This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] major infection: iebt.dll, ms av, secuirty center, IE go

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is easily the worst infection I've ever seen.

So far I've noticed redirection of web searches in both Firefox and IE, on google and yahoo searches. It's all but blocked access to IE as well. Also the infection seems to block access to sites such as suport.microsoft, avg.com, and this site as well. I'm on my laptop at the moment. I've noticed icons for "MS AV" and "Security Center" in my contol panel both with the same icon. The infection may or may not be affecting my AVG free, when I try to scan it crashes the whole program. Also this may or may not be related but for some reason i'm unable to access my safe mode, it states a video driver error i think.

Before I post my hijack log, I'd like to ask if anyone has any information on bringing legal action against malware distributors, I'd think that at least one could make a case for vandalism if nothing else.

Logfile of HijackThis v1.99.1
Scan saved at 3:11:30 PM, on 9/29/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Documents and Settings\Rich\Desktop\MAR\procexp.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.packetnews.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {16975C1E-950B-F58A-B187-08ED8F89A6B0} - C:\Program Files\Ocenpfyo\xsfjfhzz.dll (file missing)
O2 - BHO: (no name) - {2B3CBDC2-8AB6-45B1-B59E-7B0DEE595917} - C:\WINDOWS\system32\byxxutt.dll (file missing)
O2 - BHO: (no name) - {2E9D4C81-9F27-4c14-B804-7B0F6BC88A4F} - C:\Program Files\Outerinfo\Outerinfo.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {4332CAEB-3C0F-45F6-B3FF-9EAC345A21EB} - C:\WINDOWS\system32\jkhff.dll (file missing)
O2 - BHO: 768890 helper - {446EF370-1987-49DB-AAFF-8EC680903F7A} - C:\WINDOWS\system32\768890\768890.dll
O2 - BHO: (no name) - {517B0A57-A70B-41B7-BFD0-51C902378BA5} - C:\WINDOWS\system32\vtutu.dll (file missing)
O2 - BHO: (no name) - {76F262CF-0308-0FB4-F7A3-043266F3A47C} - C:\Program Files\Nuhklutj\pczefgtj.dll (file missing)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: (no name) - {CFEE97A3-4911-444D-8BE8-E243A23D3DE2} - C:\Program Files\Applications\iebt.dll (file missing)
O2 - BHO: {04543e3f-f0e3-42ea-fa24-0a915661a43e} - {e34a1665-19a0-42af-ae24-3e0ff3e34540} - C:\WINDOWS\system32\fwwfafna.dll (file missing)
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - blank (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll (file missing)
O3 - Toolbar: Internet Service - {144A6B24-0EBC-4D89-BF09-A06A718E57B5} - C:\Program Files\Applications\iebr.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [ANTIVIRUS] C:\Program Files\MSX\MSx.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ietoolthru.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ietoolthru.com/redirect.php (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.mathxl.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testgen/i…GenXInstall.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {B4A78D29-52B1-4A7B-BAC0-1471BEDF9836} - http://xscanner.shredderscan.com/setup/webinst.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O18 - Protocol: bw+0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: offline-8876480 - {46B8E40E-3FDD-443B-9CA1-0E2FB51975A5} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O20 - Winlogon Notify: AutorunsDisabled - C:\WINDOWS\
O20 - Winlogon Notify: byxxutt - byxxutt.dll (file missing)
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
O20 - Winlogon Notify: winksy32 - winksy32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: zip - {e17b764e-dbc1-452f-a4d1-b60934dedf1b} - C:\WINDOWS\Installer\{e17b764e-dbc1-452f-a4d1-b60934dedf1b}\zip.dll (file missing)
O21 - SSODL: RunOnceDrv - {ad801e2e-b185-4620-b0fe-d5598bc23663} - C:\WINDOWS\Installer\{ad801e2e-b185-4620-b0fe-d5598bc23663}\RunOnceDrv.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: EENFHZGU - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Rich\LOCALS~1\Temp\EENFHZGU.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit (mi-raysat_3dsMax2008_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Hi! Welcome to the forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.
Thank you Scotty, sorry it took a little while. Since the last time i posted it seems that the system restore utility is no longer functional. 3dk-mat-pack v.0805 3dk-mat-pack v.0905 3dk-mat-pack v.1005 3dk-mat-pack v.1105 3dk-mat-pack v.1205 3ds max 6 Ace of WAV Adobe Download Manager 2.0 (Remove Only) Adobe Flash Player 9 ActiveX Adobe Flash Player Plugin Adobe Illustrator CS2 Adobe Photoshop CS Adobe Premiere Pro 2.0 Adobe Reader 7.0.5 Adobe Reader Japanese Fonts Adobe Shockwave Player Adobe SVG Viewer 3.0 AOL Instant Messenger Autodesk 3ds Max 2008 32-bit Autodesk 3ds Max 8 Autodesk DWF Viewer AVG Free 8.0 Backburner BitTorrent 5.0.7 Calc98 Canon iP1800 series Canon iP1800 series User Registration Canon My Printer Canon Utilities Easy-LayoutPrint Canon Utilities Easy-PhotoPrint CC_ccProxyExt ccCommon ccPxyCore CDDRV_Installer CDisplay 1.8 Core Center Creative MediaSource Creative System Information Diablo II DOGA-L3: CGA kit for beginners EA Download Manager EVE-ONLINE (remove only) Flash Retriever FLV Player 2.0, build 24 FruityLoops Studio Producer Edition v5.02 Google Earth Google Updater Google Video Player Hellgate: London Hijackthis 1.99.1 HijackThis 1.99.1 Hotfix for Windows XP (KB952287) HP Extended Capabilities 4.7 HP Image Zone 4.7 HP PSC & OfficeJet 4.7 HP Software Update ICQ Toolbar ICQ 5 IEBrowse Tool IExplorer Bar InterActual Player iPod mini 1.0 for Windows User Guide iPod mini Software Updater 1.0 iTunes J2SE Runtime Environment 5.0 Update 5 KhalInstallWrapper LiveReg (Symantec Corporation) Logitech Desktop Messenger Logitech SetPoint Macromedia Flash MX 2004 Matrix-ks Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 1 Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Office Professional Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.0.0 (Pre-Release 5348) Microsoft Visual C++ 2005 Redistributable Microsoft Xbox 360 Accessories 1.1 mIRC Mozilla Firefox (3.0.3) Mpeg2Decoder 1.3 MSI DigiCell MSI Live Update 3 MSN MSRedist MSXML 4.0 SP2 (KB936181) My Screen Recorder 2.63 Nero Media Player Nero OEM NeroVision Express 2 Norton AntiSpam Norton AntiSpam Norton AntiVirus 2005 Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security 2005 (Symantec Corporation) Norton WMI Update Norton WMI Update NVIDIA Drivers NVIDIA nTune PERFECT SERIES MULTI-DIRECTION OPTICAL MOUSE 1.3 Poser 4 PowerISO Punch! Professional Home Design QuickTime RealPlayer Registry Mechanic 5.1 SecureDoc Security Update for Windows XP (KB938464) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB953839) Sony Sound Forge 8.0d Sothink SWF Decompiler Sound Blaster Audigy 2 ZS Soundtrack Producer SPBBC Spy Sweeper Symantec Script Blocking Installer SymNet Terragen TurboTax Basic 2005 TurboTax Deluxe 2007 TurboTax Home & Business 2006 TurboTax ItsDeductible 2005 TurboTax ItsDeductible 2006 UOGateway Update for Windows XP (KB951072-v2) Video Edit Magic 4.3 ViewSonic Monitor Drivers Visual IP InSight(Telmex) Warning Center WexTech AnswerWorks Winamp (remove only) WinAVIVideoConverter Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows Media Player Firefox Plugin Windows XP Service Pack 3 WinRAR archiver WinZip Xfire (remove only) Yahoo! Install Manager Yahoo! Internet Mail Yahoo! Messenger Yahoo! Toolbar Zip Repair Pro
Hi

Sorry for the delay in replying.

If you already have Combofix, please delete this copy and download it again as it's being updated regularly.

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix


Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once Recovery Console is installed, you should see a blue screen prompt like the one below:

[external image: Posted Image]

Click Yes to allow Combofix to continue scanning for malware.

When done, a log will be produced. Please post that log and a new HijackThis log in your next reply.


1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



In your next reply post:
ComboFix.txt
New HijackThis log taken after the above scan has run
thanks Scotty, the system seems to be back to relatively normal again.

ComboFix 08-10-04.01 - Rich 2008-10-04 16:44:23.6 - NTFSx86
Command switches used :: C:\Documents and Settings\Rich\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Rich\Cookies\rich@mygeek[2].txt
C:\Documents and Settings\Rich\Cookies\rich@myspace[2].txt
C:\WINDOWS\BM2fd28991.txt
C:\WINDOWS\BM2fd28991.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Installer\{ad801e2e-b185-4620-b0fe-d5598bc23663}\RunOnceDrv.dll
C:\WINDOWS\Installer\{e17b764e-dbc1-452f-a4d1-b60934dedf1b}\zip.dll
C:\WINDOWS\PerfInfo
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\2.bat
C:\WINDOWS\system32\ahkyydct.ini
C:\WINDOWS\system32\ajvbmxyo.ini
C:\WINDOWS\system32\bescrfgc.ini
C:\WINDOWS\system32\bvalimbp.ini
C:\WINDOWS\system32\ciddshoj.ini
C:\WINDOWS\system32\config\systemprofile\My Documents\My Documents.url
C:\WINDOWS\system32\config\systemprofile\My Documents\My Music\My Music.url
C:\WINDOWS\system32\config\systemprofile\My Documents\My Pictures\My Pictures.url
C:\WINDOWS\system32\config\systemprofile\My Documents\My Videos\My Video.url
C:\WINDOWS\system32\drivers\tdssserv.sys
C:\WINDOWS\system32\dxeqhhhx.ini
C:\WINDOWS\system32\faqeatbl.ini
C:\WINDOWS\system32\fnfkdfiw.ini
C:\WINDOWS\system32\fntingcy.ini
C:\WINDOWS\system32\khodoscm.ini
C:\WINDOWS\system32\kmmqsgnb.ini
C:\WINDOWS\system32\koaasphm.ini
C:\WINDOWS\system32\lhnywcmb.ini
C:\WINDOWS\system32\mcdimmfu.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\ncmqjatj.ini
C:\WINDOWS\system32\njprckha
C:\WINDOWS\system32\njprckha\bg1.gif
C:\WINDOWS\system32\njprckha\bgtop.gif
C:\WINDOWS\system32\njprckha\bottom1.gif
C:\WINDOWS\system32\njprckha\essentials.gif
C:\WINDOWS\system32\njprckha\icon1.ico
C:\WINDOWS\system32\njprckha\install1.gif
C:\WINDOWS\system32\njprckha\left1.gif
C:\WINDOWS\system32\njprckha\li.gif
C:\WINDOWS\system32\njprckha\logo.gif
C:\WINDOWS\system32\njprckha\main.htm
C:\WINDOWS\system32\njprckha\mainframe.htm
C:\WINDOWS\system32\njprckha\reinstall1.gif
C:\WINDOWS\system32\njprckha\right1.gif
C:\WINDOWS\system32\njprckha\s1.htm
C:\WINDOWS\system32\njprckha\s2.htm
C:\WINDOWS\system32\njprckha\s3.htm
C:\WINDOWS\system32\njprckha\SMTop1.gif
C:\WINDOWS\system32\njprckha\SMTop2.gif
C:\WINDOWS\system32\njprckha\SMTop3.gif
C:\WINDOWS\system32\njprckha\SMTop4.gif
C:\WINDOWS\system32\njprckha\soft1_off.gif
C:\WINDOWS\system32\njprckha\soft1_off_ext.gif
C:\WINDOWS\system32\njprckha\soft1_on.gif
C:\WINDOWS\system32\njprckha\soft1_on_ext.gif
C:\WINDOWS\system32\njprckha\soft2_off.gif
C:\WINDOWS\system32\njprckha\soft2_off_ext.gif
C:\WINDOWS\system32\njprckha\soft2_on.gif
C:\WINDOWS\system32\njprckha\soft2_on_ext.gif
C:\WINDOWS\system32\njprckha\soft3_off.gif
C:\WINDOWS\system32\njprckha\soft3_off_ext.gif
C:\WINDOWS\system32\njprckha\soft3_on.gif
C:\WINDOWS\system32\njprckha\soft3_on_ext.gif
C:\WINDOWS\system32\njprckha\softbottom_off.gif
C:\WINDOWS\system32\njprckha\softbottom_on.gif
C:\WINDOWS\system32\njprckha\softleft_off.gif
C:\WINDOWS\system32\njprckha\softleft_on.gif
C:\WINDOWS\system32\njprckha\top1.gif
C:\WINDOWS\system32\njprckha\top2.gif
C:\WINDOWS\system32\njprckha\turnoff1.gif
C:\WINDOWS\system32\njprckha\turnon1.gif
C:\WINDOWS\system32\nkyisqgc.ini
C:\WINDOWS\system32\ofmsvyes.ini
C:\WINDOWS\system32\ofvvdvjx.ini
C:\WINDOWS\system32\qmvhgjkj.ini
C:\WINDOWS\system32\snhayffd.ini
C:\WINDOWS\system32\srnguilb.ini
C:\WINDOWS\system32\sueneuwq.ini
C:\WINDOWS\system32\TDSSadw.dll
C:\WINDOWS\system32\TDSSerrors.log
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssl.dll
C:\WINDOWS\system32\TDSSlog.dll
C:\WINDOWS\system32\tdssmain.dll
C:\WINDOWS\system32\tdssserf.dll
C:\WINDOWS\system32\TDSSserf1.dll
C:\WINDOWS\system32\tdssservers.dat
C:\WINDOWS\system32\titvcnrv.ini
C:\WINDOWS\system32\ukxaswtd.ini
C:\WINDOWS\system32\vasahahc.ini
C:\WINDOWS\system32\vkoxgvcy.ini
C:\WINDOWS\system32\vmxkkusj.ini
C:\WINDOWS\system32\xdxxpdhb.ini
C:\WINDOWS\system32\xpbhyrdp.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_DOMAINSERVICE
——-\Legacy_INTERNET_SERVICE
——-\Legacy_MCHINJDRV
——-\Legacy_MSSERVICE
——-\Legacy_NTLOAD
——-\Service_DomainService
——-\Service_Internet Service
——-\Service_MsService
——-\Service_ntload


((((((((((((((((((((((((( Files Created from 2008-09-04 to 2008-10-04 )))))))))))))))))))))))))))))))
.

2008-10-01 15:23 . 2008-10-01 15:23 d——– C:\Documents and Settings\Rich\New Folder
2008-09-29 15:02 . 2008-09-29 15:02 d——– C:\WINDOWS\system32\config\systemprofile\Application Data\AVGTOOLBAR
2008-09-29 01:50 . 2008-09-29 01:50 d——– C:\37e95605e68ff844ca5a68dae91f946c
2008-09-29 00:58 . 2008-09-29 01:25 d——– C:\VundoFix Backups
2008-09-28 09:25 . 2008-10-02 00:11 d–h—– C:\$AVG8.VAULT$
2008-09-28 09:22 . 2008-09-28 09:24 d——– C:\WINDOWS\system32\drivers\Avg
2008-09-28 09:22 . 2008-09-28 09:22 d——– C:\Documents and Settings\Rich\Application Data\AVGTOOLBAR
2008-09-28 09:22 . 2008-09-28 09:22 97,928 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-28 09:22 . 2008-09-28 09:22 76,040 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-09-28 09:22 . 2008-09-28 09:22 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-09-28 09:16 . 2008-09-28 09:16 d——– C:\WINDOWS\system32\scripting
2008-09-28 09:16 . 2008-09-28 09:16 d——– C:\WINDOWS\system32\en
2008-09-28 09:16 . 2008-09-28 09:16 d——– C:\WINDOWS\system32\bits
2008-09-28 09:16 . 2008-09-28 09:16 d——– C:\WINDOWS\l2schemas
2008-09-28 09:14 . 2008-09-28 09:14 d——– C:\WINDOWS\ServicePackFiles
2008-09-28 09:10 . 2008-09-28 09:10 d——– C:\WINDOWS\EHome
2008-09-28 09:04 . 2008-06-13 07:05 272,128 —–c— C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-28 04:23 . 2008-04-13 20:11 1,888,992 ——— C:\WINDOWS\system32\ati3duag.dll
2008-09-28 04:06 . 2008-04-11 15:04 691,712 —–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-09-28 04:06 . 2008-05-08 10:02 203,136 —–c— C:\WINDOWS\system32\dllcache\rmcast.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-02 03:03 ——— d—–w C:\Program Files\MSX
2008-09-30 21:00 ——— d—–w C:\Documents and Settings\Rich\Application Data\BitTorrent
2008-09-29 18:55 ——— d—–w C:\Program Files\Applications
2008-09-29 04:40 ——— d—–w C:\Program Files\EVGA
2008-09-28 13:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg8
2008-01-16 08:01 282,592 –sha-w C:\WINDOWS\system32\ffhkj.ini2
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{446EF370-1987-49DB-AAFF-8EC680903F7A}]
2003-09-27 20:27 15360 –a—— C:\WINDOWS\system32\768890\768890.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"AIM"="C:\Program Files\AIM\aim.exe" [2005-08-05 67160]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-03-01 43008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2006-10-16 1197648]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-04 8491008]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-10-04 1234712]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-11-29 C:\WINDOWS\KHALMNPR.Exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-01-09 13:30 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CoreCenter.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CoreCenter.lnk
backup=C:\WINDOWS\pss\CoreCenter.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SecureDoc.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SecureDoc.lnk
backup=C:\WINDOWS\pss\SecureDoc.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Rich^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Rich\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Rich^Start Menu^Programs^Startup^DigiCell.lnk]
path=C:\Documents and Settings\Rich\Start Menu\Programs\Startup\DigiCell.lnk
backup=C:\WINDOWS\pss\DigiCell.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Rich^Start Menu^Programs^Startup^findfast.exe]
path=C:\Documents and Settings\Rich\Start Menu\Programs\Startup\findfast.exe
backup=C:\WINDOWS\pss\findfast.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fgbg]
C:\Documents and Settings\Rich\My Documents\T?sks\?ti2evxx.exe [?]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Msqcm]
C:\Program Files\Common Files\??mbols\?ttrib.exe [?]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xrqpkb]
C:\Documents and Settings\Rich\Application Data\a?sembly\m?hta.exe [?]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\combofix]
cd [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
–a—— 2005-08-05 19:08 67160 C:\Program Files\AIM\aim.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
–a—— 2007-03-01 19:11 43008 C:\Program Files\BitTorrent\bittorrent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2004-08-28 10:22 58488 C:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
–a—— 2003-06-18 04:00 45056 C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-13 20:12 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTRegRun]
–a—— 1999-10-10 21:00 41984 C:\WINDOWS\Ctregrun.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
–a—— 2003-09-17 13:43 57344 C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2004-09-13 18:49 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
–a—— 2005-04-10 09:13 2904660 C:\Program Files\ICQLite\ICQLite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2003-12-16 16:06 229376 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LiveMonitor]
–a—— 2004-09-23 17:19 477696 C:\Program Files\MSI\Live Update 3\LMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWBMOUSE]
–a—— 2004-04-08 07:07 365568 C:\Program Files\PERFECT SERIES\MULTI-DIRECTION OPTICAL MOUSE\1.3\Mouse32A.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
—hs—- 2008-04-13 20:12 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 14:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-10-04 21:14 8491008 C:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune]
–a—— 2004-12-06 15:06 532480 C:\Program Files\NVIDIA Corporation\nTune\nTune.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-10-04 21:14 81920 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PestPatrol Control Center]
–a—— 2002-10-04 18:53 57344 C:\Program Files\PestPatrol\PPControl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PPMemCheck]
–a—— 2002-10-16 01:16 148480 C:\PROGRA~1\PESTPA~1\PPMemCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2003-12-23 22:26 98304 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteCenter]
–a—— 2003-10-08 19:35 139264 C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBDrvDet]
–a—— 2002-12-03 21:06 45056 C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
–a—— 2004-08-25 17:52 3321344 C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-08-26 19:14 36975 C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra—— 2005-08-18 14:49 307200 C:\Program Files\adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
–a—— 2000-05-11 04:00 90112 C:\WINDOWS\Updreg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
–a—— 2004-08-31 13:29 33936 C:\Program Files\Norton Internet Security\UrlLstCk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2007-05-14 18:22 35328 C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2006-05-02 18:51 3334144 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
–a—— 2003-10-06 02:57 24576 C:\WINDOWS\system32\CTHELPER.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
–a—— 2007-11-29 03:17 55824 C:\WINDOWS\KHALMNPR.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
–a—— 2007-11-29 03:17 55824 C:\WINDOWS\KHALMNPR.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"C-DillaCdaC11BA"=2 (0x2)
"MSUpdate"=2 (0x2)
"SAVScan"=3 (0x3)
"navapsvc"=2 (0x2)
"MSZONE"=2 (0x2)
"iPodService"=3 (0x3)
"gusvc"=2 (0x2)
"GEARSecurity"=2 (0x2)
"DQCVCNLDV"=3 (0x3)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccProxy"=2 (0x2)
"ccEvtMgr"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)
"SBService"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=3 (0x3)
"SecurityConsole"=2 (0x2)
"ose"=3 (0x3)
"MsService"=2 (0x2)
"MDM"=2 (0x2)
"ISSVC"=2 (0x2)
"Internet Service"=2 (0x2)
"IDriverT"=3 (0x3)
"DomainService"=2 (0x2)
"Cmdrvets"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Autodesk\\3ds Max 2008\\3dsmax.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\system32\\sessmgr.exe"=

R3 EENFHZGU;EENFHZGU;C:\DOCUME~1\Rich\LOCALS~1\Temp\EENFHZGU.exe []
R3 PCAlertDriver;PCAlertDriver;C:\Program Files\MSI\Core Center\NTGLM7X.sys [2004-11-16 12:27]
R3 RushTopDevice;RushTopDevice;C:\Program Files\MSI\Core Center\RushTop.sys [2004-11-16 14:54]
R4 Cmdrvets;Cmdrvets;C:\WINDOWS\system32\DRIVERS\Cmdrvets.syS []
R4 DQCVCNLDV;DQCVCNLDV;C:\DOCUME~1\Rich\LOCALS~1\Temp\DQCVCNLDV.exe []
R4 MSZONE;MSZONE;C:\RECYCLER\desktop\backup\lastgood\hz\G6Service.exe []
R4 QZVGXMFJWIT;QZVGXMFJWIT;C:\DOCUME~1\Rich\LOCALS~1\Temp\QZVGXMFJWIT.exe []
R4 SecurityConsole;SecurityConsole;C:\WINDOWS\AppPatch\Patches32\svchost.exe []
S1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-09-28 09:22]
S2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-28 09:22]
S2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-28 09:22]
S2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-09-28 09:22]
S2 PfDetNT;PfDetNT;C:\WINDOWS\system32\drivers\PfModNT.sys [2003-03-05 15:19]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7ea78fbf-c8d5-11d7-bffc-0013d3163506}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e4830f87-2718-11da-839d-806d6172696f}]
\Shell\AutoRun\command - D:\Setup.exe
.
Contents of the 'Scheduled Tasks' folder

2007-11-21 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Rich.job
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe [2004-08-31 05:34]
.
- - - - ORPHANS REMOVED - - - -

BHO-{4332CAEB-3C0F-45F6-B3FF-9EAC345A21EB} - C:\WINDOWS\system32\jkhff.dll
BHO-{517B0A57-A70B-41B7-BFD0-51C902378BA5} - C:\WINDOWS\system32\vtutu.dll
BHO-{e34a1665-19a0-42af-ae24-3e0ff3e34540} - C:\WINDOWS\system32\fwwfafna.dll
Toolbar-{11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
HKLM-Explorer_Run-smile - C:\Program Files\Applications\wcs.exe
SharedTaskScheduler-{A1D9D3F0-8C2A-9A1D-A376-2CACFB10AB72} - C:\WINDOWS\system32\svchosts.dll
Notify-AutorunsDisabled - bugwfaqd.dll
Notify-byxxutt - byxxutt.dll
Notify-winksy32 - winksy32.dll
MSConfigStartUp-2ce1ba0d - C:\WINDOWS\system32\seyvsmfo.dll
MSConfigStartUp-avp - C:\WINDOWS\TEMP\win31.tmp.exe
MSConfigStartUp-CTDrive - C:\WINDOWS\system32\drvsuk.dll
MSConfigStartUp-gzmxstmv - C:\Documents and Settings\All Users\Application Data\gzmxstmv.dll
MSConfigStartUp-IPInSightLAN 01 - C:\Program Files\Telmex\Visual IP InSight\Telmex\IPClient.exe
MSConfigStartUp-IPInSightMonitor 01 - C:\Program Files\Telmex\Visual IP InSight\Telmex\IPMon32.exe
MSConfigStartUp-jyhgrude - C:\Documents and Settings\All Users\Application Data\jyhgrude.dll
MSConfigStartUp-MalwareAlarm - C:\Program Files\MalwareAlarm\MalwareAlarm.exe
MSConfigStartUp-MSDisp32 - C:\WINDOWS\system32\drvsef.dll
MSConfigStartUp-MSDrive - C:\WINDOWS\system32\drvhox.dll
MSConfigStartUp-Ooai - C:\WINDOWS\system32\STEM~1\ntvdm.exe
MSConfigStartUp-Run - C:\WINDOWS\system32\winupdate.exe
MSConfigStartUp-Spoolsv - C:\WINDOWS\system32\spoolvs.exe
MSConfigStartUp-Windows update loader - C:\Windows\xpupdate.exe
MSConfigStartUp-wlybohgd - C:\Program Files\rgpstafk\zkrkvkfe.dll
MSConfigStartUp-nwiz - nwiz.exe
MSConfigStartUp-smgr - mgrs.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Rich\Application Data\Mozilla\Firefox\Profiles\m7kf62t0.Default User\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://login.live.com/login.srf?id=2&svc=mail&cbid=24325&msppjph=1&tw=0&fs=1&fsa=1&fsat=1296000&lc=1033&_lang=EN
FF -: plugin - C:\Documents and Settings\Rich\Application Data\Mozilla\Firefox\Profiles\m7kf62t0.Default User\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07061050.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Google\Google Updater\2.2.1249.1854\npCIDetect11.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_05\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_05\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_05\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_05\bin\NPJava14.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_05\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_05\bin\NPOJI610.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPAdbESD.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-04 16:53:59
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
C:\WINDOWS\system32\wpabaln.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-10-04 17:03:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-04 21:03:27
ComboFix2.txt 2007-12-27 15:21:34

Pre-Run: 10,989,588,480 bytes free
Post-Run: 13,291,196,416 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

413 — E O F — 2008-09-30 07:01:54
Hi

Remember to disconnect from the Internet before carrying out the next instruction, and to save the following script before you do.You must
also manually disable your anti-virus and anti-spyware programs. See the link below for instructions on doing this.

http://www.bleepingcomputer.com/forums/topic114351.html

Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\system32\ffhkj.ini2
C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Rich.job

Folder::
C:\VundoFix Backups
C:\WINDOWS\system32\768890
C:\Documents and Settings\Rich\My Documents\T?sks
C:\Program Files\Common Files\??mbols
C:\Documents and Settings\Rich\Application Data\a?sembly
C:\Program Files\Common Files\Symantec Shared
C:\PROGRA~1\NORTON~1

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{446EF370-1987-49DB-AAFF-8EC680903F7A}]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fgbg]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Msqcm]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xrqpkb]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MSUpdate"=-
"MSZONE"=-
"DQCVCNLDV"=-
"MsService"=-
"Internet Service"=-
"DomainService"=-
"SecurityConsole"=-

Driver::
EENFHZGU
DQCVCNLDV
MSZONE
QZVGXMFJWIT
SecurityConsole

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

In your next reply post:
ComboFix.txt
New HijackThis log taken after the above scan has run

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI