This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]  Antivirus XP 2008 Leftovers

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I recently acquired the Antivirus XP 2008 spyware and had help from a friend eliminate it – or so I thought. We managed to get rid of most signs of the infection and problems, but there still seems to be much residue. I'm no longer getting popups or suggestions that I buy their product, but my computer seems to be running invisible processes, and I am strangely unable to access many websites, including my banking site and even this site (I'm on a secondary computer, so I'll be transferring HijackThis files between computers). Because I can not access this site on my computer, also, I can not access the HijackThis component that you ask that I install prior to asking for help. Is there anywhere else I can download this from?

Anyway, I did a basic HijackThis scan and brought it over, so you may have an intial look. I thank you in advance very much for any help any of you can offer me.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:18:46 PM, on 9/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://music.yahoo.com/launchcast/station.asp?u=136758632
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [prunnet] "C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\prun.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [prunnet] "C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\prun.exe"
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 5211 bytes
Hi filmcynic,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hi, Tomk, and thank you for your help.

I did all that you asked me to, though I had to download the programs on another computer and transfer them over to my problem computer, because neither site could be accessed on that computer. I ran both programs to your instruction, though the Malwarebyte's software attempted to update and couldn't, due to the computer's inability to access that site. After going through the instructions as far as I could, and after restarting my computer, it seems to be running fine, or at least as fine as it was when I started the thread. I still can't access certain websites and I got a Windows Defender warning upon startup. Anyway, here are the results of Malwarebyte and the latest HijackThis log:

Malwarebytes' Anti-Malware 1.28
Database version: 1134
Windows 5.1.2600 Service Pack 2

9/24/2008 12:27:52 PM
mbam-log-2008-09-24 (12-27-52).txt

Scan type: Quick Scan
Objects scanned: 41613
Time elapsed: 4 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 5
Registry Data Items Infected: 2
Folders Infected: 16
Files Infected: 30

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\{5222008a-dd62-49c7-a735-7bd18ecc7350} (Rogue.VirusRemover) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\rhc38gj0ela1 (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\PCPrivacyCleaner (Rogue.PCPrivacyCleaner) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AntiMalwareGuard (Rogue.AntiMalwareGuard) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\Outerinfo (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\components (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christopher\Application Data\Microsoft\dtsc (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christopher\Application Data\rhc38gj0ela1 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christopher\Application Data\rhc38gj0ela1\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christopher\Application Data\rhc38gj0ela1\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christopher\Application Data\rhc38gj0ela1\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christopher\Application Data\rhc38gj0ela1\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christopher\Application Data\rhc38gj0ela1\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christopher\Application Data\rhc38gj0ela1\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christopher\Application Data\rhc38gj0ela1\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christopher\Application Data\rhc38gj0ela1\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christopher\Application Data\rhc38gj0ela1\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christopher\Application Data\rhc38gj0ela1\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\mrofinu572.exe.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christopher\Application Data\Microsoft\dtsc\5562.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\Terms.rtf (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\install.rdf (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\0.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\0.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\1.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\1.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\1.ico (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\2.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\2.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\2.ico (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\3.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\3.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\4.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\5.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\7.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\sc.html (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christopher\Application Data\Microsoft\dtsc\s (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\1.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\2.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christopher\Application Data\Microsoft\Internet Explorer\Quick Launch\AntiMalwareGuard.lnk (Rogue.AntiMalwareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\atmtd.dll._ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cbxvssr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\phc78gj0ela1.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\E.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\x (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MicroAV.cpl (Rogue.MicroAntivirus) -> Quarantined and deleted successfully.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:32:24 PM, on 9/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://music.yahoo.com/launchcast/station.asp?u=136758632
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [prunnet] "C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\prun.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [prunnet] "C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\prun.exe"
O4 - HKUS\S-1-5-18\..\Run: [\YUR35.exe] C:\Windows\system32\YUR35.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [\YUR36.exe] C:\Windows\system32\YUR36.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [\YUR37.exe] C:\Windows\system32\YUR37.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [\YUR38.exe] C:\Windows\system32\YUR38.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ANTIVIRUS] C:\Program Files\MicroAV\MicroAV.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [\YUR39.exe] C:\Windows\system32\YUR39.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [\YUR35.exe] C:\Windows\system32\YUR35.exe (User 'Default user')
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 5970 bytes



Much thanks again!
filmcynic,

We're gaining. :thumbup:

Are you able to get on the internet with this computer yet?

You aren't running Anti Virus Software

Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network.
Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories. Please download a free anti-virus software (for personal use), from one these excellent vendors NOW:

1) Antivir PersonalEditionClassic
-Free anti-virus software for Windows.
-Detects and removes more than 50,000 viruses. Free support.
2) avast! 4 Home Edition
-Anti-virus program for Windows.
-The home edition is freeware for noncommercial user
3) AVG Anti-Virus Free Edition
- Free edition of the AVG anti-virus program for Windows.
- Available for single computer use for home and non commercial use.

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts.


A. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

B. Now we must disable some of your security programs so that they do not interfere with the running of our tools:

If you chose AVAST
Right click on the avast! icon in system tray (looks like this: [external image: Posted Image]) and choose (Stop On-Access Protection)

If you chose AVIRA ANTIVIR
Please navigate to the system tray on the bottom right hand corner and look for an open white umbrella on red background (looks to this: [external image: Posted Image] )
  • right click it-> untick the option AntiVir Guard enable.
  • You should now see a closed, white umbrella on a red background (looks to this: [external image: Posted Image] )
You succesfully disabled the AntiVir Guard.

If you chose AVG
Please open the AVG Control Center program -> double-click on the "AVG Resident Shield" component (looks like this: [external image: Posted Image]) -> deselect the "Turn on AVG Resident Shield" checkmark and save the setting.
When you need to enable the AVG Resident Shield, ( I will let you know when) just open the AVG Control Center program -> double-click on the "AVG Resident Shield" component -> select the "Turn on AVG Resident Shield" checkmark and save the setting.

WINDOWS DEFENDER
  • Click Start > Programs > Windows Defender or launch from the system tray icon.
  • Click on Tools & Settings > Options.
  • Under Real-time protection options, uncheck the "Real-time protection" check box.
  • Click Save.
  • Go to Start > Control Panel > Security > Windows Defender, at the bottom of the Window Defenders page uncheck under Administrator Options "use Windows Defender" and then Save.
  • (When we are done, you can re-enable Defender using the same steps but this time place a check next to "Turn on real-time protection" check box.)



C.Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • DO NOT USE your computer for any other purpose while ComboFix is running.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Tomk, thank you very much again for your help. :notworthy:

1. My internet has always been working, I just can't access certain web pages with any browser. Mostly these pages seem to either be blocked by the site (I figured my bank isn't allowing me access because of my computer infection, but I could be wrong) or blocked by the spyware, since I can't get to any of the web sites that are helping me get rid of it (this one, and all the sites with the programs you're linking me to to download).

2. Under the Windows Defender instructions, you say to go into the security options in the control panel, but there is nothing of Defender in there. Only the newly installed antivirus scan, windows firewall and automatic updates are available. I disabled Defender in the other way you requested, though.

3. A few things I worried about while Combofix ran: after the reboot, Avira started to load up. I quickly disabled it, though. Also, I received an error message that said something called "dumphive.cfexe" had experienced a problem and had to close. Finally, I wanted to give the update on my web page access: still the same. Do you know what might be causing this?

OK, here are my nre combofix and hijackthis logs:


ComboFix 08-09-24.12 - Christopher 2008-09-25 11:19:37.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.320 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\empa.exe
C:\Program Files\MicroAV
C:\Program Files\MicroAV\MicroAV.cpl
C:\Program Files\MicroAV\MicroAV.exe
C:\Program Files\MicroAV\MicroAV.ooo
C:\Program Files\MicroAV\MicroAV0.dat
C:\Program Files\MicroAV\MicroAV1.dat
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\system32\MSINET.oca

.
((((((((((((((((((((((((( Files Created from 2008-08-25 to 2008-09-25 )))))))))))))))))))))))))))))))
.

2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Program Files\Avira
2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Documents and Settings\All Users\Application Data\Avira
2008-09-24 12:16 . 2008-09-24 12:16 d——– C:\Documents and Settings\Christopher\Application Data\Malwarebytes
2008-09-24 12:16 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-24 12:16 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-24 12:15 . 2008-09-24 12:19 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-24 12:15 . 2008-09-24 12:15 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-24 07:54 . 2008-09-22 03:16 74,752 –a—— C:\WINDOWS\system32\YUR39.exe
2008-09-24 07:48 . 2008-09-22 03:16 25,088 –a—— C:\WINDOWS\system32\YUR36.exe
2008-09-24 07:48 . 2008-09-22 03:16 25,088 –a—— C:\WINDOWS\system32\YUR35.exe
2008-09-24 07:48 . 2008-09-22 03:16 24,064 –a—— C:\WINDOWS\system32\YUR38.exe
2008-09-24 07:48 . 2008-09-22 03:16 24,064 –a—— C:\WINDOWS\system32\YUR37.exe
2008-09-23 17:15 . 2008-09-23 17:15 d——– C:\Program Files\ERUNT
2008-09-21 00:09 . 2008-09-21 00:09 d——– C:\Program Files\iPod
2008-09-21 00:08 . 2008-09-21 00:10 d——– C:\Program Files\iTunes
2008-09-21 00:08 . 2008-09-21 00:10 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-21 00:02 . 2008-09-21 00:02 d——– C:\Program Files\Apple Software Update
2008-09-18 19:36 . 2008-09-18 19:36 d——– C:\Program Files\Trend Micro
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Program Files\Security Task Manager2
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-09-18 19:21 . 2008-09-18 19:21 d——– C:\Program Files\Security Task Manager
2008-09-18 16:48 . 2008-09-18 16:48 93,184 –a—— C:\WINDOWS\silent.dll
2008-09-18 15:07 . 2008-09-18 15:07 d——– C:\Program Files\uTorrent
2008-09-18 15:05 . 2008-09-18 15:05 d——– C:\WINDOWS\system32\wTR19
2008-09-18 15:05 . 2008-09-18 15:05 d——– C:\Temp\dax41
2008-09-16 08:19 . 2008-09-18 17:35 d——– C:\WINDOWS\system32\CatRoot_bak
2008-09-12 08:51 . 2008-05-01 10:30 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-06 15:09 . 2008-09-06 15:09 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts
2008-08-29 10:18 . 2008-08-29 10:18 87,336 –a—— C:\WINDOWS\system32\dns-sd.exe
2008-08-29 09:53 . 2008-08-29 09:53 61,440 –a—— C:\WINDOWS\system32\dnssd.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-25 14:54 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-09-23 19:10 ——— d—–w C:\Program Files\Soulseek
2008-09-21 04:06 ——— d—–w C:\Program Files\Bonjour
2008-09-21 04:04 ——— d—–w C:\Program Files\QuickTime
2008-09-21 04:04 ——— d—–w C:\Program Files\Common Files\Apple
2008-09-18 20:46 ——— d—–w C:\Program Files\Norton Security Scan
2008-09-12 12:42 ——— d—–w C:\Program Files\Safari
2008-09-12 12:39 ——— d—–w C:\Program Files\Common Files\Macromedia
2008-09-12 12:35 ——— d—–w C:\Program Files\iTunes(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\iPod(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\Apple Software Update(2)
2008-09-10 20:45 32,000 —-a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-07-28 14:09 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-07-28 14:09 ——— d—–w C:\Program Files\Macromedia
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-07 159744]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-11 335872]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2003-07-17 184412]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2003-09-26 237568]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-21 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 158208]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"AGRSMMSG"="AGRSMMSG.exe" [2003-09-30 C:\WINDOWS\AGRSMMSG.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"\YUR35.exe"="C:\Windows\system32\YUR35.exe" [2008-09-22 25088]
"\YUR36.exe"="C:\Windows\system32\YUR36.exe" [2008-09-22 25088]
"\YUR37.exe"="C:\Windows\system32\YUR37.exe" [2008-09-22 24064]
"\YUR38.exe"="C:\Windows\system32\YUR38.exe" [2008-09-22 24064]
"\YUR39.exe"="C:\Windows\system32\YUR39.exe" [2008-09-22 74752]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-09-15 108544]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
–a—— 2003-10-07 23:41 28672 C:\WINDOWS\system32\Ati2mdxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R0 IFP300;iRiver Internet Audio Player IFP-300;C:\WINDOWS\system32\DRIVERS\ifp300.sys [2003-03-06 13543]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

*Newly Created Service* - SSMDRV
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Aim6 - (no file)
HKU-Default-Run-ANTIVIRUS - C:\Program Files\MicroAV\MicroAV.exe
ShellExecuteHooks-{3FFE90FB-0431-4ED5-AF76-8BF8AE7E0B35} - (no file)
MSConfigStartUp-ANTIVIRUS - C:\Program Files\MicroAV\MicroAV.exe
MSConfigStartUp-lphc78gj0ela1 - C:\WINDOWS\system32\lphc78gj0ela1.exe
MSConfigStartUp-SMrhc38gj0ela1 - C:\Program Files\rhc38gj0ela1\rhc38gj0ela1.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Christopher\Application Data\Mozilla\Firefox\Profiles\579bhqqr.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://news.google.com/nwshp?hl=en&tab;=wn
FF -: plugin - C:\Documents and Settings\Christopher\Application Data\Mozilla\Firefox\Profiles\579bhqqr.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJava14.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJPI142.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPOJI610.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-25 11:28:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe??????????x????|?????? ?deB???????????????B? ??????

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seneka]
"imagepath"="\systemroot\system32\drivers\seneka.sys"
.
———————— Other Running Processes ————————
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Apoint2K\ApntEx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 2008-09-25 11:35:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-25 15:34:50

Pre-Run: 66,470,346,752 bytes free
Post-Run: 66,479,587,328 bytes free

180 — E O F — 2008-09-18 21:35:03




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:42, on 2008-09-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://music.yahoo.com/launchcast/station.asp?u=136758632
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [\YUR35.exe] C:\Windows\system32\YUR35.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [\YUR36.exe] C:\Windows\system32\YUR36.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [\YUR37.exe] C:\Windows\system32\YUR37.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [\YUR38.exe] C:\Windows\system32\YUR38.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [\YUR39.exe] C:\Windows\system32\YUR39.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [\YUR35.exe] C:\Windows\system32\YUR35.exe (User 'Default user')
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 6179 bytes
filmcynic,

You're doing fine. Still more to clean. Hopefully everything will straighten out when everything is gone.

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 7.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u7-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    File::
    C:\WINDOWS\system32\YUR39.exe
    C:\WINDOWS\system32\YUR36.exe
    C:\WINDOWS\system32\YUR35.exe
    C:\WINDOWS\system32\YUR38.exe
    C:\WINDOWS\system32\YUR37.exe
    
    Registry::
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "\YUR35.exe"=-
    "\YUR36.exe"=-
    "\YUR37.exe"=-
    "\YUR38.exe"=-
    "\YUR39.exe"=-
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

In your next reply please provide:
  • ComboFix.txt
  • Kaspersky report
  • New HijackThis log taken after everything else completed
Ok, first a few notes:

1. I took care of the Java issue
2. With the combofix run, I don't know what you mean by script blocking, and i don't think any anti-malware things are going on. But should there be a way for me to keep the Avira from opening on the reboot?
3. I am unable to do the online virus scan, because my computer won't let me go on the kaspersky website (the browsers show that they're unable to connect to the site). I don't know if there's any way around that. Is there a way for me to download that software to a flashdrive and transport it to my computer, as I've been doing with other programs? I can't seem to get it to.

Anyway, here's the other stuff you asked for, for now:

ComboFix 08-09-24.12 - Christopher 2008-09-25 12:45:02.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.317 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Christopher\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\YUR35.exe
C:\WINDOWS\system32\YUR36.exe
C:\WINDOWS\system32\YUR37.exe
C:\WINDOWS\system32\YUR38.exe
C:\WINDOWS\system32\YUR39.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\YUR35.exe
C:\WINDOWS\system32\YUR36.exe
C:\WINDOWS\system32\YUR37.exe
C:\WINDOWS\system32\YUR38.exe
C:\WINDOWS\system32\YUR39.exe

.
((((((((((((((((((((((((( Files Created from 2008-08-25 to 2008-09-25 )))))))))))))))))))))))))))))))
.

2008-09-25 12:34 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-25 12:32 . 2008-09-25 12:32 d——– C:\Program Files\Common Files\Java
2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Program Files\Avira
2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Documents and Settings\All Users\Application Data\Avira
2008-09-24 12:16 . 2008-09-24 12:16 d——– C:\Documents and Settings\Christopher\Application Data\Malwarebytes
2008-09-24 12:16 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-24 12:16 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-24 12:15 . 2008-09-24 12:19 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-24 12:15 . 2008-09-24 12:15 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-23 17:15 . 2008-09-23 17:15 d——– C:\Program Files\ERUNT
2008-09-21 00:09 . 2008-09-21 00:09 d——– C:\Program Files\iPod
2008-09-21 00:08 . 2008-09-21 00:10 d——– C:\Program Files\iTunes
2008-09-21 00:08 . 2008-09-21 00:10 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-21 00:02 . 2008-09-21 00:02 d——– C:\Program Files\Apple Software Update
2008-09-18 19:36 . 2008-09-18 19:36 d——– C:\Program Files\Trend Micro
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Program Files\Security Task Manager2
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-09-18 19:21 . 2008-09-18 19:21 d——– C:\Program Files\Security Task Manager
2008-09-18 16:48 . 2008-09-18 16:48 93,184 –a—— C:\WINDOWS\silent.dll
2008-09-18 15:07 . 2008-09-18 15:07 d——– C:\Program Files\uTorrent
2008-09-18 15:05 . 2008-09-18 15:05 d——– C:\WINDOWS\system32\wTR19
2008-09-18 15:05 . 2008-09-18 15:05 d——– C:\Temp\dax41
2008-09-16 08:19 . 2008-09-18 17:35 d——– C:\WINDOWS\system32\CatRoot_bak
2008-09-12 08:51 . 2008-05-01 10:30 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-06 15:09 . 2008-09-06 15:09 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts
2008-08-29 10:18 . 2008-08-29 10:18 87,336 –a—— C:\WINDOWS\system32\dns-sd.exe
2008-08-29 09:53 . 2008-08-29 09:53 61,440 –a—— C:\WINDOWS\system32\dnssd.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-25 16:34 ——— d—–w C:\Program Files\Java
2008-09-25 15:45 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-09-23 19:10 ——— d—–w C:\Program Files\Soulseek
2008-09-21 04:06 ——— d—–w C:\Program Files\Bonjour
2008-09-21 04:04 ——— d—–w C:\Program Files\QuickTime
2008-09-21 04:04 ——— d—–w C:\Program Files\Common Files\Apple
2008-09-18 20:46 ——— d—–w C:\Program Files\Norton Security Scan
2008-09-12 12:42 ——— d—–w C:\Program Files\Safari
2008-09-12 12:39 ——— d—–w C:\Program Files\Common Files\Macromedia
2008-09-12 12:35 ——— d—–w C:\Program Files\iTunes(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\iPod(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\Apple Software Update(2)
2008-09-10 20:45 32,000 —-a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-07-28 14:09 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-07-28 14:09 ——— d—–w C:\Program Files\Macromedia
2008-07-19 02:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es.dll
.

((((((((((((((((((((((((((((( snapshot@2008-09-25_11.32.13.10 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-25 12:22:12 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-25 16:31:05 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-09-25 12:22:12 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-25 16:31:05 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-25 12:22:12 49,152 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-25 16:31:05 49,152 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-09-15 04:09:25 24,670 —-a-w C:\WINDOWS\system32\java.exe
+ 2008-06-10 05:21:01 135,168 —-a-w C:\WINDOWS\system32\java.exe
- 2007-09-15 04:09:25 28,768 —-a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 05:21:04 135,168 —-a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 06:32:34 139,264 —-a-w C:\WINDOWS\system32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-07 159744]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-11 335872]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2003-07-17 184412]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2003-09-26 237568]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-21 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AGRSMMSG"="AGRSMMSG.exe" [2003-09-30 C:\WINDOWS\AGRSMMSG.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-09-15 108544]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
–a—— 2003-10-07 23:41 28672 C:\WINDOWS\system32\Ati2mdxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R0 IFP300;iRiver Internet Audio Player IFP-300;C:\WINDOWS\system32\DRIVERS\ifp300.sys [2003-03-06 13543]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-\YUR35.exe - C:\Windows\system32\YUR35.exe
HKU-Default-Run-\YUR36.exe - C:\Windows\system32\YUR36.exe
HKU-Default-Run-\YUR37.exe - C:\Windows\system32\YUR37.exe
HKU-Default-Run-\YUR38.exe - C:\Windows\system32\YUR38.exe
HKU-Default-Run-\YUR39.exe - C:\Windows\system32\YUR39.exe



**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-25 12:55:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????1?5?8?7??????? ?deB???????????????B? ??????

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seneka]
"imagepath"="\systemroot\system32\drivers\seneka.sys"
.
———————— Other Running Processes ————————
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Apoint2K\ApntEx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 2008-09-25 13:00:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-25 16:59:52
ComboFix2.txt 2008-09-25 15:35:05

Pre-Run: 66,376,429,568 bytes free
Post-Run: 66,367,315,968 bytes free

177 — E O F — 2008-09-18 21:35:03





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:13, on 2008-09-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://music.yahoo.com/launchcast/station.asp?u=136758632
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 6007 bytes
filmcynic,

The "real-time protection" of your Avira is what is meant by script blocking programs. If you have followed earlier instructions the umbrella in the lower right of your screen (by your clock) should be closed. That's all you can do. :thumbup:

You must be online to do an online scan. You cannot transfer from a different computer. Lets try a different scanner.

Lets run an F-Secure online scan it will scan for Viruses, Spyware and RootKits:
  • Click HERE
  • Scroll to the bottom of the page and click the Start Scanning button. A window will pop up.
  • Allow the Active X control to be installed on your computer, then click the Accept button
  • Click Full System Scan and allow the components to download and the scan to complete.
  • If malware is found, check Submit samples to F-Secure then select Automatic cleaning
  • When cleaning has finished, click Show report (this will open an Internet Explorer window containing the report)
    Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post
If Automatic cleaning with Submit samples hangs, click Cancel, then New Scan
  • When the cleaning option is presented, Uncheck Submit samples to F-Secure
  • Click Automatic cleaning
  • When cleaning has finished, click Show report (this will open an Internet Explorer window containing the report)
  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post with a new Hijackthis log.

Note: This scan will only work with Internet Explorer.
You must be logged on a administrator rights to run this scan.
The scan may take a few hours.
filmcynic,

Let's try this.

Please download SDFix and save it to your Desktop.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key repeatedly;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual user account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons.
  • A text file should automatically open, so please copy the contents and post them here. We also need you to post a new HijackThis log
Tomk,

Thanks again. I downloaded and ran the SDFix. Here are the latest logs requested:


SDFix: Version 1.229
Run by [removed] on 2008-09-26 at 10:40

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-26 10:54:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

disk error: C:\WINDOWS\system32\config\system, 0
scanning hidden registry entries …

disk error: C:\WINDOWS\system32\config\software, 0
disk error: C:\Documents and Settings\Christopher\ntuser.dat, 0
scanning hidden files …

disk error: C:\WINDOWS\

please note that you need administrator rights to perform deep scan

Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :



Files with Hidden Attributes :

Mon 8 Oct 2007 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 27 Nov 2007 32,256 …H. — "C:\Documents and Settings\Christopher\My Documents\~WRL2239.tmp"
Sun 4 Nov 2007 19,456 …H. — "C:\Documents and Settings\Christopher\My Documents\~WRL2484.tmp"
Sun 18 May 2008 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Thu 13 Dec 2007 32,768 …H. — "C:\Documents and Settings\Christopher\Application Data\Microsoft\Word\~WRL0003.tmp"
Mon 10 Dec 2007 25,600 …H. — "C:\Documents and Settings\Christopher\Application Data\Microsoft\Word\~WRL0004.tmp"
Thu 13 Dec 2007 33,792 …H. — "C:\Documents and Settings\Christopher\Application Data\Microsoft\Word\~WRL0005.tmp"
Sun 4 Nov 2007 19,968 …H. — "C:\Documents and Settings\Christopher\Application Data\Microsoft\Word\~WRL0099.tmp"
Sun 4 Nov 2007 20,480 …H. — "C:\Documents and Settings\Christopher\Application Data\Microsoft\Word\~WRL0105.tmp"
Wed 16 Apr 2008 22,528 …H. — "C:\Documents and Settings\Christopher\Application Data\Microsoft\Word\~WRL0171.tmp"
Wed 16 Apr 2008 24,576 …H. — "C:\Documents and Settings\Christopher\Application Data\Microsoft\Word\~WRL0355.tmp"
Wed 16 Apr 2008 24,064 …H. — "C:\Documents and Settings\Christopher\Application Data\Microsoft\Word\~WRL0397.tmp"
Wed 16 Apr 2008 23,552 …H. — "C:\Documents and Settings\Christopher\Application Data\Microsoft\Word\~WRL1672.tmp"
Mon 10 Dec 2007 27,136 …H. — "C:\Documents and Settings\Christopher\Application Data\Microsoft\Word\~WRL2280.tmp"
Wed 16 Apr 2008 23,552 …H. — "C:\Documents and Settings\Christopher\Application Data\Microsoft\Word\~WRL2445.tmp"
Sun 4 Nov 2007 22,016 …H. — "C:\Documents and Settings\Christopher\Application Data\Microsoft\Word\~WRL2943.tmp"
Sun 4 Nov 2007 22,016 …H. — "C:\Documents and Settings\Christopher\Application Data\Microsoft\Word\~WRL3022.tmp"
Mon 10 Dec 2007 27,136 …H. — "C:\Documents and Settings\Christopher\Application Data\Microsoft\Word\~WRL3642.tmp"
Wed 16 Apr 2008 23,040 …H. — "C:\Documents and Settings\Christopher\Application Data\Microsoft\Word\~WRL3823.tmp"

Finished!



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:56, on 2008-09-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://music.yahoo.com/launchcast/station.asp?u=136758632
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 6117 bytes
filmcynic,

Something is going on that I'm not finding. Let's try a different tool.

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
Sorry for the break in communication. I was away for the last two days. On Friday, before I left, though, I had some issues: I had a blue-screen type crash shutdown and also two other times I shut the computer down myself, or rebooted my computer, I had to actually manually force shut down, as it remained on the "Windows is shutting down" screen for a very long time and seemed frozen that way. So far it's been ok today.

Here is my lopR log:



——————–\\ Lop S&D 4.2.4-4 XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : Mobile Intel® Pentium® 4 CPU 2.80GHz )
BIOS : Ver 1.00PARTTBL
USER : Christopher ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Not Activated)
C:\ (Local Disk) - NTFS - Total : 74 Go Free : 61 Go
D:\ (CD or DVD)
E:\ (USB) - FAT - Total : 953 Mo Free : 0 Go

"C:\Lop SD" ( MAJ : 19-09-2008|22:20 )
Option : [1] ( 2008-09-28|16:43 )

——————–\\ Listing folders in APPLIC~1

[2008-09-21|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008-04-12|03:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[2008-02-25|09:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL
[2008-02-25|09:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL Downloads
[2007-09-16|02:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL OCP
[2007-09-27|11:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[2007-09-27|11:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[2008-09-25|11:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Avira
[2007-09-15|04:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Hewlett-Packard
[2007-09-15|04:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HP
[2008-09-24|12:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[2007-09-15|11:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[2007-09-15|10:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ QuickTime
[2008-09-24|07:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SecTaskMan
[2008-02-25|09:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Viewpoint
[2007-09-15|05:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WEBREG
[2007-09-15|12:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage

[2007-09-16|02:13] C:\DOCUME~1\CHRIST~1\APPLIC~1\ acccore
[2008-04-14|08:37] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Adobe
[2008-02-11|06:35] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Apple Computer
[2007-09-15|04:24] C:\DOCUME~1\CHRIST~1\APPLIC~1\ ArcSoft
[2008-01-17|01:33] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Audacity
[2008-09-19|09:35] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Help
[2007-09-15|04:55] C:\DOCUME~1\CHRIST~1\APPLIC~1\ HP
[2007-09-14|09:44] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Identities
[2008-07-03|10:12] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Image Zone Express
[2007-09-18|12:58] C:\DOCUME~1\CHRIST~1\APPLIC~1\ InterVideo
[2008-07-28|12:26] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Macromedia
[2008-09-24|12:16] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Malwarebytes
[2008-09-18|03:07] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Microsoft
[2007-09-15|06:02] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Microsoft Web Folders
[2008-05-02|01:40] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Move Networks
[2008-09-12|09:11] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Mozilla
[2008-07-03|10:12] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Printer Info Cache
[2008-02-02|12:19] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Real
[2007-09-15|12:09] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Sun
[2007-09-15|01:01] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Thunderbird
[2007-10-07|10:51] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Viewpoint

[2007-09-14|09:23] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft

[2007-09-14|11:09] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft

[2007-09-14|09:29] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[2008-09-26 07:18 PM][–a——] C:\WINDOWS\tasks\GoogleUpdateTaskUser.job
[2008-09-21 12:02 AM][–a——] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2008-09-21 06:00 PM][–a——] C:\WINDOWS\tasks\Norton Security Scan.job
[2008-09-28 04:05 PM][–ah—–] C:\WINDOWS\tasks\MP Scheduled Scan.job
[2008-09-28 03:45 PM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[2003-03-31 03:00 PM][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[2008-04-12|03:51] C:\Program Files\ Adobe
[2008-02-25|09:39] C:\Program Files\ AIM6
[2007-09-14|11:43] C:\Program Files\ Analog Devices
[2007-09-14|11:51] C:\Program Files\ Apoint2K
[2008-09-21|12:02] C:\Program Files\ Apple Software Update
[2008-09-12|08:35] C:\Program Files\ Apple Software Update(2)
[2007-09-15|04:23] C:\Program Files\ ArcSoft
[2007-09-14|11:57] C:\Program Files\ ATI Technologies
[2008-09-25|11:01] C:\Program Files\ Avira
[2008-09-21|12:06] C:\Program Files\ Bonjour
[2007-09-15|10:16] C:\Program Files\ Canon
[2008-09-25|12:49] C:\Program Files\ Common Files
[2007-09-14|09:20] C:\Program Files\ ComPlus Applications
[2008-09-23|05:15] C:\Program Files\ ERUNT
[2007-09-15|04:50] C:\Program Files\ Hewlett-Packard
[2008-04-20|05:11] C:\Program Files\ HP
[2007-09-15|12:02] C:\Program Files\ HPQ
[2008-07-28|10:09] C:\Program Files\ InstallShield Installation Information
[2008-09-12|08:55] C:\Program Files\ Internet Explorer
[2007-09-15|12:10] C:\Program Files\ InterVideo
[2008-09-21|12:09] C:\Program Files\ iPod
[2008-04-12|03:49] C:\Program Files\ iPod(2)
[2008-04-12|03:45] C:\Program Files\ iPod(3)
[2008-09-12|08:35] C:\Program Files\ iPod(4)
[2007-09-15|06:32] C:\Program Files\ iRiver
[2008-09-21|12:10] C:\Program Files\ iTunes
[2008-04-12|03:49] C:\Program Files\ iTunes(2)
[2008-04-12|03:45] C:\Program Files\ iTunes(3)
[2008-09-12|08:35] C:\Program Files\ iTunes(4)
[2008-09-25|12:34] C:\Program Files\ Java
[2008-07-28|10:09] C:\Program Files\ Macromedia
[2008-09-24|12:19] C:\Program Files\ Malwarebytes' Anti-Malware
[2008-09-12|08:57] C:\Program Files\ Messenger
[2007-09-15|06:35] C:\Program Files\ microsoft frontpage
[2007-10-08|11:32] C:\Program Files\ Microsoft IntelliPoint
[2007-09-15|06:02] C:\Program Files\ Microsoft Office
[2007-09-15|11:00] C:\Program Files\ Movie Maker
[2008-09-28|04:17] C:\Program Files\ Mozilla Firefox
[2008-09-28|04:14] C:\Program Files\ Mozilla Thunderbird
[2007-09-14|09:19] C:\Program Files\ MSN
[2007-09-14|09:19] C:\Program Files\ MSN Gaming Zone
[2007-09-16|12:14] C:\Program Files\ MSXML 4.0
[2007-11-06|09:38] C:\Program Files\ Netflix
[2007-09-15|10:56] C:\Program Files\ NetMeeting
[2008-09-18|04:46] C:\Program Files\ Norton Security Scan
[2008-01-16|05:14] C:\Program Files\ Online Services
[2007-09-15|04:23] C:\Program Files\ Outlook Express
[2008-09-21|12:04] C:\Program Files\ QuickTime
[2007-10-21|11:14] C:\Program Files\ Real
[2008-01-02|09:41] C:\Program Files\ Rhapsody
[2008-09-12|08:42] C:\Program Files\ Safari
[2008-09-18|07:21] C:\Program Files\ Security Task Manager
[2008-09-24|07:54] C:\Program Files\ Security Task Manager2
[2008-09-23|03:10] C:\Program Files\ Soulseek
[2008-04-12|03:44] C:\Program Files\ Soulseek-Test
[2008-09-18|07:36] C:\Program Files\ Trend Micro
[2007-09-14|09:44] C:\Program Files\ Uninstall Information
[2008-09-18|03:07] C:\Program Files\ uTorrent
[2007-10-29|10:21] C:\Program Files\ Viewpoint
[2007-09-15|11:39] C:\Program Files\ Windows Defender
[2007-10-08|01:08] C:\Program Files\ Windows Media Connect 2
[2007-12-04|12:48] C:\Program Files\ Windows Media Player
[2007-09-15|10:56] C:\Program Files\ Windows NT
[2007-09-15|12:26] C:\Program Files\ WindowsUpdate
[2007-09-14|09:23] C:\Program Files\ xerox

——————–\\ Listing Folders in C:\Program Files\Common Files

[2008-04-12|03:51] C:\Program Files\Common Files\ Adobe
[2007-09-16|02:09] C:\Program Files\Common Files\ AOL
[2008-09-21|12:04] C:\Program Files\Common Files\ Apple
[2007-09-15|07:13] C:\Program Files\Common Files\ Designer
[2007-09-15|04:49] C:\Program Files\Common Files\ Hewlett-Packard
[2007-09-15|04:54] C:\Program Files\Common Files\ HP
[2007-09-14|11:50] C:\Program Files\Common Files\ InstallShield
[2008-09-25|12:32] C:\Program Files\Common Files\ Java
[2008-09-12|08:39] C:\Program Files\Common Files\ Macromedia
[2007-09-15|07:11] C:\Program Files\Common Files\ Microsoft Shared
[2007-09-14|09:20] C:\Program Files\Common Files\ MSSoap
[2007-09-14|05:00] C:\Program Files\Common Files\ ODBC
[2007-10-21|11:14] C:\Program Files\Common Files\ Real
[2007-09-14|09:21] C:\Program Files\Common Files\ Services
[2007-09-14|05:00] C:\Program Files\Common Files\ SpeechEngines
[2008-02-18|10:09] C:\Program Files\Common Files\ Symantec Shared
[2007-09-15|07:03] C:\Program Files\Common Files\ System
[2007-10-21|11:14] C:\Program Files\Common Files\ xing shared

——————–\\ Process

( 45 Processes )

… OK !

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-28 16:49:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden files …
disk error: C:\WINDOWS\System32\
please note that you need administrator rights to perform deep scan

——————–\\ Searching for other infections


No other infections found !

[F:26][D:6]-> C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp
[F:22][D:0]-> C:\DOCUME~1\CHRIST~1\Cookies
[F:287][D:4]-> C:\DOCUME~1\CHRIST~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 2008-09-28|16:52 - Option : [1]

——————–\\ Scan completed at 16:52:33
filmcynic, Well. That didn't show me anything new. Let's try Combofix again. Please drag the icon on your screen to the recycle bin. Then download a fresh copy and run per instructions in post #2.
HOpe this helps:

ComboFix 08-09-27.06 - Christopher 2008-09-29 10:16:53.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.322 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-29 )))))))))))))))))))))))))))))))
.

2008-09-28 16:42 . 2008-09-28 16:52 d——– C:\Lop SD
2008-09-26 10:30 . 2008-09-26 10:30 d——– C:\WINDOWS\ERUNT
2008-09-26 10:00 . 2008-09-26 10:54 d——– C:\SDFix
2008-09-25 12:34 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-25 12:32 . 2008-09-25 12:32 d——– C:\Program Files\Common Files\Java
2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Program Files\Avira
2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Documents and Settings\All Users\Application Data\Avira
2008-09-24 12:16 . 2008-09-24 12:16 d——– C:\Documents and Settings\Christopher\Application Data\Malwarebytes
2008-09-24 12:16 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-24 12:16 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-24 12:15 . 2008-09-24 12:19 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-24 12:15 . 2008-09-24 12:15 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-23 17:15 . 2008-09-23 17:15 d——– C:\Program Files\ERUNT
2008-09-21 00:09 . 2008-09-21 00:09 d——– C:\Program Files\iPod
2008-09-21 00:08 . 2008-09-21 00:10 d——– C:\Program Files\iTunes
2008-09-21 00:08 . 2008-09-21 00:10 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-21 00:02 . 2008-09-21 00:02 d——– C:\Program Files\Apple Software Update
2008-09-18 19:36 . 2008-09-18 19:36 d——– C:\Program Files\Trend Micro
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Program Files\Security Task Manager2
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-09-18 19:21 . 2008-09-18 19:21 d——– C:\Program Files\Security Task Manager
2008-09-18 16:48 . 2008-09-18 16:48 93,184 –a—— C:\WINDOWS\silent.dll
2008-09-18 15:07 . 2008-09-18 15:07 d——– C:\Program Files\uTorrent
2008-09-18 15:05 . 2008-09-18 15:05 d——– C:\WINDOWS\system32\wTR19
2008-09-18 15:05 . 2008-09-18 15:05 d——– C:\Temp\dax41
2008-09-16 08:19 . 2008-09-18 17:35 d——– C:\WINDOWS\system32\CatRoot_bak
2008-09-12 08:51 . 2008-05-01 10:30 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-06 15:09 . 2008-09-06 15:09 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts
2008-08-29 10:18 . 2008-08-29 10:18 87,336 –a—— C:\WINDOWS\system32\dns-sd.exe
2008-08-29 09:53 . 2008-08-29 09:53 61,440 –a—— C:\WINDOWS\system32\dnssd.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-29 12:04 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-09-25 16:34 ——— d—–w C:\Program Files\Java
2008-09-23 19:10 ——— d—–w C:\Program Files\Soulseek
2008-09-21 04:06 ——— d—–w C:\Program Files\Bonjour
2008-09-21 04:04 ——— d—–w C:\Program Files\QuickTime
2008-09-21 04:04 ——— d—–w C:\Program Files\Common Files\Apple
2008-09-18 20:46 ——— d—–w C:\Program Files\Norton Security Scan
2008-09-12 12:42 ——— d—–w C:\Program Files\Safari
2008-09-12 12:39 ——— d—–w C:\Program Files\Common Files\Macromedia
2008-09-12 12:35 ——— d—–w C:\Program Files\iTunes(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\iPod(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\Apple Software Update(2)
2008-09-10 20:45 32,000 —-a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-07-28 14:09 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-07-28 14:09 ——— d—–w C:\Program Files\Macromedia
2008-07-19 02:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es.dll
.

((((((((((((((((((((((((((((( snapshot@2008-09-25_11.32.13.10 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 20:27:04 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-09-26 14:30:39 3,690,496 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2008-09-26 14:30:39 229,376 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-08-07 20:27:04 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-09-26 14:30:27 3,690,496 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
+ 2008-09-26 14:30:27 229,376 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2008-09-25 12:22:12 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-29 12:02:41 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-09-25 12:22:12 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-29 12:02:41 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-25 12:22:12 49,152 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-29 12:02:41 49,152 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-09-15 04:09:25 24,670 —-a-w C:\WINDOWS\system32\java.exe
+ 2008-06-10 05:21:01 135,168 —-a-w C:\WINDOWS\system32\java.exe
- 2007-09-15 04:09:25 28,768 —-a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 05:21:04 135,168 —-a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 06:32:34 139,264 —-a-w C:\WINDOWS\system32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"Google Update"="C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-25 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-07 159744]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-11 335872]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2003-07-17 184412]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2003-09-26 237568]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-21 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AGRSMMSG"="AGRSMMSG.exe" [2003-09-30 C:\WINDOWS\AGRSMMSG.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-09-15 108544]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
–a—— 2003-10-07 23:41 28672 C:\WINDOWS\system32\Ati2mdxx.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R0 IFP300;iRiver Internet Audio Player IFP-300;C:\WINDOWS\system32\DRIVERS\ifp300.sys [2003-03-06 13543]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Christopher\Application Data\Mozilla\Firefox\Profiles\579bhqqr.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://news.google.com/nwshp?hl=en&tab=wn
FF -: plugin - C:\Documents and Settings\Christopher\Application Data\Mozilla\Firefox\Profiles\579bhqqr.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
FF -: plugin - C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\1.2.131.11\npGoogleOneClick5.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-29 10:26:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????1?5?8?7??p???? ?deB???????????????B? ??????

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seneka]
"imagepath"="\systemroot\system32\drivers\seneka.sys"
.
———————— Other Running Processes ————————
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Apoint2K\ApntEx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-09-29 10:31:40 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-29 14:31:29
ComboFix2.txt 2008-09-25 17:00:07
ComboFix3.txt 2008-09-25 15:35:05

Pre-Run: 66,133,663,744 bytes free
Post-Run: 66,127,962,112 bytes free

179 — E O F — 2008-09-18 21:35:03


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:34, on 2008-09-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://music.yahoo.com/launchcast/station.asp?u=136758632
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 5986 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI