This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help with Adware.Agent.BN virus please!

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I've been infected with Adware.Agent.BN.
Tried to remove it with Spyware Doctor, but it returns.
McAfee doesn't even find the infection.

Causes false Window Security Alert pop-ups, redirects home page, etc.


Please advice me to fix this problem. I believe that I need to post a HickjackThis Log.
Here it goes:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:45: VIRUS ALERT!, on 8/25/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\WINDOWS\vVX3000.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Spyware Doctor\pctsGui.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=Ty…fl1zpkUBc-UGu3g
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {74CE56FF-3469-47C0-93E1-D0CB8B203EA9} - C:\WINDOWS\system32\vtUnOEUm.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O2 - BHO: CPub Object - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: QXK Olive - {E350B1C6-A8DC-4EEF-90DB-61DCAE9D1B67} - C:\WINDOWS\rodqgpvlkoa.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
O3 - Toolbar: qalkfxor - {18C388BB-5014-4906-AE38-E62BA5AA7387} - C:\WINDOWS\qalkfxor.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [Vistadrv] C:\WINDOWS\system32\drive\vsdrv.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open using &Advanced JPEG Compressor - C:\Program Files\Advanced JPEG Compressor\ajcieex.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: hsolxj.dll nyohpl.dll gyshja.dll mxymot.dll
O20 - Winlogon Notify: vtUnOEUm - C:\WINDOWS\SYSTEM32\vtUnOEUm.dll
O21 - SSODL: pdoskegl - {D9889943-6B58-4631-A57D-7801CDADEF72} - C:\WINDOWS\pdoskegl.dll
O21 - SSODL: rqbmvpso - {ED710DA2-0DB9-4574-8DD7-6F8C516CB162} - C:\WINDOWS\rqbmvpso.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: P4P Service - Unknown owner - C:\Program Files\Common Files\Sogou PXP\p2psvr.exe (file missing)
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O24 - Desktop Component 0: Privacy Protection - (no file)
O24 - Desktop Component 1: My Current Home Page - About:Home

–
End of file - 12832 bytes

Thanks,

Leo
Hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.



Please visit this web page for instructions for downloading and running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.
Hi Rorschach112,

Thank you so much for your help.

Here's the Report.txt:

SDFix: Version 1.219
Run by [removed] on Mon 08/25/2008 at 08:23 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File
Restoring Windows Product ID To Remove Fake Virus Alert

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\ETBR.EXE - Deleted
C:\Program Files\PCHealthCenter\0.exe - Deleted
C:\Program Files\PCHealthCenter\0.gif - Deleted
C:\Program Files\PCHealthCenter\1.exe - Deleted
C:\Program Files\PCHealthCenter\1.gif - Deleted
C:\Program Files\PCHealthCenter\1.ico - Deleted
C:\Program Files\PCHealthCenter\2.exe - Deleted
C:\Program Files\PCHealthCenter\2.gif - Deleted
C:\Program Files\PCHealthCenter\2.ico - Deleted
C:\Program Files\PCHealthCenter\3.exe - Deleted
C:\Program Files\PCHealthCenter\3.gif - Deleted
C:\Program Files\PCHealthCenter\4.exe - Deleted
C:\Program Files\PCHealthCenter\5.exe - Deleted
C:\Program Files\PCHealthCenter\7.exe - Deleted
C:\Program Files\PCHealthCenter\sc.html - Deleted
C:\WINDOWS\SYSTEM32\DRO32I.DLL - Deleted



Folder C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#w*w.redtube.com - Removed
Folder C:\Program Files\PCHealthCenter - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-25 20:32:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Vax347s\Config\jdgg40]

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}]
"DisplayName"="Alcohol 120%"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts]
"Il\16x\x20ac{-Nwi ?(?T?r?u?e?T?y?p?e?)?"="HDZB_75.TTF"
[HKEY_CURRENT_USER\Software\Microsoft\Windows Plus\Dancer\Genre]
"\4\xb3\xa4Â"="Random"
"vQ’["="Random"

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Application Loader"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe:*:Enabled:AOLTsMon"
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe:*:Enabled:AOLTopSpeed"
"C:\\Program Files\\Common Files\\AOL\\1161306523\\EE\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1161306523\\EE\\AOLServiceHost.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"="C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"="C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe:*:Enabled:AOL"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Sierra\\Half-life\\hl.exe"="C:\\Sierra\\Half-life\\hl.exe:*:Disabled:Half-Life Launcher"
"C:\\Sierra\\Half-life\\hlds.exe"="C:\\Sierra\\Half-life\\hlds.exe:*:Disabled:hlds"
"C:\\Program Files\\VinaGame\\CuuLongTranhBa\\NDLAUNCHER.EXE"="C:\\Program Files\\VinaGame\\CuuLongTranhBa\\NDLAUNCHER.EXE:*:Enabled:B?t d?u C?u Long Tranh B "
"C:\\Program Files\\SDP Multimedia\\SDP Downloader\\SDP.exe"="C:\\Program Files\\SDP Multimedia\\SDP Downloader\\SDP.exe:*:Enabled: SDP Downloader"
"C:\\Program Files\\FlashGet\\flashget.exe"="C:\\Program Files\\FlashGet\\flashget.exe:*:Enabled:Flashget"
"C:\\Program Files\\Boom Online\\nmcosrv.exe"="C:\\Program Files\\Boom Online\\nmcosrv.exe:*:Enabled:NexonMessenger Core"
"C:\\Program Files\\Boom Online\\ca.exe"="C:\\Program Files\\Boom Online\\ca.exe:*:Enabled:Crazy Arcade Client"
"C:\\Downloads\\zhuxian_ob.exe"="C:\\Downloads\\zhuxian_ob.exe:*:Disabled:?????????"
"C:\\Program Files\\Common Files\\Sogou PXP\\p2psvr.exe"="C:\\Program Files\\Common Files\\Sogou PXP\\p2psvr.exe:*:Enabled:Sogou P4P Service"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"="C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe:*:Enabled:LifeExp.exe"
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"="C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe:*:Enabled:LifeCam.exe"
"C:\\Program Files\\Steam\\Steam.exe"="C:\\Program Files\\Steam\\Steam.exe:*:Enabled:Steam"
"C:\\Program Files\\Games-Masters.com\\CABAL Online (Europe)\\launcher\\update\\ESTdnheadless.exe"="C:\\Program Files\\Games-Masters.com\\CABAL Online (Europe)\\launcher\\update\\ESTdnheadless.exe:*:Enabled:EST! download engine"
"C:\\Program Files\\HTTP-Tunnel\\HTTP-TunnelClient.exe"="C:\\Program Files\\HTTP-Tunnel\\HTTP-TunnelClient.exe:*:Enabled:HTTP-Tunnel Client"
"C:\\Program Files\\VentSrv\\ventrilo_srv.exe"="C:\\Program Files\\VentSrv\\ventrilo_srv.exe:*:Enabled:ventrilo_srv"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Sierra\\Half-life\\hl.exe"="C:\\Program Files\\Sierra\\Half-life\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\VinaGame\\Zing Chat\\Zing.exe"="C:\\Program Files\\VinaGame\\Zing Chat\\Zing.exe:*:Enabled:Zing Chat"
"C:\\Program Files\\Special Force\\specialforce.exe"="C:\\Program Files\\Special Force\\specialforce.exe:*:Enabled:specialforce"
"C:\\Documents and Settings\\Owner.MinhHoangNguyen\\Local Settings\\Temp\\Rar$EX00.375\\Special Force\\specialforce.exe"="C:\\Documents and Settings\\Owner.MinhHoangNguyen\\Local Settings\\Temp\\Rar$EX00.375\\Special Force\\specialforce.exe:*:Enabled:specialforce"
"C:\\Documents and Settings\\Owner.MinhHoangNguyen\\Local Settings\\Temp\\Rar$EX32.531\\Special Force\\specialforce.exe"="C:\\Documents and Settings\\Owner.MinhHoangNguyen\\Local Settings\\Temp\\Rar$EX32.531\\Special Force\\specialforce.exe:*:Enabled:specialforce"
"C:\\Documents and Settings\\Owner.MinhHoangNguyen\\Local Settings\\Temp\\Rar$EX00.360\\Special Force\\specialforce.exe"="C:\\Documents and Settings\\Owner.MinhHoangNguyen\\Local Settings\\Temp\\Rar$EX00.360\\Special Force\\specialforce.exe:*:Enabled:specialforce"
"C:\\Program Files\\SightSpeed\\SightSpeed.exe"="C:\\Program Files\\SightSpeed\\SightSpeed.exe:*:Enabled:SightSpeed"
"C:\\Rohan\\rohanclient.exe"="C:\\Rohan\\rohanclient.exe:*:Enabled:Rohan Online Game"
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"="C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"="C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe:*:Enabled:Nexon Game Manager"
"C:\\Nexon\\Combat Arms\\CombatArms.exe"="C:\\Nexon\\Combat Arms\\CombatArms.exe:*Enabled:CombatArms.exe"
"C:\\Nexon\\Combat Arms\\Engine.exe"="C:\\Nexon\\Combat Arms\\Engine.exe:*Enabled:Engine.exe"
"C:\\Nexon\\Combat Arms\\NMService.exe"="C:\\Nexon\\Combat Arms\\NMService.exe:*:Enabled:Nexon Messenger Core"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Nexon\\Combat Arms\\CombatArms.exe"="C:\\Nexon\\Combat Arms\\CombatArms.exe:*Enabled:CombatArms.exe"
"C:\\Nexon\\Combat Arms\\Engine.exe"="C:\\Nexon\\Combat Arms\\Engine.exe:*Enabled:Engine.exe"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Thu 23 Jun 2005 54,872 A..H. — "C:\Program Files\America Online 9.0\AOLphx.exe"
Thu 23 Jun 2005 31,832 A..H. — "C:\Program Files\America Online 9.0\rbm.exe"
Sun 3 Dec 2006 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 30 Nov 2007 15,604,198 A..H. — "C:\LEO\3x\MAXI 247 SCHOOL GIRL - SHINO\cos_shino_all.zip"
Fri 30 Nov 2007 43,291,866 A..H. — "C:\LEO\3x\Riri @hkplaza by arsenal-fan\pics_riri.zip"
Thu 24 Apr 2008 100,352 …H. — "C:\LEO\Truyen KH\B¡ Thu Tiˆn Ki?m - Tr?n Thanh Vƒn\~WRL0715.tmp"
Thu 24 Apr 2008 99,328 …H. — "C:\LEO\Truyen KH\B¡ Thu Tiˆn Ki?m - Tr?n Thanh Vƒn\~WRL2728.tmp"
Wed 11 Jun 2008 20,487 A.SHR — "C:\Program Files\McAfee\MQC\MRU.bak"
Wed 11 Jun 2008 265 A.SHR — "C:\Program Files\McAfee\MQC\qcconf.bak"
Sun 19 Nov 2006 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv05.tmp"
Thu 7 Feb 2002 94,208 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\lpaccodec.dll"
Fri 2 Feb 2001 40,960 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\lpac_codec_api.dll"
Mon 12 Apr 2004 212,992 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\OFR.EXE"
Thu 16 Jan 2003 278,528 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\PNCRT.dll"
Mon 5 May 2003 16,384 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\RMADEC.EXE"
Fri 11 Apr 2003 73,766 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\atrc3260.dll"
Fri 11 Apr 2003 45,099 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\auth3260.dll"
Fri 11 Apr 2003 65,575 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\cook3260.dll"
Fri 11 Apr 2003 102,437 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\drv13260.dll"
Fri 11 Apr 2003 176,165 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\drv23260.dll"
Fri 11 Apr 2003 208,935 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\drv33260.dll"
Fri 11 Apr 2003 217,127 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\drv43260.dll"
Tue 15 Apr 2003 976,896 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\pnen3260.dll"
Fri 11 Apr 2003 348,203 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\pnvi3260.dll"
Fri 11 Apr 2003 53,289 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\pnxr3260.dll"
Fri 11 Apr 2003 45,101 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\ramf3260.dll"
Fri 11 Apr 2003 135,213 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\rare3260.dll"
Mon 14 Oct 2002 57,344 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\rims3290.dll"
Fri 11 Apr 2003 163,885 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\rmff3260.dll"
Mon 14 Oct 2002 737,280 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\rmse3290.dll"
Mon 14 Oct 2002 245,760 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\rmwr3260.dll"
Fri 11 Apr 2003 245,805 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\rnlt3260.dll"
Mon 14 Oct 2002 245,760 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\rorw3290.dll"
Mon 14 Oct 2002 114,688 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\rtae3290.dll"
Mon 14 Oct 2002 65,536 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\rtin3290.dll"
Mon 14 Oct 2002 163,840 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\rtve3290.dll"
Fri 11 Apr 2003 45,093 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\rv103260.dll"
Fri 11 Apr 2003 98,341 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\rv203260.dll"
Fri 11 Apr 2003 94,247 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\rv303260.dll"
Fri 11 Apr 2003 90,151 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\rv403260.dll"
Fri 11 Apr 2003 159,785 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\rvre3260.dll"
Mon 14 Oct 2002 102,400 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\sipr3260.dll"
Fri 11 Apr 2003 61,485 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\smpl3260.dll"
Fri 11 Apr 2003 106,541 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\vsrl3260.dll"
Fri 11 Apr 2003 86,061 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\xmlp3261.dll"
Fri 11 Apr 2003 159,787 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\Common\zipf3260.dll"
Sun 23 Feb 2003 64,512 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\MusePack\MPPDEC.EXE"
Fri 25 Oct 2002 79,360 …H. — "C:\Program Files\Common Files\Nero\AudioPlugins\MusePack\MPPENC.EXE"

Finished!

So the next steps for me are:

- Install + run ComboFix .

- Windows XP Recovery Console.

- Use HiJackThis to scan my computer.

- Post new log along with ComboFix log up here.

Are they correct ?

Thanks again,

Leo
Hi again,

This is my new Hijackthis log and ComboFix log (I had my McAfee antivirus turn off while scanning through my system) :

ComboFix 08-08-24.03 - Owner 2008-08-26 5:31:51.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1501 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Error Cleaner.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Privacy Protector.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Favorites\Error Cleaner.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Favorites\Privacy Protector.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Favorites\Spyware&Malware Protection.url
.
—- Previous Run ——-
.
C:\_uninsep.bat
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\#SharedObjects\FUR8V3SE\iforex.com
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\#SharedObjects\FUR8V3SE\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\#SharedObjects\FUR8V3SE\interclick.com
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\#SharedObjects\FUR8V3SE\interclick.com\ud.sol
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\#SharedObjects\FUR8V3SE\static.youku.com
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\#SharedObjects\FUR8V3SE\static.youku.com\v1.0.0272\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com\settings.sol
C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Error Cleaner.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Privacy Protector.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Favorites\Error Cleaner.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Favorites\Privacy Protector.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Favorites\Spyware&Malware Protection.url
C:\Program Files\autorun.inf
C:\Program Files\Common Files\sogou pxp
C:\WINDOWS\system32\anshslgx.dll
C:\WINDOWS\system32\BKSCLkkj.ini
C:\WINDOWS\system32\BKSCLkkj.ini2
C:\WINDOWS\system32\dao350.dll
C:\WINDOWS\system32\ddcYsrRH.dll
C:\WINDOWS\system32\efndyonn.ini
C:\WINDOWS\system32\evlelweq.ini
C:\WINDOWS\system32\geBUMefG.dll
C:\WINDOWS\system32\ghboeqef.ini
C:\WINDOWS\system32\HPoorXbc.ini
C:\WINDOWS\system32\HPoorXbc.ini2
C:\WINDOWS\system32\Iklmmnnn.ini
C:\WINDOWS\system32\Iklmmnnn.ini2
C:\WINDOWS\system32\lcfgbsni.dll
C:\WINDOWS\system32\lqgcnjdc.ini
C:\WINDOWS\system32\mlJDvSJD.dll
C:\WINDOWS\system32\nadhexnr.dll
C:\WINDOWS\system32\RuEdJkkj.ini
C:\WINDOWS\system32\RuEdJkkj.ini2
C:\WINDOWS\system32\smtbrtbt.ini
C:\WINDOWS\system32\viwklask.dll
C:\WINDOWS\system32\WDcdLnpo.ini
C:\WINDOWS\system32\WDcdLnpo.ini2
C:\WINDOWS\system32\wjsidojk.dll
C:\WINDOWS\system32\xeejejsp.ini
C:\WINDOWS\system32\xyaGffii.ini
C:\WINDOWS\system32\xyaGffii.ini2
C:\WINDOWS\system32\ycsmkqhp.dll
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_P4P_SERVICE
——-\Service_P4P Service


((((((((((((((((((((((((( Files Created from 2008-07-26 to 2008-08-26 )))))))))))))))))))))))))))))))
.

2008-08-25 20:22 . 2008-08-25 20:22 578,560 –a–c— C:\WINDOWS\system32\dllcache\user32.dll
2008-08-25 20:20 . 2008-08-25 20:20 d——– C:\WINDOWS\ERUNT
2008-08-25 20:12 . 2008-08-25 20:35 d——– C:\SDFix
2008-08-25 15:44 . 2008-08-25 15:44 d——– C:\Program Files\Trend Micro
2008-08-25 13:44 . 2008-02-28 13:26 1,414,440 –a—— C:\WINDOWS\system32\ShellManager310E2D762.dll
2008-08-25 13:44 . 2008-02-28 13:01 774,144 –a—— C:\WINDOWS\system32\NEROINSTAEC43759.DB
2008-08-25 11:51 . 2008-08-25 11:52 d——– C:\Program Files\Common Files\Symantec Shared
2008-08-25 11:21 . 2008-08-26 05:26 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-25 11:21 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-08-25 11:21 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-08-25 11:21 . 2008-02-01 12:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-08-25 11:21 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-08-25 11:20 . 2008-08-26 04:41 d——– C:\Program Files\Spyware Doctor
2008-08-25 11:20 . 2008-08-25 11:50 d——– C:\Program Files\Norton Security Scan
2008-08-25 11:20 . 2008-08-25 11:20 d——– C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\PC Tools
2008-08-25 11:19 . 2008-08-25 12:20 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-25 11:13 . 2008-08-25 11:13 d——– C:\Program Files\NeroInstall.bak
2008-08-25 03:02 . 2008-08-22 17:22 3,262 –a—— C:\WINDOWS\system32\2.ico
2008-08-25 02:55 . 2008-08-22 15:38 165,888 –a—— C:\WINDOWS\system32\MSA.cpl
2008-08-25 02:54 . 2008-08-25 11:12 d——– C:\Program Files\MSA
2008-08-25 02:54 . 2008-08-24 03:45 380,928 –a—— C:\WINDOWS\rodqgpvlkoa.dll
2008-08-25 02:54 . 2008-08-24 03:45 233,472 –a—— C:\WINDOWS\pdoskegl.dll
2008-08-25 02:54 . 2008-08-24 03:45 188,416 –a—— C:\WINDOWS\rqbmvpso.dll
2008-08-25 02:54 . 2008-08-24 03:45 155,648 –a—— C:\WINDOWS\qalkfxor.dll
2008-08-25 02:54 . 2008-08-24 03:45 86,016 –a—— C:\WINDOWS\rvoelbxt.exe
2008-08-25 02:54 . 2008-08-22 17:22 3,262 –a—— C:\WINDOWS\system32\1.ico
2008-08-22 23:40 . 2005-03-31 01:06 36,864 ——— C:\WINDOWS\system32\CTCamMgr.dll
2008-08-22 22:50 . 2008-08-22 22:50 d——– C:\WINDOWS\system32\scripting
2008-08-22 22:50 . 2008-08-22 22:50 d——– C:\WINDOWS\system32\en
2008-08-22 22:50 . 2008-08-22 22:50 d——– C:\WINDOWS\system32\bits
2008-08-22 22:50 . 2008-08-22 22:50 d——– C:\WINDOWS\l2schemas
2008-08-22 22:48 . 2008-08-22 22:48 d——– C:\WINDOWS\ServicePackFiles
2008-08-18 20:30 . 2008-04-13 17:11 136,192 ——— C:\WINDOWS\system32\aaclient.dll
2008-08-18 20:30 . 2008-04-13 17:11 4,255 ——— C:\WINDOWS\system32\drivers\adv01nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,967 ——— C:\WINDOWS\system32\drivers\adv02nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,775 ——— C:\WINDOWS\system32\drivers\adv11nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,711 ——— C:\WINDOWS\system32\drivers\adv09nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,647 ——— C:\WINDOWS\system32\drivers\adv07nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,615 ——— C:\WINDOWS\system32\drivers\adv05nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,135 ——— C:\WINDOWS\system32\drivers\adv08nt5.dll
2008-08-15 09:59 . 2008-08-15 09:59 d——– C:\Program Files\Sun
2008-08-14 19:04 . 2008-05-01 07:33 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-14 19:03 . 2008-04-11 12:04 691,712 —–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-04 16:45 . 2008-08-22 23:27 d——– C:\Program Files\CamStudio
2008-08-01 23:45 . 2008-08-01 23:45 d——– C:\Nexon
2008-08-01 23:45 . 2008-08-01 23:49 d——– C:\Documents and Settings\All Users\Application Data\NexonUS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-26 02:57 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\SiteAdvisor
2008-08-25 20:44 ——— d—–w C:\Program Files\Nero
2008-08-25 20:44 ——— d—–w C:\Program Files\Common Files\Nero
2008-08-25 20:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2008-08-25 18:19 ——— d—–w C:\Program Files\Google
2008-08-25 18:12 ——— d—–w C:\Program Files\soft
2008-08-25 07:16 737,280 -c–a-w C:\WINDOWS\iun6002.exe
2008-08-24 09:11 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\skypePM
2008-08-24 09:11 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\Skype
2008-08-24 09:07 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\uTorrent
2008-08-23 06:33 ——— d—–w C:\Program Files\Java
2008-08-20 21:36 ——— d—–w C:\Program Files\9Dragons
2008-08-12 21:05 ——— d—–w C:\Program Files\FlashGet
2008-07-19 05:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 05:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 05:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 01:38 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\Nuotex
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-01 19:25 ——— d—–w C:\Program Files\YahooFriend
2008-06-30 09:53 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\fltk.org
2008-06-28 10:29 ——— d—–w C:\Program Files\Advanced JPEG Compressor
2008-06-27 20:18 ——— d—–w C:\Program Files\Skype
2008-06-27 20:18 ——— d—–w C:\Program Files\Common Files\Skype
2008-06-27 20:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2008-06-24 16:43 74,240 —-a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-05-27 04:30 36,864 —-a-w C:\WINDOWS\system32\VisualTaskTips.exe
2007-06-17 21:24 0 -c–a-w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\wklnhst.dat
2007-02-08 20:18 1,067,256 -c–a-w C:\Program Files\check.md
2006-12-21 23:31 21,526 -c–a-w C:\Program Files\CopyRight.txt
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E350B1C6-A8DC-4EEF-90DB-61DCAE9D1B67}]
2008-08-24 03:45 380928 –a—— C:\WINDOWS\rodqgpvlkoa.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{18C388BB-5014-4906-AE38-E62BA5AA7387}"= "C:\WINDOWS\qalkfxor.dll" [2008-08-24 03:45 155648]

[HKEY_CLASSES_ROOT\clsid\{18c388bb-5014-4906-ae38-e62ba5aa7387}]
[HKEY_CLASSES_ROOT\qalkfxor.1]
[HKEY_CLASSES_ROOT\TypeLib\{2E94E090-6554-4076-97A0-BC0EBE5CD9B2}]
[HKEY_CLASSES_ROOT\qalkfxor]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-03-18 12:35 630784]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 17:12 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 20:56 64512]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 07:47 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 07:47 688218]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-05-23 19:22 573440]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 12:17 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 12:13 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 12:17 118784]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 11:55 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 11:56 602182]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 17:30 152144]
"VX3000"="C:\WINDOWS\vVX3000.exe" [2006-10-13 16:04 707376]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2006-10-13 16:01 277296]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2007-01-17 12:24 36904]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-03-18 12:35 630784]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-18 17:42 79448]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]
"SigmatelSysTrayApp"="stsystra.exe" [2005-12-27 10:20 413696 C:\WINDOWS\stsystra.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-07-22 23:25 28160 C:\WINDOWS\KHALMNPR.Exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"pdoskegl"= {D9889943-6B58-4631-A57D-7801CDADEF72} - C:\WINDOWS\pdoskegl.dll [2008-08-24 03:45 233472]
"rqbmvpso"= {ED710DA2-0DB9-4574-8DD7-6F8C516CB162} - C:\WINDOWS\rqbmvpso.dll [2008-08-24 03:45 188416]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="logonuiX.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUnOEUm]
vtUnOEUm.dll [BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\ff_vfw.dll
"vidc.wmv3"= C:\PROGRA~1\COMBIN~1\Filters\wmv9vcm.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe [BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"FlashGet"="C:\Program Files\FlashGet\FlashGet.exe" /min
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"podXP"=C:\Program Files\podXP\podXP.exe
"Anti-Blaxx Manager"=C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
"HostManager"=C:\Program Files\Common Files\AOL\1161306523\EE\AOLHostManager.exe
"SecurDisc"=C:\Program Files\Nero\Nero\Nero8\InCD\NBHGui.exe
"InCD"=C:\Program Files\Nero\Nero\Nero8\InCD\InCD.exe
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"\VIE318.exe"=C:\Windows\System32\VIE318.exe
"\VIE319.exe"=C:\Windows\System32\VIE319.exe
"\VIE31A.exe"=C:\Windows\System32\VIE31A.exe
"\VIE31D.exe"=C:\Windows\System32\VIE31D.exe
"\SUE31E.exe"=C:\Windows\SUE31E.exe
"\VIE3.exe"=C:\Windows\System32\VIE3.exe
"\VIE4.exe"=C:\Windows\System32\VIE4.exe
"\VIE5.exe"=C:\Windows\System32\VIE5.exe
"\VIE6.exe"=C:\Windows\System32\VIE6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"C:\\Program Files\\Common Files\\AOL\\1161306523\\EE\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\SDP Multimedia\\SDP Downloader\\SDP.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Sierra\\Half-life\\hl.exe"=
"C:\\Program Files\\Special Force\\specialforce.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 MSCamSvc;MSCamSvc;C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2006-10-13 16:01]
R3 kbdcap;kbdcap;C:\WINDOWS\system32\drivers\kbdcap.sys [2007-06-09 15:46]
S3 DeepFree Update;DeepFree Update;C:\WINDOWS\system32\drivers\pcihdd2.sys []
S3 Revolution1;Revolution1;C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Revolution_Engine_8.3_ShaK3\SHAK3.sys []
S3 tap0801;TAP-Win32 Adapter V8;C:\WINDOWS\system32\DRIVERS\tap0801.sys [2007-02-15 10:48]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d6f23399-3c73-11dc-8dca-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ed5f27f3-3d2d-11dc-9703-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f3b09c99-8c8a-11db-af2b-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ff6d408b-76ba-11db-afa6-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder

2008-08-23 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]

2008-08-15 C:\WINDOWS\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2008-08-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2008-08-25 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-18 23:42]

2008-08-26 C:\WINDOWS\Tasks\User_Feed_Synchronization-{6FE1F0EA-AD86-4209-A2CB-7B9242E62E24}.job
- C:\WINDOWS\system32\msfeedssync.exe [2006-10-17 11:58]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Vistadrv - C:\WINDOWS\system32\drive\vsdrv.exe
HKLM-Run-Zing Chat - (no file)


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\Mozilla\Firefox\Profiles\mwru2jmp.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com.vn/
FF -: plugin - C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF -: plugin - C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npdrmv2.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npdsplay.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npitunes.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPMGWRAP.DLL
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npwmsdrm.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-26 05:33:32
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-08-26 5:35:04
ComboFix-quarantined-files.txt 2008-08-26 12:34:27

Pre-Run: 7,780,044,800 bytes free
Post-Run: 7,762,255,872 bytes free

333 — E O F — 2008-08-24 09:06:49




Hijackthis's log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 05:37: VIRUS ALERT!, on 8/26/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=Ty…fl1zpkUBc-UGu3g
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O2 - BHO: CPub Object - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: QXK Olive - {E350B1C6-A8DC-4EEF-90DB-61DCAE9D1B67} - C:\WINDOWS\rodqgpvlkoa.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
O3 - Toolbar: qalkfxor - {18C388BB-5014-4906-AE38-E62BA5AA7387} - C:\WINDOWS\qalkfxor.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open using &Advanced JPEG Compressor - C:\Program Files\Advanced JPEG Compressor\ajcieex.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: vtUnOEUm - vtUnOEUm.dll (file missing)
O21 - SSODL: pdoskegl - {D9889943-6B58-4631-A57D-7801CDADEF72} - C:\WINDOWS\pdoskegl.dll
O21 - SSODL: rqbmvpso - {ED710DA2-0DB9-4574-8DD7-6F8C516CB162} - C:\WINDOWS\rqbmvpso.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O24 - Desktop Component 0: My Current Home Page - About:Home

–
End of file - 12352 bytes


Looking forward your reply and thank you so much for your help.

Leo
Hello

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\2.ico
C:\WINDOWS\rodqgpvlkoa.dll
C:\WINDOWS\pdoskegl.dll
C:\WINDOWS\rqbmvpso.dll
C:\WINDOWS\qalkfxor.dll
C:\WINDOWS\rvoelbxt.exe
C:\WINDOWS\system32\1.ico

Folder::

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"\VIE318.exe"=-
"\VIE319.exe"=-
"\VIE31A.exe"=-
"\VIE31D.exe"=-
"\SUE31E.exe"=-
"\VIE3.exe"=-
"\VIE4.exe"=-
"\VIE5.exe"=-
"\VIE6.exe"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d6f23399-3c73-11dc-8dca-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ed5f27f3-3d2d-11dc-9703-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f3b09c99-8c8a-11db-af2b-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ff6d408b-76ba-11db-afa6-806d6172696f}]

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.




  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:

    • C:\WINDOWS\system32\dllcache\user32.dll
  • Click on the Upload button
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Hi, I copied the contents of the Clipboard but I couldn't find it anywhere. So I copied the contents from the website directly. Hope this will work. Please let me know if it doesnt work, I will try to search for the clipboard. Thanks Oh, here is the text: File Name : user32.dll File Size : 578560 byte File Type : MS-DOS executable (EXE), OS/2 or MS Windows MD5 : b26b135ff1b9f60c9388b4a7d16f600b SHA1 : 08fe9ff1fe9b8fd237adedb10d65fb0447b91fe5 Scanner results Scanner results : 3% Scanner(1/36) found malware! Scanner Engine Ver Sig Ver Sig Date Scan result Time a-squared 3.5.0.18 2008.06.04 2008-06-04 - 4.276 AhnLab V3 2008.06.05.01 2008.06.05 2008-06-05 - 2.045 AntiVir 7.8.0.26 7.0.4.145 2008-06-05 - 7.076 Arcavir 1.0.4 200806041951 2008-06-04 - 3.634 AVAST! 1.0.8 080605-0 2008-06-05 - 7.693 AVG 7.5.51.442 270.0.0/1484 2008-06-04 - 6.531 BitDefender 7.60825.1256309 7.19350 2008-06-05 - 7.211 CA (VET) 9.0.0.143 31.6.5849 2008-06-05 - 11.928 ClamAV 0.93 7367 2008-06-05 - 0.207 Comodo 2.11 2.0.0.546 2008-06-05 - 1.472 CP Secure 1.1.0.715 2008.06.05 2008-06-05 - 20.280 Dr.Web 4.44.0.9170 2008.06.05 2008-06-05 - 14.402 ewido 4.0.0.2 2008.06.04 2008-06-04 - 3.476 F-Prot 4.4.1.52 20080604 2008-06-04 - 4.823 F-Secure 5.51.6100 2008.06.04.06 2008-06-04 - 0.070 Fortinet 2.81-3.11 9.168 2008-06-05 - 2.889 Ikarus T3.1.01.26 2008.06.05.70870 2008-06-05 - 8.968 JiangMin 11.0.706 2008.06.05 2008-06-05 - 2.873 Kaspersky 5.5.10 2008.06.05 2008-06-05 - 15.682 KingSoft 2008.1.14.15 2008.6.5.14 2008-06-05 - 1.331 McAfee 5.2.00 5310 2008-06-04 - 4.058 Microsoft 1.3604 2008.06.05 2008-06-05 - 8.190 mks_vir 2.01 2008.06.04 2008-06-04 - 6.160 Norman 5.92.08 5.92.00 2008-06-04 - 11.702 nProtect 2008-06-05.00 1534841 2008-06-05 - 5.832 Panda 9.04.03.0001 2008.06.04 2008-06-04 - 3.407 Prevx V2 20080605 2008-06-05 TROJAN.PWDSTEALER.GEN 3.024 Quick Heal 9.00 2008.06.04 2008-06-04 - 0.474 Rising 20.0 20.47.30.00 2008-06-05 - 1.787 Sophos 2.74.1 4.30 2008-06-05 - 8.328 Symantec 1.3.0.24 20080604.003 2008-06-04 - 0.246 The Hacker 6.2.92 v00335 2008-06-04 - 1.504 Trend Micro 8.700-1004 5.320.02 2008-06-04 - 0.045 VBA32 3.12.6.7 20080604.1021 2008-06-04 - 4.763 ViRobot 20080604 2008.06.04 2008-06-04 - 0.786 VirusBuster 4.3.19:9 9.130.14/11.0 2008-06-04 - 3.316 Leo
Do this


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\dllcache\user32.dll

Folder::

Registry::

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.




Also post a new HJT log
Hi Rorschach112,

I did as you advised me.

Here's the new ComboFix log:

ComboFix 08-08-24.03 - Owner 2008-08-26 19:24:10.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1460 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\system32\dllcache\user32.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\dllcache\user32.dll

.
((((((((((((((((((((((((( Files Created from 2008-07-27 to 2008-08-27 )))))))))))))))))))))))))))))))
.

2008-08-25 20:20 . 2008-08-25 20:20 d——– C:\WINDOWS\ERUNT
2008-08-25 20:12 . 2008-08-25 20:35 d——– C:\SDFix
2008-08-25 15:44 . 2008-08-25 15:44 d——– C:\Program Files\Trend Micro
2008-08-25 13:44 . 2008-02-28 13:26 1,414,440 –a—— C:\WINDOWS\system32\ShellManager310E2D762.dll
2008-08-25 13:44 . 2008-02-28 13:01 774,144 –a—— C:\WINDOWS\system32\NEROINSTAEC43759.DB
2008-08-25 11:51 . 2008-08-25 11:52 d——– C:\Program Files\Common Files\Symantec Shared
2008-08-25 11:21 . 2008-08-26 13:39 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-25 11:21 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-08-25 11:21 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-08-25 11:21 . 2008-02-01 12:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-08-25 11:21 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-08-25 11:20 . 2008-08-26 11:48 d——– C:\Program Files\Spyware Doctor
2008-08-25 11:20 . 2008-08-25 11:50 d——– C:\Program Files\Norton Security Scan
2008-08-25 11:20 . 2008-08-25 11:20 d——– C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\PC Tools
2008-08-25 11:19 . 2008-08-26 13:20 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-25 11:13 . 2008-08-25 11:13 d——– C:\Program Files\NeroInstall.bak
2008-08-25 02:55 . 2008-08-22 15:38 165,888 –a—— C:\WINDOWS\system32\MSA.cpl
2008-08-25 02:54 . 2008-08-25 11:12 d——– C:\Program Files\MSA
2008-08-22 23:40 . 2005-03-31 01:06 36,864 ——— C:\WINDOWS\system32\CTCamMgr.dll
2008-08-22 22:50 . 2008-08-22 22:50 d——– C:\WINDOWS\system32\scripting
2008-08-22 22:50 . 2008-08-22 22:50 d——– C:\WINDOWS\system32\en
2008-08-22 22:50 . 2008-08-22 22:50 d——– C:\WINDOWS\system32\bits
2008-08-22 22:50 . 2008-08-22 22:50 d——– C:\WINDOWS\l2schemas
2008-08-22 22:48 . 2008-08-22 22:48 d——– C:\WINDOWS\ServicePackFiles
2008-08-18 20:30 . 2008-04-13 17:11 136,192 ——— C:\WINDOWS\system32\aaclient.dll
2008-08-18 20:30 . 2008-04-13 17:11 4,255 ——— C:\WINDOWS\system32\drivers\adv01nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,967 ——— C:\WINDOWS\system32\drivers\adv02nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,775 ——— C:\WINDOWS\system32\drivers\adv11nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,711 ——— C:\WINDOWS\system32\drivers\adv09nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,647 ——— C:\WINDOWS\system32\drivers\adv07nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,615 ——— C:\WINDOWS\system32\drivers\adv05nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,135 ——— C:\WINDOWS\system32\drivers\adv08nt5.dll
2008-08-15 09:59 . 2008-08-15 09:59 d——– C:\Program Files\Sun
2008-08-14 19:04 . 2008-05-01 07:33 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-14 19:03 . 2008-04-11 12:04 691,712 —–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-04 16:45 . 2008-08-22 23:27 d——– C:\Program Files\CamStudio
2008-08-01 23:45 . 2008-08-01 23:45 d——– C:\Nexon
2008-08-01 23:45 . 2008-08-01 23:49 d——– C:\Documents and Settings\All Users\Application Data\NexonUS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-26 02:57 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\SiteAdvisor
2008-08-25 20:44 ——— d—–w C:\Program Files\Nero
2008-08-25 20:44 ——— d—–w C:\Program Files\Common Files\Nero
2008-08-25 20:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2008-08-25 18:19 ——— d—–w C:\Program Files\Google
2008-08-25 18:12 ——— d—–w C:\Program Files\soft
2008-08-25 07:16 737,280 -c–a-w C:\WINDOWS\iun6002.exe
2008-08-24 09:11 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\skypePM
2008-08-24 09:11 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\Skype
2008-08-24 09:07 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\uTorrent
2008-08-23 06:33 ——— d—–w C:\Program Files\Java
2008-08-20 21:36 ——— d—–w C:\Program Files\9Dragons
2008-08-12 21:05 ——— d—–w C:\Program Files\FlashGet
2008-07-19 05:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 05:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 05:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 01:38 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\Nuotex
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-01 19:25 ——— d—–w C:\Program Files\YahooFriend
2008-06-30 09:53 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\fltk.org
2008-06-28 10:29 ——— d—–w C:\Program Files\Advanced JPEG Compressor
2008-06-27 20:18 ——— d—–w C:\Program Files\Skype
2008-06-27 20:18 ——— d—–w C:\Program Files\Common Files\Skype
2008-06-27 20:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2008-06-24 16:43 74,240 —-a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-05-27 04:30 36,864 —-a-w C:\WINDOWS\system32\VisualTaskTips.exe
2007-06-17 21:24 0 -c–a-w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\wklnhst.dat
2007-02-08 20:18 1,067,256 -c–a-w C:\Program Files\check.md
2006-12-21 23:31 21,526 -c–a-w C:\Program Files\CopyRight.txt
.

((((((((((((((((((((((((((((( snapshot@2008-08-26_ 5.29.16.56 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-26 10:37:53 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-08-27 02:21:24 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-08-26 10:37:53 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-08-27 02:21:24 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-03-18 12:35 630784]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 17:12 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 20:56 64512]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 07:47 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 07:47 688218]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-05-23 19:22 573440]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 12:17 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 12:13 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 12:17 118784]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 11:55 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 11:56 602182]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 17:30 152144]
"VX3000"="C:\WINDOWS\vVX3000.exe" [2006-10-13 16:04 707376]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2006-10-13 16:01 277296]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2007-01-17 12:24 36904]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-03-18 12:35 630784]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-18 17:42 79448]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]
"SigmatelSysTrayApp"="stsystra.exe" [2005-12-27 10:20 413696 C:\WINDOWS\stsystra.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-07-22 23:25 28160 C:\WINDOWS\KHALMNPR.Exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="logonuiX.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUnOEUm]
vtUnOEUm.dll [BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\ff_vfw.dll
"vidc.wmv3"= C:\PROGRA~1\COMBIN~1\Filters\wmv9vcm.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe [BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"FlashGet"="C:\Program Files\FlashGet\FlashGet.exe" /min
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"podXP"=C:\Program Files\podXP\podXP.exe
"Anti-Blaxx Manager"=C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
"HostManager"=C:\Program Files\Common Files\AOL\1161306523\EE\AOLHostManager.exe
"SecurDisc"=C:\Program Files\Nero\Nero\Nero8\InCD\NBHGui.exe
"InCD"=C:\Program Files\Nero\Nero\Nero8\InCD\InCD.exe
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"\VIE318.exe"=C:\Windows\System32\VIE318.exe
"\VIE319.exe"=C:\Windows\System32\VIE319.exe
"\VIE31A.exe"=C:\Windows\System32\VIE31A.exe
"\VIE31D.exe"=C:\Windows\System32\VIE31D.exe
"\SUE31E.exe"=C:\Windows\SUE31E.exe
"\VIE3.exe"=C:\Windows\System32\VIE3.exe
"\VIE4.exe"=C:\Windows\System32\VIE4.exe
"\VIE5.exe"=C:\Windows\System32\VIE5.exe
"\VIE6.exe"=C:\Windows\System32\VIE6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"C:\\Program Files\\Common Files\\AOL\\1161306523\\EE\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\SDP Multimedia\\SDP Downloader\\SDP.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Sierra\\Half-life\\hl.exe"=
"C:\\Program Files\\Special Force\\specialforce.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 MSCamSvc;MSCamSvc;C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2006-10-13 16:01]
R3 kbdcap;kbdcap;C:\WINDOWS\system32\drivers\kbdcap.sys [2007-06-09 15:46]
S3 DeepFree Update;DeepFree Update;C:\WINDOWS\system32\drivers\pcihdd2.sys []
S3 Revolution1;Revolution1;C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Revolution_Engine_8.3_ShaK3\SHAK3.sys []
S3 tap0801;TAP-Win32 Adapter V8;C:\WINDOWS\system32\DRIVERS\tap0801.sys [2007-02-15 10:48]

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder

2008-08-23 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]

2008-08-15 C:\WINDOWS\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2008-08-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2008-08-25 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-18 23:42]

2008-08-26 C:\WINDOWS\Tasks\User_Feed_Synchronization-{6FE1F0EA-AD86-4209-A2CB-7B9242E62E24}.job
- C:\WINDOWS\system32\msfeedssync.exe [2006-10-17 11:58]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-26 19:26:00
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-08-26 19:27:36
ComboFix-quarantined-files.txt 2008-08-27 02:27:00
ComboFix2.txt 2008-08-26 20:08:19
ComboFix3.txt 2008-08-26 12:35:05

Pre-Run: 8,017,821,696 bytes free
Post-Run: 7,998,873,600 bytes free

235 — E O F — 2008-08-24 09:06:49



And here's the new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:31, on 8/26/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=Ty…fl1zpkUBc-UGu3g
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O2 - BHO: CPub Object - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open using &Advanced JPEG Compressor - C:\Program Files\Advanced JPEG Compressor\ajcieex.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: vtUnOEUm - vtUnOEUm.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O24 - Desktop Component 0: My Current Home Page - About:Home

–
End of file - 11855 bytes


Thank you very much for your time.

Leo
Fix this with HJT

O20 - Winlogon Notify: vtUnOEUm - vtUnOEUm.dll (file missing)



Please do an online scan with Kaspersky WebScanner

Make sure you are using Internet Explorer for this. Click on Kaspersky Online Scanner and click Accept

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Hi, Here's the kaspersky report: ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Wednesday, August 27, 2008 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Wednesday, August 27, 2008 14:14:21 Records in database: 1151343 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Files scanned: 108502 Threat name: 14 Infected objects: 25 Suspicious objects: 0 Duration of the scan: 01:54:13 File name / Threat name / Threats count C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Unused Desktop Shortcuts\Bkav2006.exe Infected: not-a-virus:FraudTool.Win32.BachKhoa.t 1 C:\Program Files\Bkav2006\Bkav2006.exe Infected: not-a-virus:FraudTool.Win32.BachKhoa.t 1 C:\Program Files\MSA\MSA.cpl Infected: not-a-virus:FraudTool.Win32.UltimateAntivirus.bq 1 C:\Program Files\MSA\MSA.exe Infected: not-a-virus:FraudTool.Win32.MSAntivirus.a 1 C:\Program Files\soft\BHome.exe Infected: not-a-virus:FraudTool.Win32.BachKhoa.t 1 C:\Program Files\soft\Nero.8UltraEdi.8280.InclKeygen.part1.rar Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm 1 C:\Program Files\soft\Nero.8UltraEdi.8280.InclKeygen.part2.rar Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm 1 C:\Program Files\soft\ProxyCap_v3.02.rar Infected: Trojan.Win32.Zapchast.mn 1 C:\QooBox\Quarantine\C\WINDOWS\system32\anshslgx.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.cwt 1 C:\QooBox\Quarantine\C\WINDOWS\system32\lcfgbsni.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.cwt 1 C:\QooBox\Quarantine\C\WINDOWS\system32\nadhexnr.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.cwt 1 C:\QooBox\Quarantine\C\WINDOWS\system32\viwklask.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.cwt 1 C:\QooBox\Quarantine\C\WINDOWS\system32\wjsidojk.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.cwt 1 C:\QooBox\Quarantine\C\WINDOWS\system32\ycsmkqhp.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.cwt 1 C:\SDFix\backups\backups.zip Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.bc 1 C:\SDFix\backups\backups.zip Infected: not-a-virus:FraudTool.Win32.Agent.bj 1 C:\SDFix\backups\backups.zip Infected: not-a-virus:FraudTool.Win32.Agent.bi 1 C:\SDFix\backups\backups.zip Infected: Trojan.Win32.Agent.aalr 1 C:\SDFix\backups\backups.zip Infected: Trojan.Win32.Agent.aaux 1 C:\SDFix\backups\backups.zip Infected: not-a-virus:FraudTool.Win32.UltimateAntivirus.bq 1 C:\SDFix\backups\backups.zip Infected: not-a-virus:FraudTool.Win32.MSAntivirus.a 1 C:\SDFix\backups\backups.zip Infected: Trojan-Downloader.Win32.Agent.achm 1 C:\SDFix\backups\backups.zip Infected: Trojan.Win32.BHO.ggd 1 C:\WINDOWS\system32\MSA.cpl Infected: not-a-virus:FraudTool.Win32.UltimateAntivirus.bq 1 D:\i386\Apps\App00577\comps\toolbar\toolbr.exe Infected: not-a-virus:AdWare.Win32.SearchIt.t 1 The selected area was scanned.
You got infected because you downloaded keygens, in the future you will have to reformat as you wont get helped here

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Unused Desktop Shortcuts\Bkav2006.exe
    C:\Program Files\Bkav2006
    C:\Program Files\MSA
    C:\Program Files\soft\BHome.exe
    C:\Program Files\soft\Nero.8UltraEdi.8280.InclKeygen.part1.rar 
    C:\Program Files\soft\Nero.8UltraEdi.8280.InclKeygen.part2.rar
    C:\Program Files\soft\ProxyCap_v3.02.rar
    D:\i386\Apps\App00577\comps\toolbar\toolbr.exe
    purity 
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.



Please download DirLook by jpshortstuff from here.
  • Double-click DirLook.exe to run it.
  • Ensure that Show Hidden Files/Folders and BBCode Ouput are both checked.
  • Copy the content of the following codebox into the main textfield:

    C:\Program Files\soft
  • Click the DirLook button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. (Note: The log can also be found at C:\dl_log.txt)
Note: Scanning may take longer for large folders.



Also post a new HJT log
Hi Rorschach,

Thanks for your help so much.

I downloaded the program from a friend's link. I didn't know that it got me infected (I'm not good at computer).

I did as you advised, and here's the logs:

OTMoveIt:

Explorer killed successfully
C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Unused Desktop Shortcuts\Bkav2006.exe moved successfully.
C:\Program Files\Bkav2006\Help\images moved successfully.
C:\Program Files\Bkav2006\Help moved successfully.
C:\Program Files\Bkav2006\Backup moved successfully.
C:\Program Files\Bkav2006 moved successfully.
C:\Program Files\MSA moved successfully.
C:\Program Files\soft\BHome.exe moved successfully.
C:\Program Files\soft\Nero.8UltraEdi.8280.InclKeygen.part1.rar moved successfully.
C:\Program Files\soft\Nero.8UltraEdi.8280.InclKeygen.part2.rar moved successfully.
C:\Program Files\soft\ProxyCap_v3.02.rar moved successfully.
D:\i386\Apps\App00577\comps\toolbar\toolbr.exe moved successfully.
< purity >
< EmptyTemp >
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\~DF6515.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\hsperfdata_Owner\3192 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\Arj.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\avlib.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\Avp1.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\AvpMgr.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\btimages.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\CAB.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\dmap.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\dtreg.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\FsDrvPlg.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\FSSync.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\HashCont.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\HashMD5.PPL scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\HCCMP.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\ichk2.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\iChkSA.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\Inflate.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\IWGen.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\kave.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\kosglue-7.0.25.0.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\lha.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\L_llio.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\mdb.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\MDMAP.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\MemModSc.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\MemScan.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\minizip.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\MKavIO.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\msoe.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\nfio.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\NTFSstrm.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\prKernel.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\prLoader.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\prseqio.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\PrUtil.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\Quantum.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\rar.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\ScanningProcess.exe scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\sfdb.PPL scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\TempFile.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\thpimpl.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\UniArc.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\UnLZX.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\UnStored.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\WDiskIO.ppl scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcafee_8horHoR1abF0E6Q scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_avLC1TG4hwBQRym scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_H0nvEeL1VpqikoS scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_HJBOwJ6pgb4xgf4 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_PPAnkeQBaDOrrsr scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_f2fHbK82yac2HaB scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_KtHV06vZAQRauFY scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_qExfaRcwLAMfnee scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_Sq7u2LsQE0f4O27 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_w7QMDXchibfDJWG scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08272008_162557

Files moved on Reboot…
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\~DF6515.tmp moved successfully.
File C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\hsperfdata_Owner\3192 not found!
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\Arj.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\avlib.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\Avp1.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\AvpMgr.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\btimages.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\CAB.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\dmap.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\dtreg.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\FsDrvPlg.ppl moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\FSSync.dll
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\FSSync.dll NOT unregistered.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\FSSync.dll moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\HashCont.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\HashMD5.PPL moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\HCCMP.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\ichk2.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\iChkSA.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\Inflate.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\IWGen.ppl moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\kave.dll
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\kave.dll NOT unregistered.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\kave.dll moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\kosglue-7.0.25.0.dll
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\kosglue-7.0.25.0.dll NOT unregistered.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\kosglue-7.0.25.0.dll moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\lha.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\L_llio.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\mdb.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\MDMAP.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\MemModSc.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\MemScan.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\minizip.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\MKavIO.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\msoe.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\nfio.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\NTFSstrm.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\prKernel.ppl moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\prLoader.dll
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\prLoader.dll NOT unregistered.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\prLoader.dll moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\prseqio.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\PrUtil.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\Quantum.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\rar.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\ScanningProcess.exe moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\sfdb.PPL moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\TempFile.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\thpimpl.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\UniArc.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\UnLZX.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\UnStored.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIN\LOCALS~1\Temp\jkos-Owner\binaries\WDiskIO.ppl moved successfully.
File C:\WINDOWS\temp\mcafee_8horHoR1abF0E6Q not found!
File C:\WINDOWS\temp\mcmsc_avLC1TG4hwBQRym not found!
File C:\WINDOWS\temp\mcmsc_H0nvEeL1VpqikoS not found!
File C:\WINDOWS\temp\mcmsc_HJBOwJ6pgb4xgf4 not found!
File C:\WINDOWS\temp\mcmsc_PPAnkeQBaDOrrsr not found!
C:\WINDOWS\temp\sqlite_f2fHbK82yac2HaB moved successfully.
C:\WINDOWS\temp\sqlite_KtHV06vZAQRauFY moved successfully.
File C:\WINDOWS\temp\sqlite_qExfaRcwLAMfnee not found!
File C:\WINDOWS\temp\sqlite_Sq7u2LsQE0f4O27 not found!
File C:\WINDOWS\temp\sqlite_w7QMDXchibfDJWG not found!


DirLook:

DirLook.exe by jpshortstuff
Log created at 16:40:11 on Wed 08/27/2008

==============================

Contents of "C:\Program Files\soft" (inc. hidden/system files/folders)

—FOLDERS—


—FILES—

2bdec8422bded4201c622eb6a6a82eb6-UniKeyNT.exe (126464 bytes, created: 01/03/2007 08:50) –a——
Acrobat.part1.rar (71759872 bytes, created: 01/14/2008 01:15) –a–c—
Acrobat.part2.rar (42456657 bytes, created: 01/14/2008 01:37) –a–c—
AdbeRdr708_en_US.exe (21290704 bytes, created: 11/18/2006 17:20) –a——
Advanced JPEG Compressor 5.rar (1796973 bytes, created: 06/28/2008 03:20) –a——
Amadis.Video.Converter.Suite.v3.5.2.rar (9547683 bytes, created: 01/14/2008 01:23) –a——
AVVoiceChanDia.rar (11734105 bytes, created: 01/07/2008 18:46) –a–c—
BitTorrent-5.0.1.exe (6171229 bytes, created: 11/30/2006 00:21) –a——
blzd_avax.zip (9979367 bytes, created: 07/27/2007 02:34) –a——
BuddyCheck-1.0.2-Setup.exe (335438 bytes, created: 03/29/2007 22:48) –a——
CamStudio20.exe (1364995 bytes, created: 08/04/2008 16:40) –a——
cheatmega.rar (1422 bytes, created: 01/04/2007 23:27) –a–c—
Codec-Pack (BEST) Combined-Community.exe (5743211 bytes, created: 12/17/2006 00:17) –a——
Coheed_Cambria.exe (196235 bytes, created: 11/30/2006 20:28) –a——
December.exe (325710 bytes, created: 11/30/2006 20:32) –a——
DivX.Pro.v6.8.0.30.zip (17784447 bytes, created: 01/13/2008 23:14) –a–c—
DynastyWarriors4HyperPLUS10Trainer.rar (29582 bytes, created: 12/08/2007 03:05) –a–c—
FileSJ.exe (388608 bytes, created: 07/23/2007 12:09) –a——
Firefox Setup 2.0.0.16.exe (6046584 bytes, created: 08/07/2008 10:35) –a——
Firefox Setup 3.0.1.exe (7499056 bytes, created: 08/07/2008 10:21) –a——
flashget181en.exe (3656992 bytes, created: 03/01/2007 16:17) –a——
flvplayer_setup.exe (1181812 bytes, created: 01/06/2008 14:56) –a——
hannelore_pink.exe (276217 bytes, created: 11/30/2006 20:30) –a——
HDZB_75.TTF (5659925 bytes, created: 05/13/2007 20:20) –a–c—
hjsplit.zip (172058 bytes, created: 01/05/2007 17:50) –a——
iFox_Smooth.exe (724992 bytes, created: 11/30/2006 20:38) –a——
ImageSpyderV0.2.8.rar (444900 bytes, created: 10/12/2007 15:46) –a–c—
install_flash_player.exe (1410680 bytes, created: 11/18/2006 17:30) –a——
Install_Messenger_nous.exe (16332072 bytes, created: 11/24/2006 16:10) –a——
iTunesSetup.exe (36808256 bytes, created: 11/19/2006 16:00) –a——
keygen.rar (39735 bytes, created: 12/04/2007 01:47) –a–c—
klmcodec357.exe (17462806 bytes, created: 11/28/2007 23:17) –a——
lamwebsitenhac.zip (3180309 bytes, created: 12/15/2007 23:44) –a–c—
LimeWireWin.exe (3044944 bytes, created: 11/19/2006 00:03) –a——
Mac_OS_Brushed.exe (323274 bytes, created: 11/30/2006 20:37) –a——
Mediaplay-plugin_1_4_2_0.zip (4450270 bytes, created: 11/25/2006 00:38) –a——
msgr8us.exe (433192 bytes, created: 11/17/2006 22:51) –a——
name+vietphase.rar (228690 bytes, created: 06/28/2008 11:02) –a——
nettransport1.94.281.exe (1680896 bytes, created: 03/02/2007 00:20) –a——
NewUpdate.exe (17026194 bytes, created: 05/30/2007 06:54) –a——
npdrmv2.rar (81822 bytes, created: 11/20/2006 02:18) –a——
PDF Password Remover 2[1].2.rar (516959 bytes, created: 05/11/2008 17:11) –a–c—
PDFToolkit v1.0.2008.208.rar (1415795 bytes, created: 05/18/2008 20:48) –a–c—
phanmemdocPRC.rar (3246170 bytes, created: 04/06/2008 22:54) –a–c—
productkey.txt (29 bytes, created: 11/25/2006 00:14) –a——
pSX_1_11.rar (568968 bytes, created: 06/16/2007 19:30) –a–c—
RealPlayer10-5GOLD.exe (12969488 bytes, created: 11/18/2006 12:48) –a——
SDP_v2_3_0.msi (1384960 bytes, created: 11/27/2006 19:55) –a–c—
Setup-1.1.9.EXE (1061655 bytes, created: 06/19/2008 00:39) –a——
setup-Fraps.exe (756696 bytes, created: 06/30/2007 17:15) –a——
Shockwave_Installer_Slim.exe (2599088 bytes, created: 11/18/2006 17:31) –a——
shutter.exe (671695 bytes, created: 11/25/2006 00:07) –a——
siavpnint.exe (15253839 bytes, created: 10/06/2007 18:06) –a——
SkypeSetup.exe (22414120 bytes, created: 06/27/2008 13:16) –a——
smjle.exe (1243380 bytes, created: 06/19/2008 00:14) –a——
sn.exe (131072 bytes, created: 11/25/2006 00:51) –a——
startupsetup.exe (1197093 bytes, created: 07/06/2007 22:47) –a——
SteamInstall.msi (1567232 bytes, created: 10/06/2007 11:49) –a–c—
SuperMegaSpoof.exe (2080036 bytes, created: 07/23/2007 12:10) –a——
TangTocFF-d5zebjagr9.rar (904067 bytes, created: 07/13/2007 08:11) –a——
UKHook35.dll (61440 bytes, created: 04/07/2004 20:33) –a——
vdict.plugins.zip (9388 bytes, created: 04/23/2007 23:04) –a——
ventrilo-2.3.0-Windows-i386.exe (2010624 bytes, created: 10/19/2007 20:55) –a——
videoscreensaverSetup.exe (3432330 bytes, created: 09/18/2007 22:05) –a——
vlc-0.8.6d-win32.exe (9733451 bytes, created: 12/19/2007 18:08) –a——
voicemask458.exe (2046758 bytes, created: 01/07/2008 18:47) –a——
WengoPhone-2.0-windows.exe (11037607 bytes, created: 11/25/2006 20:41) –a——
WGAPluginInstall.exe (855344 bytes, created: 11/18/2006 18:02) –a——
winavi_77.zip (7624752 bytes, created: 11/25/2006 00:40) –a–c—
Windows_Aero_Black.zip (131833 bytes, created: 12/12/2007 20:51) –a——
Windows_Aero_Black_Shadow2.zip (151357 bytes, created: 12/12/2007 20:52) –a–c—
WinDVD8.exe (121242712 bytes, created: 11/25/2006 00:54) –a——
winrar.3.xx.generic.patch.rar (124400 bytes, created: 11/17/2007 04:17) –a–c—
winrar-hjsplit-hide ip platinum 3.4.rar (2921391 bytes, created: 11/17/2007 04:24) –a–c—
wmp11-windowsxp-x86-enu.exe (25755448 bytes, created: 11/18/2006 17:43) –a——
wrar361.exe (1035090 bytes, created: 11/20/2006 02:10) –a——
wrar371.exe (1206366 bytes, created: 11/17/2007 04:16) –a——
XSS.pdf (169210 bytes, created: 12/15/2007 23:21) –a–c—
XviD-1.1.0.exe (639255 bytes, created: 11/25/2006 01:24) –a——
YMTV.zip (488189 bytes, created: 01/07/2008 19:23) –a——
zg603std(zipGenius).exe (5414735 bytes, created: 06/13/2007 19:30) –a——
zsnesw151.zip (867785 bytes, created: 06/11/2007 22:19) –a——

==============================

=EOF=


and HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:48, on 8/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\WINDOWS\vVX3000.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=Ty…fl1zpkUBc-UGu3g
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O2 - BHO: CPub Object - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open using &Advanced JPEG Compressor - C:\Program Files\Advanced JPEG Compressor\ajcieex.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O15 - Trusted Zone: http://www.kaspersky.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O24 - Desktop Component 0: My Current Home Page - About:Home

–
End of file - 12444 bytes
All keygens and cracks contain malware

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\Program Files\soft\keygen.rar
    C:\Program Files\soft\winrar.3.xx.generic.patch.rar 
    purity 
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
Hi Rorschach, Thank you for the information. I'm certainly did not know that before. Here's the log of OTMoveIt2 : Explorer killed successfully C:\Program Files\soft\keygen.rar moved successfully. C:\Program Files\soft\winrar.3.xx.generic.patch.rar moved successfully. < purity > < EmptyTemp > File delete failed. C:\WINDOWS\temp\mcafee_z5WumDEpV1rom9s scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\mcmsc_fZienhYLkyH25KS scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_4lJ1orodYzTlscy scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_h0p36rWl4cjqNP7 scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_K87T4G9RUeqVjXi scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_pnJcMKcEZVTDPig scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_QAfI5h4upiIGS7L scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_T5xbiLqWQze2Ba7 scheduled to be deleted on reboot. Temp folders emptied. IE temp folders emptied. Explorer started successfully OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08282008_020315 Files moved on Reboot… File C:\WINDOWS\temp\mcafee_z5WumDEpV1rom9s not found! File C:\WINDOWS\temp\mcmsc_fZienhYLkyH25KS not found! C:\WINDOWS\temp\sqlite_4lJ1orodYzTlscy moved successfully. C:\WINDOWS\temp\sqlite_h0p36rWl4cjqNP7 moved successfully. C:\WINDOWS\temp\sqlite_K87T4G9RUeqVjXi moved successfully. File C:\WINDOWS\temp\sqlite_pnJcMKcEZVTDPig not found! File C:\WINDOWS\temp\sqlite_QAfI5h4upiIGS7L not found! File C:\WINDOWS\temp\sqlite_T5xbiLqWQze2Ba7 not found!
Your logs are clean

Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    [external image: Posted Image]



  • Make sure you have an Internet Connection.
  • Double-click OTMoveIt2.exe to run it.
  • Click on the CleanUp! button
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OtMoveit2 to rech the Internet, please allow the application to do so.
  • Click Yes to beging the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:

SpywareBlaster protects against bad ActiveX
IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here

* SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program or there will be a conflict.

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here

* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here

Thank you for your patience, and performing all of the procedures requested.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI