This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virtumonde.Generic

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I ran spybot S&D and it found Virtumonde.Generic, I tried getting rid of it but it keeps coming back. I tried running vundofix but it found no files that were infected. The computer seems to be running slower and freezing up more frequently with system errors. Mostly, when I do a search in google it redirects me several times to a random website but if I click on the back button and try the link again it works. As for pop-ups, I get them but they are blocked.

Logfile of HijackThis v1.99.1
Scan saved at 12:45:56 AM, on 14/08/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WgaTray.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Internet Call Manager\ICM.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Documents and Settings\Raymond White\Desktop\HijackThis(spyware remover)\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.ca
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9A853E36-4A35-4DBF-9C03-AD9423798E35} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Internet Call Manager.LNK = C:\Program Files\Internet Call Manager\ICM.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O12 - Plugin for .wma: C:\Program Files\Sympatico\Communicator\Program\PLUGINS\npdsplay.dll
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1136658589914
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{63E9BA26-3749-4A06-8022-78E155A92AE6}: NameServer = 85.255.115.22 85.255.112.101
O17 - HKLM\System\CS2\Services\Tcpip\..\{63E9BA26-3749-4A06-8022-78E155A92AE6}: NameServer = 85.255.115.22 85.255.112.101
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: vtuvtsr - vtuvtsr.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winudu32 - winudu32.dll (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE (file missing)
Hello

Please download FixWareout from here:
http://downloads.subratam.org/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts. If your firewall gives an alert, (because this tool will download an additional file from the internet), please don't let your firewall block it, but allow it instead.
Then you will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
Once the desktop loads please post the text that will open (report.txt) and a new Hijackthis log

If you have internet connection problems then do the following :

Please go to Start -> Control Panel, and choose Network Connections. Then right click on your default connection, usually Local Area Connection or Dial-up Connection if you are using Dial-up, and left click on properties. Double-click on the Internet Protocol (TCP/IP) item and select the radio button that says Obtain DNS servers automatically. Click OK twice, and restart your computer.



Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
  • When it has finished, dss will open two Notepads main.txt and extra.txt – please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
Ok everything went perfect, all scans went through and I connected just fine to the internet. As for the second program you told me to download I kept getting a prompt which told me there was a temporary network problem and it kept asking me to retry to download to no avail. If I do get it to work I'll post it asap. Here are the scan reports.

Username "Raymond White" - 14/08/2008 18:31:49 [Fixwareout edited 9/01/2007]

~~~~~ Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="csvqd.exe"


System was rebooted successfully.

~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
….
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "llun" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion "dqvsc" Value deleted
HKCR\CLSID\{8289C467-F285-48B3-9A53-A53A6A158D73}\_h\4 Deleted.
….
~~~~~ Misc files.
….
~~~~~ Checking for older varients.
….

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"="SysTray.Exe"
"AdaptecDirectCD"="C:\\Program Files\\Adaptec\\Easy CD Creator 5\\DirectCD\\DirectCD.exe"
"Share-to-Web Namespace Daemon"="C:\\Program Files\\Hewlett-Packard\\HP Share-to-Web\\hpgs2wnd.exe"
"CamMonitor"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\hpqcmon.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"Microsoft Works Update Detection"="C:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkUFind.exe"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\System32\\ctfmon.exe"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
….
Hosts file was reset, If you use a custom hosts file please replace it…
C:\WINDOWS\System32\AUTOEXEC.NT missing
~~~~~ End report ~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 6:38:06 PM, on 14/08/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WgaTray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Call Manager\ICM.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Documents and Settings\Raymond White\Desktop\HijackThis(spyware remover)\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.ca
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9A853E36-4A35-4DBF-9C03-AD9423798E35} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Internet Call Manager.LNK = C:\Program Files\Internet Call Manager\ICM.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O12 - Plugin for .wma: C:\Program Files\Sympatico\Communicator\Program\PLUGINS\npdsplay.dll
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1136658589914
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: vtuvtsr - vtuvtsr.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winudu32 - winudu32.dll (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE (file missing)
Deckard's System Scanner v20071014.68
Run by [removed] on 2008-08-14 19:09:37
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
8: 2008-08-14 22:09:48 UTC - RP603 - Deckard's System Scanner Restore Point
7: 2008-08-13 22:56:11 UTC - RP602 - System Checkpoint
6: 2008-08-12 15:01:12 UTC - RP601 - System Checkpoint
5: 2008-08-11 14:56:53 UTC - RP600 - System Checkpoint
4: 2008-08-10 12:38:20 UTC - RP599 - System Checkpoint


– First Restore Point –
1: 2008-08-07 00:03:30 UTC - RP596 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 384 MiB (512 MiB recommended).


– HijackThis (run as Raymond White.exe) —————————————

Unable to find log (file not found); running clone.
– HijackThis Clone ————————————————————


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-08-14 19:14:44
Platform: Windows XP (5.01.2600)
MSIE: Internet Explorer (6.00.2600.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\SYSTEM32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\SYSTEM32\services.exe
C:\WINDOWS\SYSTEM32\lsass.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\spoolsv.exe
C:\WINDOWS\SYSTEM32\DRIVERS\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\WgaTray.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\Directcd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\SYSTEM32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Call Manager\ICM.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Raymond White\Desktop\HijackThis(spyware remover)\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.microsoft.com/search/lobby/search.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.ca
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9A853E36-4A35-4DBF-9C03-AD9423798E35} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Internet Call Manager.LNK = C:\Program Files\Internet Call Manager\ICM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {00000055-0000-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/fhgax.CAB
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {31564D57-0000-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/wmvax.cab
O16 - DPF: {32564D57-0000-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/wmv8ax.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1136658589914
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} () - http://v4.windowsupdate.microsoft.com/CAB/…7622.4436226852
O16 - DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} () - http://windowsupdate.microsoft.com/R999/V3…en/actsetup.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\SYSTEM32\msvidctl.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Filter: application/x-icq - {db40c160-09a1-11d3-baf2-000000000000} - C:\Program Files\ICQ\IExplorerMime.dll (file missing)
O20 - Winlogon Notify: vtuvtsr - C:\WINDOWS\System32\vtuvtsr.dll (file missing)
O20 - Winlogon Notify: winudu32 - C:\WINDOWS\System32\winudu32.dll (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\SYSTEM32\DRIVERS\KodakCCS.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE


–
End of file - 7722 bytes

– HijackThis Fixed Entries (C:\DOCUME~1\RAYMON~1\Desktop\HIJACK~1\backups\) —

backup-20060803-213314-483 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
backup-20060803-213314-604 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20060803-213314-570 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20060803-213314-169 R3 - URLSearchHook: (no name) - _{5A2DE536-0BF1-0F04-A1E9-05D58C25E39F} - (no file)
backup-20060803-213314-452 R3 - URLSearchHook: (no name) - _{8277E983-5647-01B0-4517-5A50D4513193} - (no file)
backup-20060803-213314-960 R3 - URLSearchHook: (no name) - {C1255F66-E4A1-BF55-A6A9-E13B82077695} - (no file)
backup-20060803-213314-430 O1 - Hosts: localhost 127.0.0.1
backup-20060803-213314-485 O2 - BHO: (no name) - {130405B1-F11C-B7BF-00C1-E4D5BDA3E2FA} - C:\WINDOWS\System32\ynbwgike.dll (file missing)
backup-20060803-213314-947 O2 - BHO: (no name) - {262935B1-DC2F-828B-2DF1-D4F88D93CFCA} - C:\WINDOWS\System32\ynbwgike.dll (file missing)
backup-20060803-213314-639 O2 - BHO: (no name) - {44880B16-FFE5-B646-AE2B-EA3563C3BDFE} - C:\WINDOWS\System32\skzh.dll (file missing)
backup-20060803-213314-330 O2 - BHO: (no name) - {4C69C042-32EB-2349-A2AB-72FCDF53E9F8} - C:\WINDOWS\System32\qact.dll (file missing)
backup-20060803-213314-791 O2 - BHO: (no name) - {5A2DE536-0BF1-0F04-A1E9-05D58C25E39F} - C:\WINDOWS\System32\ozzslemr.dll (file missing)
backup-20060803-213314-690 O2 - BHO: (no name) - {5C2567E6-9949-88EB-0721-DAC69C76F9AC} - C:\WINDOWS\System32\aixpz.dll (file missing)
backup-20060803-213314-118 O2 - BHO: (no name) - {690857E6-B47A-BDDF-2A11-EAEBAC46D49C} - C:\WINDOWS\System32\aixpz.dll (file missing)
backup-20060803-213314-331 O2 - BHO: (no name) - {71A53B16-D2D6-8372-831B-DA1853F390CE} - C:\WINDOWS\System32\skzh.dll (file missing)
backup-20060803-213314-191 O2 - BHO: (no name) - {80AF48D5-E074-ABD0-6ED7-F5F41FBC77AD} - C:\WINDOWS\System32\qwbfyi.dll (file missing)
backup-20060803-213314-464 O2 - BHO: (no name) - {8277E983-5647-01B0-4517-5A50D4513193} - C:\WINDOWS\System32\rearx.dll (file missing)
backup-20060803-213314-646 O2 - BHO: (no name) - {8EE82CB3-CF70-95D5-7804-CB891A086496} - C:\WINDOWS\System32\cfkshs.dll (file missing)
backup-20060803-213314-662 O2 - BHO: (no name) - {C58BCA75-3782-2A73-9FB8-234934BE61F5} - C:\WINDOWS\System32\svglcyf.dll (file missing)
backup-20060803-213314-363 O2 - BHO: (no name) - {D22CADD0-0978-1388-3782-105A95F627FB} - C:\WINDOWS\System32\retns.dll (file missing)
backup-20060803-213314-922 O4 - HKLM\..\Run: [dmatd.exe] C:\WINDOWS\System32\dmatd.exe
backup-20060803-213314-212 O4 - HKLM\..\Run: [htzqt.exe] C:\WINDOWS\System32\htzqt.exe
backup-20060803-213314-873 O4 - HKCU\..\Run: [Raoa] "C:\DOCUME~1\RAYMON~1\MYDOCU~1\MCROSO~1.NET\wuauclt.exe" -vt ndrv
backup-20060803-213314-514 O4 - Global Startup: MSWin.exe
backup-20060803-213316-654 O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200203…meInstaller.exe
backup-20060803-225026-495 O4 - HKLM\..\Run: [ZICORN] C:\WINDOWS\System32\ZICORN
backup-20060805-222832-672 O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\DOWNLO~1\INCRED~1\INCRED~1\bin\WebMenuImg.htm
backup-20070523-003556-199 O4 - HKLM\..\Run: [ipmon] ipmon.exe
backup-20070524-225208-425 O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll (file missing)
backup-20070524-225208-873 O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

– File Associations ———————————————————–

.bat - batfile - DefaultIcon - C:\WINDOWS\SYSTEM32\SHELL32.DLL,-153
.com - comfile - DefaultIcon - C:\WINDOWS\SYSTEM32\SHELL32.DLL,2
.hlp - hlpfile - DefaultIcon - C:\WINDOWS\SYSTEM32\SHELL32.DLL,23
.ini - inifile - DefaultIcon - shell32.dll,-151
.js - JSFile - DefaultIcon - C:\WINDOWS\System32\migicons.exe,8
.reg - regfile - DefaultIcon - C:\WINDOWS\regedit.exe,1
.txt - txtfile - DefaultIcon - shell32.dll,-152
.vbs - VBSFile - DefaultIcon - C:\WINDOWS\System32\migicons.exe,7


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R1 SbcpHid - c:\windows\system32\drivers\sbcphid.sys

S1 eeCtrl (Symantec Eraser Control driver) - c:\program files\common files\symantec shared\eengine\eectrl.sys (file missing)
S3 giveio - c:\windows\system32\giveio.sys
S3 SymEvent - c:\program files\symantec\symevent.sys (file missing)
S3 SYMIDSCO - c:\progra~1\common~1\symant~1\symcdata\ids-di~1\20060322.078\symidsco.sys (file missing)


– Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ——————–

S2 ScsiAccess - c:\windows\system32\scsiaccess.exe (file missing)


– Device Manager: Disabled —————————————————-

No disabled devices found.


– Files created between 2008-07-14 and 2008-08-14 —————————–

2008-08-13 10:33:54 0 d——– C:\VundoFix Backups


– Find3M Report —————————————————————

2008-06-26 16:38:10 0 d——– C:\Program Files\ArcSoft
2008-06-26 15:34:38 0 d——– C:\Documents and Settings\Raymond White\Application Data\Canon


– Registry Dump —————————————————————

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9A853E36-4A35-4DBF-9C03-AD9423798E35}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"="SysTray.Exe" [23/08/2001 12:00 PM C:\WINDOWS\SYSTEM32\systray.exe]
"AdaptecDirectCD"="C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [19/07/2002 11:16 PM]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [17/04/2002 10:42 AM]
"CamMonitor"="C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [11/07/2002 04:24 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [10/11/2005 01:03 PM]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [11/02/2003 08:00 AM]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" []
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [23/08/2001 12:00 PM]
"@"="" []
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [19/01/2007 12:54 PM]

C:\Documents and Settings\Raymond White\Start Menu\Programs\Startup\
Internet Call Manager.LNK - C:\Program Files\Internet Call Manager\ICM.EXE [18/10/2007 2:16:00 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuvtsr]
vtuvtsr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winudu32]
winudu32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"AtiCwd32"=Aticwd32.exe
"AtiQiPcl"=AtiQiPcl.exe
"LoadQM"=loadqm.exe
"TaskReg"=C:\DOWNLOADS\MORPHEUS DOWNLOADS\SUPER MARIO BROS 2 (1).EXE
"QuickTime Task"=C:\WINDOWS\SYSTEM32\qttask.exe
"webHancer Agent"="C:\Program Files\webHancer\Programs\whAgent.exe"
"New.net Startup"=rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
"Gator"="C:\Program Files\Gator.com\Gator\Gator.exe"
"Hotbar"=C:\PROGRAM FILES\IMESH\CLIENT\HBINST.EXE /Upgrade
"NAV Agent"=C:\PROGRA~1\NORTON~1\NAVAPW32.EXE


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
C:\WINDOWS\SYSTEM32\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl



– End of Deckard's System Scanner: finished at 2008-08-14 19:15:57 ————




Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
——————————————————————————–

– System Information ———————————————————-

Microsoft Windows XP Professional (build 2600)
Architecture: X86; Language: English

CPU 0: Intel Pentium III processor
Percentage of Memory in Use: 58%
Physical Memory (total/avail): 383.54 MiB / 159.49 MiB
Pagefile Memory (total/avail): 539.15 MiB / 379.62 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1948.65 MiB

A: is Removable (No Media)
C: is Fixed (FAT32) - 8.59 GiB total, 1.38 GiB free.
D: is CDROM (No Media)
E: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - QUANTUM FIREBALLP KA9.1 - 8.6 GiB - 1 partition
\PARTITION0 (bootable) - Unknown - 8.6 GiB - C:



– Security Center ————————————————————-

AUOptions is disabled.


– Environment Variables ——————————————————-

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Raymond White\Application Data
CLASSPATH=C:\Program Files\PhotoDeluxe 2.0\AdobeConnectables
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=FUTUREGEN
ComSpec=C:\WINDOWS\system32\cmd.exe
HOMEDRIVE=C:
HOMEPATH=\
LOGONSERVER=\\FUTUREGEN
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\COMMAND;C:\;C:\WINDOWS\system32\WBEM;C:\Program Files\Common Files\Adaptec Shared\System
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 7 Stepping 3, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0703
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\RAYMON~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\RAYMON~1\LOCALS~1\Temp
USERDOMAIN=FUTUREGEN
USERNAME=Raymond White
USERPROFILE=C:\Documents and Settings\Raymond White
winbootdir=C:\WINDOWS
windir=C:\WINDOWS


– User Profiles —————————————————————

Raymond White (admin)
Administrator (admin)


– Add/Remove Programs ———————————————————

–> "C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /UNINSTALL /PROMPT
Adobe Acrobat 4.0 –> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 4.0\98\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 4.0\98\Uninst.dll"
Adobe Acrobat Reader 3.01 –> C:\WINDOWS\uninst.exe -fc:\downloads\DeIsL1.isu
Adobe Flash Player 9 ActiveX –> C:\WINDOWS\System32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Flash Player ActiveX –> C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe
Adobe Shockwave Player –> C:\WINDOWS\SYSTEM32\MACROMED\SHOCKW~3\UNWISE.EXE C:\WINDOWS\SYSTEM32\MACROMED\SHOCKW~3\INSTALL.LOG
Adobe Type Manager –> C:\WINDOWS\ATMFM.EXE -U
AOpen FM56-PM 56K Modem –> infunist.exe
aspi –> MsiExec.exe /I{015E4B8A-29B5-4AE3-BD08-38220FADFF4C}
ATI mach64 Display Driver –> atiuinst.exe -uninstall
ATI Video Player –> C:\WINDOWS\IsUninst.exe -fC:\ATI\ATIDESK\Uninst.isu
Canon CanoScan Toolbox 4.1 –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BCE46757-7674-4416-BEDB-68205A60409E}\setup.exe" -l0x416
Canon i350 –> C:\WINDOWS\System32\CNMCP53.exe "-PRINTERNAMECanon i350" "-HELPERDLLC:\BJPrinter\CNMWINDOWS\Canon i350 Installer\Inst2\cnmis.dll" "-RCDLLC:\BJPrinter\CNMWINDOWS\Canon i350 Installer\Inst2\cnmi0409.dll"
CCHelp –> MsiExec.exe /I{9D1CF8B6-17B3-4832-B062-2C2DD0B57B04}
CCScore –> MsiExec.exe /I{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}
CR2 –> MsiExec.exe /I{432C3720-37BF-4BD7-8E49-F38E090246D0}
DivX 4.12 Codec –> "C:\Program Files\DivXCodec\uninstall.exe"
Easy-WebPrint –> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Canon\Easy-WebPrint\Uninst.isu"
Easy CD Creator 5 Platinum –> MsiExec.exe /I{8851E12C-0EF9-11D4-A788-009027ABA5D0}
ESSAdpt –> MsiExec.exe /I{D15E9DB5-6BEB-4534-901E-80C0A29BAB97}
ESSANUP –> MsiExec.exe /I{A6F18A67-B771-4191-8A33-36D2E742D6D9}
ESSBrwr –> MsiExec.exe /I{643EAE81-920C-4931-9F0B-4B343B225CA6}
ESSCAM –> MsiExec.exe /I{469730CC-78DF-4CD3-B286-562D459EA619}
ESSCDBK –> MsiExec.exe /I{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}
ESScore –> MsiExec.exe /I{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}
ESSgui –> MsiExec.exe /I{91517631-A9F3-4B7C-B482-43E0068FD55A}
ESShelp –> MsiExec.exe /I{87843A41-7808-4F2E-B13F-25C1E67CF2FD}
ESSini –> MsiExec.exe /I{8E92D746-CD9F-4B90-9668-42B74C14F765}
ESSPCD –> MsiExec.exe /I{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}
ESSTUTOR –> MsiExec.exe /I{CA60320D-6A16-49C8-A34F-84EEF4799567}
ESSvpaht –> MsiExec.exe /I{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}
ESSvpot –> MsiExec.exe /I{48C82F7A-F100-4DAB-A310-8E18BF2159E1}
getPlus®_ocx –> rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\inf\GETPLUSo.INF, DefaultUninstall
HijackThis 1.99.1 –> C:\Documents and Settings\Raymond White\Desktop\HijackThis.exe /uninstall
hp instant support –> C:\PROGRA~1\HEWLET~1\HPINST~1\Uninstall.exe CeS
HP Photo and Imaging 1.1 - Photosmart Cameras –> MsiExec.exe /X{1EEE2A9F-6471-42fa-8923-E8879168CE26}
Internet Call Manager –> C:\PROGRA~1\INTERN~2\UNINST~1.EXE C:\PROGRA~1\INTERN~2\INSTALL.LOG
J2SE Runtime Environment 5.0 Update 6 –> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
Java 2 Runtime Environment, SE v1.4.2_03 –> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
Kodak EasyShare software –> C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_3c0002_41f9f3\Setup.exe /APR-REMOVE
KSU –> MsiExec.exe /I{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}
Legacy 5.0 –> C:\Legacy\UNWISE.EXE /U C:\Legacy\Install.log
Microsoft Data Access Components KB870669 –> C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
Microsoft Office XP Professional with FrontPage –> MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
Microsoft Picture It! Express 7.0 –> MsiExec.exe /I{369B36BE-3D64-4641-9AEA-808D436FE130}
Microsoft Windows Journal Viewer –> MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA8}
Microsoft XML Parser and SDK –> MsiExec.exe /I{3E908702-AF35-4611-9518-955DA24B7E07}
Netscape (7.2) –> C:\WINDOWS\NSUninst.exe /ua "7.2 (en)"
Netscape SmartDownload 1.4 –> C:\WINDOWS\SYSTEM32\npnsdad.exe /u
Notifier –> MsiExec.exe /I{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}
OTtBP –> MsiExec.exe /I{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}
Outlook Express Q823353 –> C:\WINDOWS\oeuninst.exe C:\WINDOWS\INF\Q823353.inf
PCDLNCH –> MsiExec.exe /I{69BD6399-3D8F-45B7-81D9-819361F5101D}
QuickTime –> C:\WINDOWS\unvise32qt.exe C:\WINDOWS\System32\QuickTime\Uninstall.log
RootsMagic Demo –> MsiExec.exe /I{D9B4A1B1-210C-4C6A-B8D4-68739E2D5DAA}
SFR –> MsiExec.exe /I{C354C9B6-A4E0-4BB0-A368-6DC6BCA0E314}
SFR2 –> MsiExec.exe /I{ABE068DF-8DC4-4947-ABFC-DD2B40850225}
Shockwave –> C:\WINDOWS\SYSTEM32\MACROMED\SHOCKW~2\UNWISE.EXE C:\WINDOWS\SYSTEM32\MACROMED\SHOCKW~2\INSTALL.LOG
Snood –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\ENGINE\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8DCCC000-B22F-11D4-9BBB-A8791A39273D}\SETUP.EXE"
Spybot - Search & Destroy 1.4 –> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Sympatico –> C:\WINDOWS\cd32405.exe
Winamp (remove only) –> "C:\Program Files\Winamp\UninstWA.exe"
Windows Blaster Worm Removal Tool (KB833330) –> C:\WINDOWS\$NtUninstallKB833330$\spuninst\spuninst.exe
Windows Live Messenger –> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
Windows Live Sign-in Assistant –> MsiExec.exe /I{22B3CC30-77B8-419C-AA4B-F571FDF5D66D}
Windows XP Application Compatibility Update[Q319580] –> C:\WINDOWS\$NtUninstallQ319580$\spuninst\spuninst.exe
WinRAR archiver –> C:\Program Files\WinRAR\uninstall.exe
WinZip –> "C:\PROGRAM FILES\WINZIP\WINZIP32.EXE" /uninstall


– Application Event Log ——————————————————-

Event Record #/Type2390 / Error
Event Submitted/Written: 08/14/2008 06:42:00 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application explorer.exe, version 6.0.2600.0, faulting module mshtml.dll, version 6.0.2745.2800, fault address 0x0006582c.

Event Record #/Type2380 / Error
Event Submitted/Written: 08/14/2008 00:35:14 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application explorer.exe, version 6.0.2600.0, faulting module mshtml.dll, version 6.0.2745.2800, fault address 0x0006582c.

Event Record #/Type2378 / Error
Event Submitted/Written: 08/14/2008 00:32:52 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application explorer.exe, version 6.0.2600.0, faulting module mshtml.dll, version 6.0.2745.2800, fault address 0x0006582c.

Event Record #/Type2377 / Error
Event Submitted/Written: 08/13/2008 10:17:54 PM
Event ID/Source: 1000 / Windows Live Messenger
Event Description:
msnmsgr.exe8.1.178.045b12d6amsnmsgr.exe8.1.178.045b12d6a00005f712

Event Record #/Type2367 / Warning
Event Submitted/Written: 08/13/2008 00:58:51 AM
Event ID/Source: 1524 / Userenv
Event Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.



– Security Event Log ———————————————————-

No Errors/Warnings found.


– System Event Log ————————————————————

Event Record #/Type212696 / Error
Event Submitted/Written: 08/14/2008 06:34:36 PM
Event ID/Source: 7026 / Service Control Manager
Event Description:
The following boot-start or system-start driver(s) failed to load:
eeCtrl

Event Record #/Type212695 / Error
Event Submitted/Written: 08/14/2008 06:34:36 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The ScsiAccess service failed to start due to the following error:
%%2

Event Record #/Type212694 / Error
Event Submitted/Written: 08/14/2008 06:34:36 PM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The IPSEC Services service terminated with the following error:
%%1747

Event Record #/Type212667 / Error
Event Submitted/Written: 08/14/2008 04:28:44 PM
Event ID/Source: 7026 / Service Control Manager
Event Description:
The following boot-start or system-start driver(s) failed to load:
eeCtrl

Event Record #/Type212666 / Error
Event Submitted/Written: 08/14/2008 04:28:44 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The ScsiAccess service failed to start due to the following error:
%%2



– End of Deckard's System Scanner: finished at 2008-08-14 19:15:57 ————
Hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9A853E36-4A35-4DBF-9C03-AD9423798E35} - (no file)
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O20 - Winlogon Notify: vtuvtsr - vtuvtsr.dll (file missing)
O20 - Winlogon Notify: winudu32 - winudu32.dll (file missing)


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\WINDOWS\System32\dmatd.exe
    C:\WINDOWS\System32\htzqt.exe
    C:\DOCUME~1\RAYMON~1\MYDOCU~1\MCROSO~1.NET\wuauclt.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MSWin.exe
    C:\WINDOWS\System32\ipmon.exe
    purity 
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.



Run DSS again, using these instructions:

Click START> Run - then copy the following bold blue text and paste it into the Run box & click OK

"%userprofile%\desktop\dss.exe" /daft

Read the disclaimer and click OK.

Click on Scan.

Place a checkmark next to the entries displayed when the scan is finished then Click on Fix.

Repeat the scan; you should get a message "All Associations OK!"

Next, click Save Log, and post this log in your next reply.



Also post a new DSS log
Explorer killed successfully
File/Folder C:\WINDOWS\System32\dmatd.exe not found.
File/Folder C:\WINDOWS\System32\htzqt.exe not found.
File/Folder C:\DOCUME~1\RAYMON~1\MYDOCU~1\MCROSO~1.NET\wuauclt.exe not found.
File/Folder C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MSWin.exe not found.
File/Folder C:\WINDOWS\System32\ipmon.exe not found.
< purity >
C:\WINDOWS\Fοnts moved successfully.
C:\WINDOWS\system32\аѕsembly moved successfully.
C:\WINDOWS\system32\Fоnts moved successfully.
C:\WINDOWS\system32\ѕуstem moved successfully.
C:\WINDOWS\system32\sуstem moved successfully.
C:\WINDOWS\system32\ѕуstem32 moved successfully.
C:\WINDOWS\system32\Таsks moved successfully.
C:\WINDOWS\system32\WіnSxS moved successfully.
C:\Program Files\Τаsks moved successfully.
C:\Program Files\Common Files\AрpPatch moved successfully.
C:\Program Files\Common Files\аѕsembly moved successfully.
C:\Documents and Settings\Raymond White\My Documents\Mіcrosoft.NET\MCROSO~1.NET moved successfully.
C:\Documents and Settings\Raymond White\My Documents\Mіcrosoft.NET moved successfully.
C:\Documents and Settings\Raymond White\My Documents\Μicrosoft.NET moved successfully.
C:\Documents and Settings\Raymond White\My Documents\Τаsks moved successfully.
C:\Documents and Settings\Raymond White\Application Data\Mіcrosoft moved successfully.
C:\Documents and Settings\Raymond White\Application Data\sуmbols moved successfully.
< EmptyTemp >
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08142008_215918



Deckard's System Scanner v20071014.68
Run by [removed] on 2008-08-14 22:08:29
Computer is in Normal Mode.
——————————————————————————–

Total Physical Memory: 384 MiB (512 MiB recommended).


– HijackThis (run as Raymond White.exe) —————————————

Unable to find log (file not found); running clone.
– HijackThis Clone ————————————————————


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-08-14 22:09:32
Platform: Windows XP (5.01.2600)
MSIE: Internet Explorer (6.00.2600.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\SYSTEM32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\SYSTEM32\services.exe
C:\WINDOWS\SYSTEM32\lsass.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\spoolsv.exe
C:\WINDOWS\SYSTEM32\DRIVERS\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\WgaTray.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\Directcd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\SYSTEM32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Call Manager\ICM.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Raymond White\Desktop\dss.exe
C:\Documents and Settings\Raymond White\Desktop\HijackThis(spyware remover)\Raymond White.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.microsoft.com/search/lobby/search.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.ca
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Internet Call Manager.LNK = C:\Program Files\Internet Call Manager\ICM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {00000055-0000-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/fhgax.CAB
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {31564D57-0000-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/wmvax.cab
O16 - DPF: {32564D57-0000-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/wmv8ax.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1136658589914
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} () - http://v4.windowsupdate.microsoft.com/CAB/…7622.4436226852
O16 - DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} () - http://windowsupdate.microsoft.com/R999/V3…en/actsetup.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\SYSTEM32\msvidctl.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Filter: application/x-icq - {db40c160-09a1-11d3-baf2-000000000000} - C:\Program Files\ICQ\IExplorerMime.dll (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\SYSTEM32\DRIVERS\KodakCCS.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE


–
End of file - 7477 bytes

– Files created between 2008-07-14 and 2008-08-14 —————————–

2008-08-13 10:33:54 0 d——– C:\VundoFix Backups


– Find3M Report —————————————————————

2008-06-26 16:38:10 0 d——– C:\Program Files\ArcSoft
2008-06-26 15:34:38 0 d——– C:\Documents and Settings\Raymond White\Application Data\Canon


– Registry Dump —————————————————————

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"="SysTray.Exe" [23/08/2001 12:00 PM C:\WINDOWS\SYSTEM32\systray.exe]
"AdaptecDirectCD"="C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [19/07/2002 11:16 PM]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [17/04/2002 10:42 AM]
"CamMonitor"="C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [11/07/2002 04:24 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [10/11/2005 01:03 PM]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [11/02/2003 08:00 AM]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" []
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [23/08/2001 12:00 PM]
"@"="" []
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [19/01/2007 12:54 PM]

C:\Documents and Settings\Raymond White\Start Menu\Programs\Startup\
Internet Call Manager.LNK - C:\Program Files\Internet Call Manager\ICM.EXE [18/10/2007 2:16:00 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"AtiCwd32"=Aticwd32.exe
"AtiQiPcl"=AtiQiPcl.exe
"LoadQM"=loadqm.exe
"TaskReg"=C:\DOWNLOADS\MORPHEUS DOWNLOADS\SUPER MARIO BROS 2 (1).EXE
"QuickTime Task"=C:\WINDOWS\SYSTEM32\qttask.exe
"webHancer Agent"="C:\Program Files\webHancer\Programs\whAgent.exe"
"New.net Startup"=rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
"Gator"="C:\Program Files\Gator.com\Gator\Gator.exe"
"Hotbar"=C:\PROGRAM FILES\IMESH\CLIENT\HBINST.EXE /Upgrade
"NAV Agent"=C:\PROGRA~1\NORTON~1\NAVAPW32.EXE


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
C:\WINDOWS\SYSTEM32\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl



– End of Deckard's System Scanner: finished at 2008-08-14 22:10:51 ————
Hello

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\Program Files\webHancer
    C:\PROGRA~1\NEWDOT~1
    C:\PROGRAM FILES\IMESH\CLIENT\HBINST.EXE
    C:\Program Files\Gator.com
    purity 
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.



Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe



Now we need to fix your problems by making a .reg file. Copy the code below into a Notepad file. Name the file as fix.reg, change the "Save as Type" to "All files" and save it on the desktop.

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"webHancer Agent"=-
"New.net Startup"=-
"Hotbar"=-
"Gator"=-


Then double click on the fix.reg file, when it prompts to merge click "Yes".




Please run the MGA Diagnostic Tool and post back the report it shall produce:
  • Download MGADiag to your desktop.
  • Double-click on MGADiag.exe to launch the program
  • Click "Continue"
  • Ensure that the "Windows" tab is selected (it should be by default).
  • Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.
  • Paste the MGA Diagnostic Report back here in your next reply.


Also post a new DSS log
I did everything to said, but either the link for the mga tool is dead or my browser is not allowing me to download it? It was coming up as if it didn't exist or work.

Explorer killed successfully
File/Folder C:\Program Files\webHancer not found.
File/Folder C:\PROGRA~1\NEWDOT~1 not found.
File/Folder C:\PROGRAM FILES\IMESH\CLIENT\HBINST.EXE not found.
File/Folder C:\Program Files\Gator.com not found.
< purity >
< EmptyTemp >
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08152008_182333


Deckard's System Scanner v20071014.68
Run by [removed] on 2008-08-16 00:18:43
Computer is in Normal Mode.
——————————————————————————–

Total Physical Memory: 384 MiB (512 MiB recommended).


– HijackThis (run as Raymond White.exe) —————————————

Unable to find log (file not found); running clone.
– HijackThis Clone ————————————————————


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-08-16 00:18:46
Platform: Windows XP (5.01.2600)
MSIE: Internet Explorer (6.00.2600.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\SYSTEM32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\SYSTEM32\services.exe
C:\WINDOWS\SYSTEM32\lsass.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\spoolsv.exe
C:\WINDOWS\SYSTEM32\DRIVERS\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\SYSTEM32\WgaTray.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\Directcd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\SYSTEM32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Call Manager\ICM.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Documents and Settings\Raymond White\Desktop\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.microsoft.com/search/lobby/search.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.ca
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Internet Call Manager.LNK = C:\Program Files\Internet Call Manager\ICM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {00000055-0000-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/fhgax.CAB
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {31564D57-0000-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/wmvax.cab
O16 - DPF: {32564D57-0000-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/wmv8ax.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1136658589914
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} () - http://v4.windowsupdate.microsoft.com/CAB/…7622.4436226852
O16 - DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} () - http://windowsupdate.microsoft.com/R999/V3…en/actsetup.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{63E9BA26-3749-4A06-8022-78E155A92AE6}: NameServer = 85.255.115.22 85.255.112.101
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\SYSTEM32\msvidctl.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Filter: application/x-icq - {db40c160-09a1-11d3-baf2-000000000000} - C:\Program Files\ICQ\IExplorerMime.dll (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\SYSTEM32\DRIVERS\KodakCCS.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE


–
End of file - 7505 bytes

– Files created between 2008-07-16 and 2008-08-16 —————————–

2008-08-14 23:43:04 0 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-14 23:42:44 0 d——– C:\Program Files\SpywareBlaster
2008-08-13 10:33:54 0 d——– C:\VundoFix Backups


– Find3M Report —————————————————————

2008-06-26 16:38:10 0 d——– C:\Program Files\ArcSoft
2008-06-26 15:34:38 0 d——– C:\Documents and Settings\Raymond White\Application Data\Canon


– Registry Dump —————————————————————

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"="SysTray.Exe" [23/08/2001 12:00 PM C:\WINDOWS\SYSTEM32\systray.exe]
"AdaptecDirectCD"="C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [19/07/2002 11:16 PM]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [17/04/2002 10:42 AM]
"CamMonitor"="C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [11/07/2002 04:24 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [10/11/2005 01:03 PM]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [11/02/2003 08:00 AM]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" []
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [23/08/2001 12:00 PM]
"@"="" []
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [19/01/2007 12:54 PM]

C:\Documents and Settings\Raymond White\Start Menu\Programs\Startup\
Internet Call Manager.LNK - C:\Program Files\Internet Call Manager\ICM.EXE [18/10/2007 2:16:00 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"AtiCwd32"=Aticwd32.exe
"AtiQiPcl"=AtiQiPcl.exe
"LoadQM"=loadqm.exe
"TaskReg"=C:\DOWNLOADS\MORPHEUS DOWNLOADS\SUPER MARIO BROS 2 (1).EXE
"QuickTime Task"=C:\WINDOWS\SYSTEM32\qttask.exe
"NAV Agent"=C:\PROGRA~1\NORTON~1\NAVAPW32.EXE


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
C:\WINDOWS\SYSTEM32\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl



– End of Deckard's System Scanner: finished at 2008-08-16 00:19:55 ————
Make sure to try it in Internet Explorer

Please download Runscanner to your desktop and run it.
  • When the first page comes up select Beginner Mode
  • On the next page select Save a binary .Run file (Recommended) then click Start full scan at the top.
  • At this time Runscanner.exe may request access to the Internet through your firewall please allow it to do so, it will then run for two or three minutes.
  • On completion it will ask for a location to save the file and a name. It will do this for both the .run file and the log file
  • Call the .run file "Select a name" and save it to your desktop. You will see the .run file on your desktop. Upload that file here.




Please do an online scan with Kaspersky WebScanner

Make sure you are using Internet Explorer for this. Click on Kaspersky Online Scanner and click Accept

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.



If WGA Test fails again try this link

http://www.microsoft.com/resources/howtote…ion%20Assistant

And tell me the results
One thing I forgot to mention is anytime I go to reply in Internet Explorer I get a system error and Explorer(not IE) has to restart.I wasn't able to run Kaspersky WebScanner because I do not have Java 1.5 or higher and when I went to download it, it would always freeze. The WGA test also wouldn't work still. I think it may be because it says my Windows is not genuine.


Runscanner logfile http://www.runscanner.net

* = signed file
- = file not found

000 General info
—————-
Computer name : FUTUREGEN
Creation time : 16/08/2008 10:15:47 AM
Hosts <> 127.0.0.1 : 0
Hosts file location : %SystemRoot%\System32\drivers\etc
IE version : 6.0.2600.0000
OS : Microsoft Windows XP
OS Build : 2600
OS SP :
RunScanner Version : 1.6.3.0
User Language : English (Canada)
User rights : Administrator
Windows folder : C:\WINDOWS

001 Running processes
———————
* c:\windows\system32\csrss.exe (Microsoft Corporation)
* c:\windows\system32\ctfmon.exe (Microsoft Corporation)
c:\program files\adaptec\easy cd creator 5\directcd\directcd.exe (Roxio)
* c:\windows\system32\svchost.exe (Microsoft Corporation)
* c:\windows\system32\svchost.exe (Microsoft Corporation)
* c:\windows\system32\svchost.exe (Microsoft Corporation)
* c:\windows\system32\svchost.exe (Microsoft Corporation)
* c:\windows\system32\svchost.exe (Microsoft Corporation)
c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe (Hewlett-Packard)
c:\program files\hewlett-packard\hp share-to-web\hpgs2wnf.exe
c:\program files\hewlett-packard\digital imaging\unload\hpqcmon.exe
c:\program files\internet call manager\icm.exe (InfoInterActive Corp.)
c:\program files\java\jre1.5.0_06\bin\jusched.exe (Sun Microsystems, Inc.)
* c:\windows\system32\drivers\kodakccs.exe (Eastman Kodak Company)
* c:\windows\system32\lsass.exe (Microsoft Corporation)
c:\program files\common files\microsoft shared\vs7debug\mdm.exe (Microsoft Corporation)
* c:\program files\msn messenger\msnmsgr.exe (Microsoft Corporation)
c:\program files\common files\microsoft shared\works shared\wkufind.exe (Microsoft® Corporation)
* c:\documents and settings\raymond white\desktop\runscanner.exe (Runscanner.net)
* c:\windows\system32\services.exe (Microsoft Corporation)
* c:\windows\system32\spoolsv.exe (Microsoft Corporation)
* c:\windows\explorer.exe (Microsoft Corporation)
* c:\windows\system32\wgatray.exe (Microsoft Corporation)
* c:\windows\system32\winlogon.exe (Microsoft Corporation)
* c:\windows\system32\smss.exe (Microsoft Corporation)

002 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (+subkeys)
—————————————————————–
c:\program files\adaptec\easy cd creator 5\directcd\directcd.exe (Roxio)
c:\program files\hewlett-packard\digital imaging\unload\hpqcmon.exe
c:\program files\common files\microsoft shared\works shared\wkufind.exe (Microsoft® Corporation)
c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe (Hewlett-Packard)
c:\program files\java\jre1.5.0_06\bin\jusched.exe (Sun Microsystems, Inc.)
- c:\progra~1\symnet~1\sndmon.exe

004 C:\Documents and Settings\Raymond White\Start Menu\Programs\Startup
———————————————————————–
c:\progra~1\intern~2\icm.exe (InfoInterActive Corp.)

010 HKLM\SYSTEM\CurrentControlSet\Services (Services)
—————————————————–
c:\program files\common files\microsoft shared\vs7debug\mdm.exe (Machine Debug Manager)
- c:\windows\system32\scsiaccess.exe (ScsiAccess)

011 HKLM\SYSTEM\CurrentControlSet\Services (drivers)
—————————————————-
c:\windows\system32\drivers\cdr4_xp.sys (Cdr4_xp)
c:\windows\system32\drivers\cdralw2k.sys (Cdralw2k)
c:\windows\system32\drivers\cdudf_xp.sys (cdudf_XP)
- c:\windows\system32\drivers\changer.sys (Changer)
c:\windows\system32\drivers\dvd_2k.sys (dvd_2K)
c:\windows\system32\giveio.sys (giveio)
- c:\windows\system32\drivers\i2omgmt.sys (i2omgmt)
- c:\windows\system32\drivers\lbrtfdc.sys (lbrtfdc)
c:\windows\system32\drivers\mmc_2k.sys (mmc_2K)
c:\windows\system32\drivers\mxlw2k.sys (MxlW2k)
- c:\windows\system32\drivers\pcidump.sys (PCIDump)
- c:\windows\system32\drivers\pdcomp.sys (PDCOMP)
- c:\windows\system32\drivers\pdframe.sys (PDFRAME)
- c:\windows\system32\drivers\pdreli.sys (PDRELI)
- c:\windows\system32\drivers\pdrframe.sys (PDRFRAME)
c:\windows\system32\drivers\pwd_2k.sys (pwd_2K)
C:\WINDOWS\system32\drivers\pxhelp20.sys (PxHelp20)
c:\windows\system32\drivers\sbcphid.sys (SbcpHid)
- c:\program files\common files\symantec shared\eengine\eectrl.sys (Symantec Eraser Control driver)
- c:\program files\symantec\symevent.sys (SymEvent)
- c:\progra~1\common~1\symant~1\symcdata\ids-di~1\20060322.078\symidsco.sys (SYMIDSCO)
c:\windows\system32\drivers\udfreadr_xp.sys (UdfReadr_xp)
- c:\windows\system32\drivers\wdica.sys (WDICA)

030 HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
——————————————
- c:\program files\icq\iexplorermime.dll {db40c160-09a1-11d3-baf2-000000000000}

031 HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
——————————————-
c:\program files\common files\system\ole db\msdaipp.dll (Microsoft Corporation) {E1D2BF42-A96B-11d1-9C6B-0000F875AC61}
c:\program files\common files\system\ole db\msdaipp.dll (Microsoft Corporation) {E1D2BF42-A96B-11d1-9C6B-0000F875AC61}
c:\program files\common files\microsoft shared\web folders\pkmcdo.dll (Microsoft Corporation) {CD00020A-8B95-11D1-82DB-00C04FB1625D}
c:\program files\common files\microsoft shared\information retrieval\msitss.dll (Microsoft Corporation) {0A9007C0-4076-11D3-8789-0000F8105754}
c:\program files\common files\system\ole db\msdaipp.dll (Microsoft Corporation) {E1D2BF40-A96B-11d1-9C6B-0000F875AC61}

035 HKLM-HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components
——————————————————————
c:\windows\system32\updcrl.exe (Microsoft Corporation) {9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}
- rundll setupx.dll,installhinfsection powercfg.user 0 powercfg.inf {CA0A4247-44BE-11d1-A005-00805F8ABE06}

047 Trusted zones
—————–
Zone: : msn

052 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
———————————————————————————-
c:\program files\java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.) {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}

061 HKLM-HCKU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
———————————————————————————
c:\progra~1\adaptec\easycd~1\directcd\shellex.dll (Roxio) {5E44E225-A408-11CF-B581-008029601108}
c:\windows\system32\thumbvw.dll (Microsoft Corporation) {8DE56A0D-E58B-41FE-9F80-3563CDCB2C22}
- deskpan.dll {42071714-76d4-11d1-8b24-00a0c9068ff3}
c:\program files\icq\icqshell.dll {f802f260-519b-11d1-bb5d-0060974c6013}
c:\program files\common files\kodak\ifscore\kodakshx.dll (Eastman Kodak Company) {acb4a560-3606-11d3-aef4-00104bd0f92d}
c:\windows\system32\thumbvw.dll (Microsoft Corporation) {8BEBB290-52D0-11D0-B7F4-00C04FD706EC}
c:\progra~1\common~1\micros~1\webfol~1\msonsext.dll (Microsoft Corporation) {BDEADF00-C265-11D0-BCED-00A0C90AB50F}

100 Internet Explorer settings
——————————
Default_Page_URL HKLM : http://www.google.ca
SearchAssistant HKCU : http://ie.search.msn.com
SearchUrl HKCU : http://home.microsoft.com/access/autosearch.asp?p=%s
Start Page HKCU : http://www.google.ca/

104 HKLM\Software\Microsoft\Code Store Database\Distribution Units
——————————————————————
GUID / CLSID not found {00000055-0000-0010-8000-00AA00389B71}
c:\windows\system32\qtplugin.ocx (Apple Computer, Inc.) {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
- c:\windows\downlo~1\ewidoo~1.dll {193C772A-87BE-4B19-A7BB-445B226FE9A1}
- c:\windows\downloaded program files\minesweeper.dll {2917297F-F02B-4B9D-81DF-494B6333150B}
GUID / CLSID not found {31564D57-0000-0010-8000-00AA00389B71}
GUID / CLSID not found {32564D57-0000-0010-8000-00AA00389B71}
GUID / CLSID not found {33564D57-0000-0010-8000-00AA00389B71}
GUID / CLSID not found {33564D57-9980-0010-8000-00AA00389B71}
- c:\windows\downloaded program files\rufsi.dll {644E432F-49D3-41A1-8DD5-E099162EEEC5}
c:\program files\java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.) {8AD9C840-044E-11D1-B3E9-00805F499D93}
- c:\windows\downloaded program files\messengerstatsclient.dll {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
GUID / CLSID not found {9F1C11AA-197B-4942-BA54-47A8489BB47F}
c:\program files\java\j2re1.4.2_03\bin\npjpi142_03.dll (JavaSoft / Sun Microsystems, Inc.) {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
c:\program files\java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.) {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
c:\program files\java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.) {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
GUID / CLSID not found {CEBC955E-58AF-11D2-A30A-00A0C903492B}
- c:\windows\downloaded program files\gp.ocx {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7}
GUID / CLSID not found Internet Explorer Classes for Java

105 HKCU\Software\Microsoft\Internet Explorer\MenuExt
—————————————————–
E&xport to Microsoft Excel : res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

120 Domain/DNS hijacking
————————
NameServer {63E9BA26-3749-4A06-8022-78E155A92AE6} : 85.255.115.22 85.255.112.101

173 HKCR\*\shellex\ContextMenuHandlers
————————————–
c:\program files\icq\icqshell.dll {f802f260-519b-11d1-bb5d-0060974c6013}
- c:\downloads\incredimail\incredimail\bin\imshext.dll {F8984111-38B6-11D5-8725-0050DA2761C4}
c:\progra~1\winzip\wzshlstb.dll (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
C:\WINDOWS\System32\shellwp.dll (Corel Corporation Limited)

221 HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers
——————————————————-
c:\program files\icq\icqshell.dll {f802f260-519b-11d1-bb5d-0060974c6013}
- c:\downloads\incredimail\incredimail\bin\imshext.dll {F8984111-38B6-11D5-8725-0050DA2761C4}
c:\progra~1\winzip\wzshlstb.dll (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
C:\WINDOWS\System32\shellwp.dll (Corel Corporation Limited)

225 HKCU\Software\Classes\Folder\ShellEx\ContextMenuHandlers
————————————————————
c:\progra~1\winzip\wzshlstb.dll (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
c:\progra~1\winzip\wzshlstb.dll (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}

227 HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers
—————————————————————
c:\program files\icq\icqshell.dll {f802f260-519b-11d1-bb5d-0060974c6013}
c:\progra~1\winzip\wzshlstb.dll (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
One thing I forgot to mention is anytime I go to reply in Internet Explorer I get a system error and Explorer(not IE) has to restart.I wasn't able to run Kaspersky WebScanner because I do not have Java 1.5 or higher and when I went to download it, it would always freeze. The WGA test also wouldn't work still. I think it may be because it says my Windows is not genuine. I am using Netscape navigator as my browser and it has an endless loadtime when I try to upload the .run file too.


Runscanner logfile http://www.runscanner.net

* = signed file
- = file not found

000 General info
—————-
Computer name : FUTUREGEN
Creation time : 16/08/2008 10:15:47 AM
Hosts <> 127.0.0.1 : 0
Hosts file location : %SystemRoot%\System32\drivers\etc
IE version : 6.0.2600.0000
OS : Microsoft Windows XP
OS Build : 2600
OS SP :
RunScanner Version : 1.6.3.0
User Language : English (Canada)
User rights : Administrator
Windows folder : C:\WINDOWS

001 Running processes
———————
* c:\windows\system32\csrss.exe (Microsoft Corporation)
* c:\windows\system32\ctfmon.exe (Microsoft Corporation)
c:\program files\adaptec\easy cd creator 5\directcd\directcd.exe (Roxio)
* c:\windows\system32\svchost.exe (Microsoft Corporation)
* c:\windows\system32\svchost.exe (Microsoft Corporation)
* c:\windows\system32\svchost.exe (Microsoft Corporation)
* c:\windows\system32\svchost.exe (Microsoft Corporation)
* c:\windows\system32\svchost.exe (Microsoft Corporation)
c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe (Hewlett-Packard)
c:\program files\hewlett-packard\hp share-to-web\hpgs2wnf.exe
c:\program files\hewlett-packard\digital imaging\unload\hpqcmon.exe
c:\program files\internet call manager\icm.exe (InfoInterActive Corp.)
c:\program files\java\jre1.5.0_06\bin\jusched.exe (Sun Microsystems, Inc.)
* c:\windows\system32\drivers\kodakccs.exe (Eastman Kodak Company)
* c:\windows\system32\lsass.exe (Microsoft Corporation)
c:\program files\common files\microsoft shared\vs7debug\mdm.exe (Microsoft Corporation)
* c:\program files\msn messenger\msnmsgr.exe (Microsoft Corporation)
c:\program files\common files\microsoft shared\works shared\wkufind.exe (Microsoft® Corporation)
* c:\documents and settings\raymond white\desktop\runscanner.exe (Runscanner.net)
* c:\windows\system32\services.exe (Microsoft Corporation)
* c:\windows\system32\spoolsv.exe (Microsoft Corporation)
* c:\windows\explorer.exe (Microsoft Corporation)
* c:\windows\system32\wgatray.exe (Microsoft Corporation)
* c:\windows\system32\winlogon.exe (Microsoft Corporation)
* c:\windows\system32\smss.exe (Microsoft Corporation)

002 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (+subkeys)
—————————————————————–
c:\program files\adaptec\easy cd creator 5\directcd\directcd.exe (Roxio)
c:\program files\hewlett-packard\digital imaging\unload\hpqcmon.exe
c:\program files\common files\microsoft shared\works shared\wkufind.exe (Microsoft® Corporation)
c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe (Hewlett-Packard)
c:\program files\java\jre1.5.0_06\bin\jusched.exe (Sun Microsystems, Inc.)
- c:\progra~1\symnet~1\sndmon.exe

004 C:\Documents and Settings\Raymond White\Start Menu\Programs\Startup
———————————————————————–
c:\progra~1\intern~2\icm.exe (InfoInterActive Corp.)

010 HKLM\SYSTEM\CurrentControlSet\Services (Services)
—————————————————–
c:\program files\common files\microsoft shared\vs7debug\mdm.exe (Machine Debug Manager)
- c:\windows\system32\scsiaccess.exe (ScsiAccess)

011 HKLM\SYSTEM\CurrentControlSet\Services (drivers)
—————————————————-
c:\windows\system32\drivers\cdr4_xp.sys (Cdr4_xp)
c:\windows\system32\drivers\cdralw2k.sys (Cdralw2k)
c:\windows\system32\drivers\cdudf_xp.sys (cdudf_XP)
- c:\windows\system32\drivers\changer.sys (Changer)
c:\windows\system32\drivers\dvd_2k.sys (dvd_2K)
c:\windows\system32\giveio.sys (giveio)
- c:\windows\system32\drivers\i2omgmt.sys (i2omgmt)
- c:\windows\system32\drivers\lbrtfdc.sys (lbrtfdc)
c:\windows\system32\drivers\mmc_2k.sys (mmc_2K)
c:\windows\system32\drivers\mxlw2k.sys (MxlW2k)
- c:\windows\system32\drivers\pcidump.sys (PCIDump)
- c:\windows\system32\drivers\pdcomp.sys (PDCOMP)
- c:\windows\system32\drivers\pdframe.sys (PDFRAME)
- c:\windows\system32\drivers\pdreli.sys (PDRELI)
- c:\windows\system32\drivers\pdrframe.sys (PDRFRAME)
c:\windows\system32\drivers\pwd_2k.sys (pwd_2K)
C:\WINDOWS\system32\drivers\pxhelp20.sys (PxHelp20)
c:\windows\system32\drivers\sbcphid.sys (SbcpHid)
- c:\program files\common files\symantec shared\eengine\eectrl.sys (Symantec Eraser Control driver)
- c:\program files\symantec\symevent.sys (SymEvent)
- c:\progra~1\common~1\symant~1\symcdata\ids-di~1\20060322.078\symidsco.sys (SYMIDSCO)
c:\windows\system32\drivers\udfreadr_xp.sys (UdfReadr_xp)
- c:\windows\system32\drivers\wdica.sys (WDICA)

030 HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
——————————————
- c:\program files\icq\iexplorermime.dll {db40c160-09a1-11d3-baf2-000000000000}

031 HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
——————————————-
c:\program files\common files\system\ole db\msdaipp.dll (Microsoft Corporation) {E1D2BF42-A96B-11d1-9C6B-0000F875AC61}
c:\program files\common files\system\ole db\msdaipp.dll (Microsoft Corporation) {E1D2BF42-A96B-11d1-9C6B-0000F875AC61}
c:\program files\common files\microsoft shared\web folders\pkmcdo.dll (Microsoft Corporation) {CD00020A-8B95-11D1-82DB-00C04FB1625D}
c:\program files\common files\microsoft shared\information retrieval\msitss.dll (Microsoft Corporation) {0A9007C0-4076-11D3-8789-0000F8105754}
c:\program files\common files\system\ole db\msdaipp.dll (Microsoft Corporation) {E1D2BF40-A96B-11d1-9C6B-0000F875AC61}

035 HKLM-HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components
——————————————————————
c:\windows\system32\updcrl.exe (Microsoft Corporation) {9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}
- rundll setupx.dll,installhinfsection powercfg.user 0 powercfg.inf {CA0A4247-44BE-11d1-A005-00805F8ABE06}

047 Trusted zones
—————–
Zone: : msn

052 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
———————————————————————————-
c:\program files\java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.) {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}

061 HKLM-HCKU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
———————————————————————————
c:\progra~1\adaptec\easycd~1\directcd\shellex.dll (Roxio) {5E44E225-A408-11CF-B581-008029601108}
c:\windows\system32\thumbvw.dll (Microsoft Corporation) {8DE56A0D-E58B-41FE-9F80-3563CDCB2C22}
- deskpan.dll {42071714-76d4-11d1-8b24-00a0c9068ff3}
c:\program files\icq\icqshell.dll {f802f260-519b-11d1-bb5d-0060974c6013}
c:\program files\common files\kodak\ifscore\kodakshx.dll (Eastman Kodak Company) {acb4a560-3606-11d3-aef4-00104bd0f92d}
c:\windows\system32\thumbvw.dll (Microsoft Corporation) {8BEBB290-52D0-11D0-B7F4-00C04FD706EC}
c:\progra~1\common~1\micros~1\webfol~1\msonsext.dll (Microsoft Corporation) {BDEADF00-C265-11D0-BCED-00A0C90AB50F}

100 Internet Explorer settings
——————————
Default_Page_URL HKLM : http://www.google.ca
SearchAssistant HKCU : http://ie.search.msn.com
SearchUrl HKCU : http://home.microsoft.com/access/autosearch.asp?p=%s
Start Page HKCU : http://www.google.ca/

104 HKLM\Software\Microsoft\Code Store Database\Distribution Units
——————————————————————
GUID / CLSID not found {00000055-0000-0010-8000-00AA00389B71}
c:\windows\system32\qtplugin.ocx (Apple Computer, Inc.) {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
- c:\windows\downlo~1\ewidoo~1.dll {193C772A-87BE-4B19-A7BB-445B226FE9A1}
- c:\windows\downloaded program files\minesweeper.dll {2917297F-F02B-4B9D-81DF-494B6333150B}
GUID / CLSID not found {31564D57-0000-0010-8000-00AA00389B71}
GUID / CLSID not found {32564D57-0000-0010-8000-00AA00389B71}
GUID / CLSID not found {33564D57-0000-0010-8000-00AA00389B71}
GUID / CLSID not found {33564D57-9980-0010-8000-00AA00389B71}
- c:\windows\downloaded program files\rufsi.dll {644E432F-49D3-41A1-8DD5-E099162EEEC5}
c:\program files\java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.) {8AD9C840-044E-11D1-B3E9-00805F499D93}
- c:\windows\downloaded program files\messengerstatsclient.dll {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
GUID / CLSID not found {9F1C11AA-197B-4942-BA54-47A8489BB47F}
c:\program files\java\j2re1.4.2_03\bin\npjpi142_03.dll (JavaSoft / Sun Microsystems, Inc.) {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
c:\program files\java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.) {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
c:\program files\java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.) {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
GUID / CLSID not found {CEBC955E-58AF-11D2-A30A-00A0C903492B}
- c:\windows\downloaded program files\gp.ocx {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7}
GUID / CLSID not found Internet Explorer Classes for Java

105 HKCU\Software\Microsoft\Internet Explorer\MenuExt
—————————————————–
E&xport to Microsoft Excel : res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

120 Domain/DNS hijacking
————————
NameServer {63E9BA26-3749-4A06-8022-78E155A92AE6} : 85.255.115.22 85.255.112.101

173 HKCR\*\shellex\ContextMenuHandlers
————————————–
c:\program files\icq\icqshell.dll {f802f260-519b-11d1-bb5d-0060974c6013}
- c:\downloads\incredimail\incredimail\bin\imshext.dll {F8984111-38B6-11D5-8725-0050DA2761C4}
c:\progra~1\winzip\wzshlstb.dll (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
C:\WINDOWS\System32\shellwp.dll (Corel Corporation Limited)

221 HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers
——————————————————-
c:\program files\icq\icqshell.dll {f802f260-519b-11d1-bb5d-0060974c6013}
- c:\downloads\incredimail\incredimail\bin\imshext.dll {F8984111-38B6-11D5-8725-0050DA2761C4}
c:\progra~1\winzip\wzshlstb.dll (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
C:\WINDOWS\System32\shellwp.dll (Corel Corporation Limited)

225 HKCU\Software\Classes\Folder\ShellEx\ContextMenuHandlers
————————————————————
c:\progra~1\winzip\wzshlstb.dll (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
c:\progra~1\winzip\wzshlstb.dll (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}

227 HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers
—————————————————————
c:\program files\icq\icqshell.dll {f802f260-519b-11d1-bb5d-0060974c6013}
c:\progra~1\winzip\wzshlstb.dll (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
I tried attaching the file several times but it just won't attach, I let it run for over an hour once and wouldn't attach, I'm not sure why. As for Windows I'm quite sure it isn't legit.
Honestly we cant help with fake OS

Using an unpatched Windows XP with no service packs is so dangerous and pointless for us fixing up your PC since it is highly likely it will be re-infected very soon

Here are some tips to keep your PC clean, that is the only help I can offer


Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:

SpywareBlaster protects against bad ActiveX
IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here

* SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program or there will be a conflict.

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here

* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here

Thank you for your patience, and performing all of the procedures requested.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI