36 . 2008-08-07 21:36 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-07 21:36 . 2008-08-07 21:36 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-08-07 21:36 . 2008-07-30 20:07 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-07 21:36 . 2008-07-30 20:07 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-07-31 13:18 . 2008-07-31 13:36 250 –a—— C:\WINDOWS\gmer.ini
2008-07-29 08:56 . 2008-07-29 08:56 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-07-29 08:50 . 2008-07-29 08:50 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-07-28 08:39 . 2008-07-25 09:39 117,417 ——— C:\WINDOWS\hpoins11.dat.temp
2008-07-28 08:39 . 2007-04-19 18:14 11,634 ——— C:\WINDOWS\hpomdl11.dat.temp
2008-07-25 09:08 . 2008-07-25 09:08 d——– C:\Program Files\Common Files\Sonic Shared
2008-07-25 08:53 . 2008-07-25 08:53 d——– C:\Program Files\Common Files\Hewlett-Packard
2008-07-25 08:52 . 2006-04-10 14:03 38,400 –a—— C:\WINDOWS\system32\hpz3l054.dll
2008-07-25 08:51 . 2006-04-12 19:02 827,392 -ra—— C:\WINDOWS\system32\hpotiop2.dll
2008-07-25 08:51 . 2006-04-12 19:02 659,456 -ra—— C:\WINDOWS\system32\HPOWIAX2.DLL
2008-07-25 08:51 . 2006-04-12 19:02 659,456 –a—— C:\WINDOWS\system32\HPOWIAX2(3).DLL
2008-07-25 08:51 . 2006-04-12 19:02 659,456 –a—— C:\WINDOWS\system32\HPOWIAX2(2).DLL
2008-07-25 08:51 . 2006-04-12 19:02 254,026 -ra—— C:\WINDOWS\system32\hpovst09.dll
2008-07-25 08:51 . 2006-04-12 19:02 254,026 –a—— C:\WINDOWS\system32\hpovst09(2).dll
2008-07-25 08:51 . 2001-08-17 13:53 6,784 –a—— C:\WINDOWS\system32\drivers\serscan.sys
2008-07-25 08:51 . 2001-08-17 13:53 6,784 –a—— C:\WINDOWS\system32\dllcache\serscan.sys
2008-07-25 08:51 . 2008-07-25 08:51 732 –a—— C:\WINDOWS\hpntwksetup.ini
2008-07-25 08:51 . 2008-07-25 08:51 164 –a—— C:\WINDOWS\system32\AddPort.ini
2008-07-25 08:44 . 2008-07-28 08:57 116,864 –a—— C:\WINDOWS\hpoins11.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-09 13:34 40,960 —-a-w C:\WINDOWS\system32\PingIPscan307.exe
2008-06-30 01:47 2,235 —-a-w C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\SAS7_000.DAT
2008-06-30 01:34 ——— d—–w C:\Program Files\Common Files\ScanSoft Shared
2008-06-30 01:34 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\ScanSoft
2008-06-27 16:09 ——— d—–w C:\Program Files\Nuance
2008-06-26 17:54 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip
2008-06-26 16:47 ——— d—–w C:\Program Files\Sun
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 —-a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:45 360,320 ——w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 10:44 138,368 ——w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-20 09:52 225,920 ——w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10 272,128 —-a-w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 01:43 ——— d—–w C:\Program Files\activePDF
2008-05-16 16:58 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2007-03-09 22:29 87,608 —-a-w C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\ezpinst.exe
2007-03-09 22:29 47,360 —-a-w C:\Documents and Settings\Carey Mumford.KEYGOLF\Application Data\pcouffin.sys
2005-01-01 14:26 0 —-a-w C:\Program Files\All_Sorted_dedup.txt
2004-04-18 12:02 560 —-a-w C:\Documents and Settings\Carey Mumford\PCDOC.BAT
2003-10-28 23:56 208,360 —-a-w C:\Program Files\INSTALL.LOG
2001-05-24 18:59 162,304 —-a-w C:\Program Files\UNWISE.EXE
2004-09-08 10:57 32 –sha-w C:\WINDOWS\{4887AAC7-C120-4D58-9A59-CF1DF497F9E4}.dat
2007-01-22 21:52 4,263 –sh–w C:\WINDOWS\windllreg1c.sys
2005-07-29 21:24 472 –sha-r C:\WINDOWS\Q2FyZXkgTXVtZm9yZA\kZIVtr40nrpQtA6VtE.vbs
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSGTAG"="C:\Program Files\MSGTAG Status\MSGTAGStatus.exe" [2007-07-10 21:38 1820160]
"RealPopup"="C:\Program Files\RealPopup\RealPopup.exe" [2005-02-24 00:50 237568]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"SpybotSD TeaTimer"="H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2008-07-31 06:19 2131600]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 16:48 1443072]
"DefragTaskBar"="H:\Program Files\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe" [2008-04-18 09:11 173408]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 16:15 221184]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 09:03 210472]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 14:03 106544 C:\WINDOWS\system32\TWEAKUI.CPL]

C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\
Camio Viewer.lnk - C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe [2004-09-08 19:14:22 102912]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"= DrvTrNTm.dll
"wave"= DrvTrNTm.dll
"VIDC.CSCD"= camcodec.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Desktop Weather Authority.lnk]
backup=C:\WINDOWS\pss\Desktop Weather Authority.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Energizer FileSaver.lnk]
backup=C:\WINDOWS\pss\Energizer FileSaver.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Carey Mumford.KEYGOLF^Start Menu^Programs^Startup^Camio Viewer.lnk]
backup=C:\WINDOWS\pss\Camio Viewer.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GhostStartTrayApp]
–a—— 2002-08-14 15:21 94208 C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2005-08-19 19:34 3084288 C:\Program Files\Yahoo!\Messenger\YPager.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\FTP Commander\\Ftpcomm.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MSGTAG\\MSGTAG.exe"=
"C:\\Program Files\\Hewlett-Packard\\HP Install Network Printer Wizard\\hpjsi.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\FIREFOX.EXE"=
"C:\\WINDOWS\\System32\\mmc.exe"=
"C:\\WINDOWS\\System32\\SPOOLSV.EXE"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqtra08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqste08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpofxm08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hposfx08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hposid01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqscnvw.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqkygrp.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqCopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpfccopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpzwiz01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpoews01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqnrs08.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"86:TCP"= 86:TCP:BroadCam Web Server

R1 emStreamm;emStreamm;C:\WINDOWS\system32\drivers\emStreamm.sys [2008-04-23 13:36]
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-03-13 16:52]
R1 GhPciScan;GhostPciScanner;C:\Program Files\Norton SystemWorks\Norton Ghost\ghpciscan.sys [2002-08-14 15:11]
R2 WG1N;SyGate for NT, WG1N;C:\WINDOWS\system32\Drivers\WG1N.sys [2001-10-29 18:44]
R2 WG2N;SyGate for NT, WG2N;C:\WINDOWS\system32\Drivers\WG2N.sys [2001-10-29 18:44]
R3 CCCP106;CIF USB Camera (2110A);C:\WINDOWS\system32\DRIVERS\cccp106.sys [2003-04-28 06:03]
S3 s3legacy;s3legacy;C:\WINDOWS\system32\DRIVERS\s3legacy.sys [2001-08-17 08:57]
S3 SiSV;SiSV;C:\WINDOWS\system32\DRIVERS\SiSV.sys [2001-08-17 12:50]
S3 USB28xxBGA;USB 2820 Device;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2006-09-12 21:21]
S3 USB28xxOEM;USB 28xx OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2006-08-21 23:38]
S3 VNUSB;VN Series Device;C:\WINDOWS\system32\DRIVERS\VNUSB.sys [2006-04-07 17:06]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\DCBook.exe
.
Contents of the 'Scheduled Tasks' folder

2008-08-08 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job
- C:\Program Files\Norton SystemWorks\OBC.exe [2002-09-29 21:57]

2008-08-11 C:\WINDOWS\Tasks\HP Usg Login.job
- C:\Program Files\HP Photosmart 11\Printer\Hphusg04.exe []

2007-12-09 C:\WINDOWS\Tasks\RegCure.job
- H:\RegCure\RegCure.exe [2007-08-02 10:20]

2008-08-11 C:\WINDOWS\Tasks\RegCure Program Check.job
- H:\RegCure\RegCure.exe [2007-08-02 10:20]
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-10 21:55:53
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
H:\Program Files\aawservice.exe
C:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\A2SERVICE.EXE
H:\Program Files\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\PROGRAM FILES\ESET\ESET NOD32 ANTIVIRUS\EKRN.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON GHOST\GHOSTS~2.EXE
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LSSRVC.EXE
C:\WINDOWS\SYSTEM32\HPZIPM12.EXE
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\PROGRAM FILES\UPSMON\UPSMON_SERVICE.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\PROGRAM FILES\UPSMON\UPSINT2.EXE
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragMonitorService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZinw12.exe
.
**************************************************************************
.
Completion time: 2008-08-10 22:03:50 - machine was rebooted [Carey Mumford]
ComboFix-quarantined-files.txt 2008-08-11 03:03:36
ComboFix3.txt 2008-08-10 20:54:46
ComboFix2.txt 2008-08-10 22:45:20

Pre-Run: 14,467,760,128 bytes free
Post-Run: 14,506,852,352 bytes free

213 — E O F — 2008-07-09 11:00:01

Logfile of HijackThis v1.99.1
Scan saved at 10:05:23 PM, on 8/10/08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
H:\Program Files\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UPSMON\UPSMON_Service.Exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\UPSMON\UPSInt2.exe
C:\WINDOWS\System32\svchost.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragMonitorService.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\Program Files\a-squared Anti-Malware\a2guard.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
H:\Program Files\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\MSGTAG Status\MSGTAGStatus.exe
C:\Program Files\RealPopup\RealPopup.exe
C:\WINDOWS\system32\ctfmon.exe
H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Carey Mumford.KEYGOLF\Desktop\Unused Desktop Shortcuts\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\PROGRA~1\TEXTAL~1\TAForIE.dll
O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DefragTaskBar] "H:\Program Files\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKCU\..\Run: [MSGTAG] "C:\Program Files\MSGTAG Status\MSGTAGStatus.exe" /startup
O4 - HKCU\..\Run: [RealPopup] "C:\Program Files\RealPopup\RealPopup.exe" BOOT
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Search - ?p=ZUfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support2.charter.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://38.114.50.171/activex/AMC.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - H:\Program Files\aawservice.exe
O23 - Service: Ashampoo Defrag Service (AshampooDefragService) - - H:\Program Files\Ashampoo Magical Defrag 2\bin\aDefragService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: UPSMONService - Unknown owner - C:\Program Files\UPSMON\UPSMON_Service.Exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI