This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] UiPopHidden, Can't seem to get it out! Please

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I don't know what do anymore, I am beside myself. I just read the thread of Snow and Gringo and it got rid of most of my malwares but not all. Here's my Hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 6:38:41 PM, on 30/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Bell\Security Manager\Fws.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Personal Vault\VaultClientUpgrade.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
C:\Program Files\Bell\Security Manager\Rps.exe
C:\WINDOWS\ALCFDRTM.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BigFix\BigFix.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSAComHandler.exe
C:\Program Files\Bell\Security Manager\rpsupdaterR.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.imdb.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
O4 - HKLM\..\Run: [Sympatico Security Manager] "C:\Program Files\Bell\Security Manager\Rps.exe"
O4 - HKLM\..\Run: [AlcFDMonitor] C:\WINDOWS\ALCFDRTM.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Security Manager\IdxClnR.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Security Manager\IdxClnR.exe"
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1219122505109
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://hgtv2.view22.com/view22/app/view22rte.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: mwrhva.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Sympatico Security Manager (Radialpoint Security Services) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\RpsSecurityAware.exe
O23 - Service: Sympatico Security Manager Update Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\rpsupdaterR.exe
O23 - Service: Sympatico Security Manager Firewall (RP_FWS) - Bell Sympatico - C:\Program Files\Bell\Security Manager\Fws.exe
O23 - Service: Personal Vault Upgrade Service (VaultClientUpgrade) - BELL - C:\Program Files\Personal Vault\VaultClientUpgrade.exe


Whoever can help I would be immensly greatful!
http://www.castlecops.com/p1113130-PLEASE_…opUpHidden.html

You need to let them know you're being helped at another site so they can close that topic.

1. launch Notepad (Start>All Programs>Accessories), and copy/paste all the Quoted REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""



2. Save this text as fixme.reg. Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop. Include the word REGEDIT4

3. Double-click on fixme.reg. When it asks you to merge the information to the registry click Yes.

4.Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
I did what you asked. My computer acts weird, when i want to scroll down or up on a page (internet and everything else), it lags per scroll so it looks like my computer freezes every 2 secondes.

Here's my new log, and thanks in advance

Logfile of HijackThis v1.99.1
Scan saved at 3:24:24 PM, on 01/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Bell\Security Manager\Fws.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Personal Vault\VaultClientUpgrade.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
C:\Program Files\Bell\Security Manager\Rps.exe
C:\WINDOWS\ALCFDRTM.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSAComHandler.exe
C:\Program Files\Bell\Security Manager\rpsupdaterR.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.imdb.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
O4 - HKLM\..\Run: [Sympatico Security Manager] "C:\Program Files\Bell\Security Manager\Rps.exe"
O4 - HKLM\..\Run: [AlcFDMonitor] C:\WINDOWS\ALCFDRTM.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Security Manager\IdxClnR.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Security Manager\IdxClnR.exe"
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1219122505109
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://hgtv2.view22.com/view22/app/view22rte.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Sympatico Security Manager (Radialpoint Security Services) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\RpsSecurityAware.exe
O23 - Service: Sympatico Security Manager Update Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\rpsupdaterR.exe
O23 - Service: Sympatico Security Manager Firewall (RP_FWS) - Bell Sympatico - C:\Program Files\Bell\Security Manager\Fws.exe
O23 - Service: Personal Vault Upgrade Service (VaultClientUpgrade) - BELL - C:\Program Files\Personal Vault\VaultClientUpgrade.exe
Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

Here's the Malwarebytes' log

Malwarebytes' Anti-Malware 1.28
Database version: 1225
Windows 5.1.2600 Service Pack 3

01/10/2008 6:08:09 PM
mbam-log-2008-10-01 (18-08-09).txt

Scan type: Quick Scan
Objects scanned: 51367
Time elapsed: 7 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

And here's the Hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 6:09:01 PM, on 01/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Bell\Security Manager\Fws.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Personal Vault\VaultClientUpgrade.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
C:\Program Files\Bell\Security Manager\Rps.exe
C:\WINDOWS\ALCFDRTM.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Bell\Sympatico Security Advisor\SSAComHandler.exe
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Bell\Security Manager\rpsupdaterR.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.imdb.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
O4 - HKLM\..\Run: [Sympatico Security Manager] "C:\Program Files\Bell\Security Manager\Rps.exe"
O4 - HKLM\..\Run: [AlcFDMonitor] C:\WINDOWS\ALCFDRTM.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Security Manager\IdxClnR.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Security Manager\IdxClnR.exe"
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1219122505109
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://hgtv2.view22.com/view22/app/view22rte.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Sympatico Security Manager (Radialpoint Security Services) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\RpsSecurityAware.exe
O23 - Service: Sympatico Security Manager Update Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\rpsupdaterR.exe
O23 - Service: Sympatico Security Manager Firewall (RP_FWS) - Bell Sympatico - C:\Program Files\Bell\Security Manager\Fws.exe
O23 - Service: Personal Vault Upgrade Service (VaultClientUpgrade) - BELL - C:\Program Files\Personal Vault\VaultClientUpgrade.exe


THANK you!
Well that showed nothing. Lets dig deeper.

Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.


Make sure you are disconnected from the net

1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net

2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
Give it atleast 20-30 minutes to finish if needed.

I forgot to say how my computer was. I used to have these random popups everytime I went on the internet, and my computer never had popups before so thats what got me worried, but now there aren't anymore popups. Well I hope not anymore.
But my computer still does the weird freezing thing everytime I scroll down or up a page .


I forgot to say how my computer was. I used to have these random popups everytime I went on the internet, and my computer never had popups before so thats what got me worried, but now there aren't anymore popups. Well I hope not anymore.
But my computer still does the weird freezing thing ebrytime I scroll down or up a page .

That might not have anything to do with spyware/malware but running the combofix scan will help in telling us.
Here's my combofix log


ComboFix 08-10-01.06 - Yvonne 2008-10-02 15:35:13.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.232 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-09-02 to 2008-10-02 )))))))))))))))))))))))))))))))
.

2008-10-02 00:01 . 2008-10-02 00:01 268 –ah—– C:\sqmdata17.sqm
2008-10-02 00:01 . 2008-10-02 00:01 244 –ah—– C:\sqmnoopt17.sqm
2008-10-01 17:57 . 2008-10-01 17:59 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-01 17:57 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-01 17:57 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-01 17:29 . 2008-10-01 17:29 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\AdobeUM
2008-10-01 15:33 . 2008-10-01 15:33 244 –ah—– C:\sqmnoopt16.sqm
2008-10-01 15:33 . 2008-10-01 15:33 232 –ah—– C:\sqmdata16.sqm
2008-10-01 15:14 . 2008-10-01 15:14 244 –ah—– C:\sqmnoopt15.sqm
2008-10-01 15:14 . 2008-10-01 15:14 232 –ah—– C:\sqmdata15.sqm
2008-10-01 12:45 . 2008-10-01 12:45 244 –ah—– C:\sqmnoopt14.sqm
2008-10-01 12:45 . 2008-10-01 12:45 232 –ah—– C:\sqmdata14.sqm
2008-10-01 05:34 . 2008-10-01 05:34 244 –ah—– C:\sqmnoopt13.sqm
2008-10-01 05:34 . 2008-10-01 05:34 232 –ah—– C:\sqmdata13.sqm
2008-10-01 05:23 . 2008-10-01 05:23 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\Template
2008-10-01 05:23 . 2008-10-01 21:40 484 –a—— C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\wklnhst.dat
2008-09-30 17:23 . 2008-09-30 17:23 244 –ah—– C:\sqmnoopt12.sqm
2008-09-30 17:23 . 2008-09-30 17:23 232 –ah—– C:\sqmdata12.sqm
2008-09-30 16:21 . 2008-09-30 16:21 d——– C:\Program Files\Panda Security
2008-09-30 16:21 . 2008-06-19 17:24 28,544 –a—— C:\WINDOWS\system32\drivers\pavboot.sys
2008-09-30 15:36 . 2008-09-30 15:36 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\Malwarebytes
2008-09-30 15:36 . 2008-09-30 15:36 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-30 15:17 . 2008-09-30 15:17 244 –ah—– C:\sqmnoopt11.sqm
2008-09-30 15:17 . 2008-09-30 15:17 232 –ah—– C:\sqmdata11.sqm
2008-09-30 10:24 . 2008-09-30 10:24 244 –ah—– C:\sqmnoopt10.sqm
2008-09-30 10:24 . 2008-09-30 10:24 232 –ah—– C:\sqmdata10.sqm
2008-09-29 21:50 . 2008-09-29 21:50 244 –ah—– C:\sqmnoopt09.sqm
2008-09-29 21:50 . 2008-09-29 21:50 232 –ah—– C:\sqmdata09.sqm
2008-09-29 15:43 . 2008-10-01 15:54 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Contacts
2008-09-29 14:22 . 2008-09-29 14:22 244 –ah—– C:\sqmnoopt08.sqm
2008-09-29 14:22 . 2008-09-29 14:22 232 –ah—– C:\sqmdata08.sqm
2008-09-29 05:12 . 2008-09-29 05:12 d——– C:\Program Files\Raxco
2008-09-29 05:12 . 2008-09-29 05:12 d——– C:\Documents and Settings\All Users\Application Data\Raxco
2008-09-29 05:11 . 2008-09-29 05:11 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\InstallShield
2008-09-27 22:34 . 2008-09-27 22:34 95 –a—— C:\WINDOWS\wininit.ini
2008-09-27 22:02 . 2008-09-28 14:25 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-27 20:33 . 2008-09-27 20:33 268 –ah—– C:\sqmdata07.sqm
2008-09-27 20:33 . 2008-09-27 20:33 244 –ah—– C:\sqmnoopt07.sqm
2008-09-27 12:53 . 2008-09-27 12:53 d——– C:\temp
2008-09-27 10:40 . 2008-09-27 10:40 268 –ah—– C:\sqmdata06.sqm
2008-09-27 10:40 . 2008-09-27 10:40 244 –ah—– C:\sqmnoopt06.sqm
2008-09-27 10:36 . 2008-09-27 10:36 268 –ah—– C:\sqmdata05.sqm
2008-09-27 10:36 . 2008-09-27 10:36 244 –ah—– C:\sqmnoopt05.sqm
2008-09-27 01:41 . 2008-09-27 01:41 268 –ah—– C:\sqmdata04.sqm
2008-09-27 01:41 . 2008-09-27 01:41 244 –ah—– C:\sqmnoopt04.sqm
2008-09-26 23:01 . 2008-09-26 23:01 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Yvonne
2008-09-26 21:30 . 2008-09-26 21:30 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\Bell
2008-09-26 21:29 . 2004-08-11 05:06 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\WINDOWS
2008-09-26 21:29 . 2008-08-19 00:52 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\SampleView
2008-09-26 21:29 . 2008-08-19 00:50 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\McAfee
2008-09-26 21:29 . 2008-09-29 15:43 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY
2008-09-26 17:31 . 2008-09-26 17:31 268 –ah—– C:\sqmdata03.sqm
2008-09-26 17:31 . 2008-09-26 17:31 244 –ah—– C:\sqmnoopt03.sqm
2008-09-25 15:23 . 2008-09-25 15:23 95,232 –a—— C:\WINDOWS\system32\tjsywdle.dll
2008-09-24 16:36 . 2008-09-24 16:36 354 –ahs—- C:\WINDOWS\system32\lgpxqaon.ini2
2008-09-24 15:33 . 2008-09-24 15:33 902,319 –ahs—- C:\WINDOWS\system32\lgpxqaon.tmp
2008-09-24 15:33 . 2008-09-24 15:33 294 –ahs—- C:\WINDOWS\system32\lgpxqaon.ini
2008-09-24 15:21 . 2008-09-24 15:21 95,232 –a—— C:\WINDOWS\system32\ollpntke.dll
2008-09-23 20:48 . 2008-09-23 20:48 91,136 –a—— C:\WINDOWS\system32\qvvjvami.dll
2008-09-23 20:32 . 2008-09-23 20:32 d——– C:\WINDOWS\Sun
2008-09-23 09:33 . 2008-09-23 09:33 268 –ah—– C:\sqmdata02.sqm
2008-09-23 09:33 . 2008-09-23 09:33 244 –ah—– C:\sqmnoopt02.sqm
2008-09-20 23:47 . 2008-09-20 23:47 268 –ah—– C:\sqmdata01.sqm
2008-09-20 23:47 . 2008-09-20 23:47 244 –ah—– C:\sqmnoopt01.sqm
2008-09-18 18:24 . 2008-09-26 21:38 d——– C:\Program Files\Pilates for Wimps Workout.xvid. DVDRip
2008-09-14 21:29 . 2008-09-14 21:29 89 –a—— C:\WINDOWS\system32\xi?
2008-09-07 22:22 . 2008-09-07 22:22 d——– C:\Program Files\Windows Media Connect 2
2008-09-06 22:20 . 2008-09-06 22:20 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-04 22:52 . 2008-09-04 22:52 244 –ah—– C:\sqmnoopt00.sqm
2008-09-04 22:52 . 2008-09-04 22:52 232 –ah—– C:\sqmdata00.sqm
2008-09-04 18:48 . 2008-09-04 18:48 d——– C:\Program Files\View22
2008-09-03 15:35 . 2008-09-03 15:35 940,794 –a—— C:\WINDOWS\system32\LoopyMusic.wav
2008-09-03 15:35 . 2008-09-03 15:35 146,650 –a—— C:\WINDOWS\system32\BuzzingBee.wav
2008-09-03 15:35 . 2008-09-17 05:00 73,728 –a—— C:\WINDOWS\ALCFDRTM.VER
2008-09-03 15:35 . 2008-09-03 15:35 73,728 –a—— C:\WINDOWS\ALCFDRTM.EXE
2008-09-02 13:33 . 2006-11-16 17:05 12,840 –a—— C:\WINDOWS\BigFixClientOverride.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-29 09:11 53,192 —-a-w C:\WINDOWS\system32\drivers\rp_skt32.sys
2008-09-28 18:48 ——— d—–w C:\Program Files\Common Files\Scanner
2008-09-27 01:39 ——— d—–w C:\Program Files\Symantec
2008-09-08 01:48 ——— d—–w C:\Program Files\CONEXANT
2008-09-02 17:34 ——— d—–w C:\Program Files\BigFix
2008-09-02 17:33 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-02 17:32 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-08-26 02:26 ——— d—–w C:\Documents and Settings\Melanie\Application Data\CyberLink
2008-08-25 17:15 ——— d—–w C:\Program Files\Windows Live
2008-08-25 17:14 ——— dcsh–w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-25 17:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-23 04:14 0 —ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2008-08-23 04:14 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_zumbus_01007.Wdf
2008-08-23 04:13 ——— d—–w C:\Program Files\Zune
2008-08-23 03:57 ——— d—–w C:\Program Files\Digital Media Reader
2008-08-23 03:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-08-22 08:58 ——— d—–w C:\Documents and Settings\Nicole\Application Data\Bell
2008-08-21 17:29 ——— d—–w C:\Program Files\Common Files\Adobe
2008-08-20 05:41 ——— d—–w C:\Documents and Settings\Melanie\Application Data\Bell
2008-08-19 19:43 ——— d—–w C:\Program Files\MSXML 4.0
2008-08-19 19:35 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-19 18:13 294,912 —-a-w C:\WINDOWS\HideWin.exe
2008-08-19 18:13 ——— d—–w C:\Program Files\Realtek
2008-08-19 05:45 ——— d—–w C:\Program Files\Personal Vault
2008-08-19 05:45 ——— d—–w C:\Program Files\Common Files\Authentium
2008-08-19 05:44 ——— d—–w C:\Program Files\CA
2008-08-19 05:44 ——— d—–w C:\Program Files\Bell
2008-08-19 05:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\Bell
2008-08-19 05:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-19 05:02 ——— d—–w C:\Program Files\Program Shortcuts
2008-08-19 04:52 ——— d—–w C:\WINDOWS\system32\config\systemprofile\Application Data\SampleView
2008-08-19 04:52 ——— d—–w C:\Documents and Settings\Nicole\Application Data\SampleView
2008-08-19 04:52 ——— d—–w C:\Documents and Settings\Melanie\Application Data\SampleView
2008-08-19 04:51 ——— d—–w C:\Program Files\CyberLink
2008-08-19 04:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-08-19 04:50 ——— d—–w C:\WINDOWS\system32\config\systemprofile\Application Data\McAfee
2008-08-19 04:50 ——— d—–w C:\Program Files\MSN Encarta Plus
2008-08-19 04:50 ——— d—–w C:\Program Files\Microsoft Money 2005
2008-08-19 04:50 ——— d—–w C:\Documents and Settings\Nicole\Application Data\McAfee
2008-08-19 04:50 ——— d—–w C:\Documents and Settings\Melanie\Application Data\McAfee
2008-08-19 04:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-08-19 04:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-19 04:47 ——— d—–w C:\Program Files\Google
2008-08-19 04:46 ——— d—–w C:\Program Files\Microsoft Works
2008-08-19 04:44 ——— d—–w C:\Program Files\Ahead
2008-08-19 04:43 ——— d—–w C:\Program Files\Microsoft Picture It! 10
2008-08-19 04:43 ——— d—–w C:\Program Files\Intel
2008-08-19 04:43 ——— d—–w C:\Program Files\Common Files\Ahead
2008-08-19 04:40 ——— d—–w C:\Program Files\Java
2008-08-19 04:40 ——— d—–w C:\Program Files\Common Files\New Boundary
2008-08-19 04:40 ——— d—–w C:\Program Files\Common Files\Java
2008-08-19 04:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Prism Deploy
2008-08-19 04:36 ——— d—–w C:\WINDOWS\system32\config\systemprofile\Application Data\Symantec
2008-07-19 04:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 04:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 04:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 04:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 04:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 04:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 04:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 04:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 03:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 03:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 212992]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"SSA.exe"="C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" [2007-03-27 2061816]
"Sympatico Security Manager"="C:\Program Files\Bell\Security Manager\Rps.exe" [2008-03-10 311024]
"AlcFDMonitor"="C:\WINDOWS\ALCFDRTM.EXE" [2008-09-03 73728]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2008-04-29 158624]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 C:\WINDOWS\system32\HdAShCut.exe]
"CHotkey"="zHotkey.exe" [2004-05-17 C:\WINDOWS\zHotkey.exe]
"ShowWnd"="ShowWnd.exe" [2003-09-19 C:\WINDOWS\ShowWnd.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-05-12 C:\WINDOWS\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2005-05-12 C:\WINDOWS\ALCWZRD.EXE]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\BigFix.exe [2008-08-19 2348584]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Digital Media Reader\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=

R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 28544]
R2 VaultClientUpgrade;Personal Vault Upgrade Service;C:\Program Files\Personal Vault\VaultClientUpgrade.exe [2008-03-07 53248]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-04-29 40704]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-04-29 61856]
S3 Radialpoint Security Services;Sympatico Security Manager;C:\Program Files\Bell\Security Manager\RpsSecurityAware.exe [2008-03-10 67824]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-04-29 245664]
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\Mozilla\Firefox\Profiles\jkr89vla.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.imdb.com
FF -: plugin - c:\Program Files\Adobe\Acrobat 6.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Digital Media Reader\Veoh\Plugins\noreg\NPVeohVersion.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJava14.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJPI142.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-02 15:36:33
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-10-02 15:37:18
ComboFix-quarantined-files.txt 2008-10-02 19:37:15

Pre-Run: 186,111,442,944 bytes free
Post-Run: 186,108,141,568 bytes free

224 — E O F — 2008-09-10 09:56:43

Thanks
The files ending in .sqm are from logging into Windows Live. Harmless but useless as well.



Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
C:\WINDOWS\system32\tjsywdle.dll
C:\WINDOWS\system32\lgpxqaon.ini2
C:\WINDOWS\system32\lgpxqaon.tmp
C:\WINDOWS\system32\lgpxqaon.ini
C:\WINDOWS\system32\ollpntke.dll
C:\WINDOWS\system32\qvvjvami.dll
C:\WINDOWS\system32\xi?
C:\sqmdata17.sqm
C:\sqmnoopt17.sqm
C:\sqmnoopt16.sqm
C:\sqmdata16.sqm
C:\sqmnoopt15.sqm
C:\sqmdata15.sqm
C:\sqmnoopt14.sqm
C:\sqmdata14.sqm
C:\sqmnoopt13.sqm
C:\sqmdata13.sqm
C:\sqmnoopt12.sqm
C:\sqmdata12.sqm
C:\sqmnoopt11.sqm
C:\sqmdata11.sqm
C:\sqmnoopt10.sqm
C:\sqmdata10.sqm
C:\sqmnoopt09.sqm
C:\sqmdata09.sqm
C:\sqmnoopt08.sqm
C:\sqmdata08.sqm
C:\sqmdata07.sqm
C:\sqmnoopt07.sqm
C:\sqmdata06.sqm
C:\sqmnoopt06.sqm
C:\sqmdata05.sqm
C:\sqmnoopt05.sqm
C:\sqmdata04.sqm
C:\sqmnoopt04.sqm
C:\sqmdata03.sqm
C:\sqmnoopt03.sqm
C:\sqmdata02.sqm
C:\sqmnoopt02.sqm
C:\sqmdata01.sqm
C:\sqmnoopt01.sqm
C:\sqmnoopt00.sqm
C:\sqmdata00.sqm

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Here's new combo fix log. My computer still does the whole freezing everytime I try to go up or down on a page. But I think UiPopuphidden is gone

ComboFix 08-10-02.04 - Yvonne 2008-10-03 6:04:17.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.229 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\sqmdata00.sqm
C:\sqmdata01.sqm
C:\sqmdata02.sqm
C:\sqmdata03.sqm
C:\sqmdata04.sqm
C:\sqmdata05.sqm
C:\sqmdata06.sqm
C:\sqmdata07.sqm
C:\sqmdata08.sqm
C:\sqmdata09.sqm
C:\sqmdata10.sqm
C:\sqmdata11.sqm
C:\sqmdata12.sqm
C:\sqmdata13.sqm
C:\sqmdata14.sqm
C:\sqmdata15.sqm
C:\sqmdata16.sqm
C:\sqmdata17.sqm
C:\sqmnoopt00.sqm
C:\sqmnoopt01.sqm
C:\sqmnoopt02.sqm
C:\sqmnoopt03.sqm
C:\sqmnoopt04.sqm
C:\sqmnoopt05.sqm
C:\sqmnoopt06.sqm
C:\sqmnoopt07.sqm
C:\sqmnoopt08.sqm
C:\sqmnoopt09.sqm
C:\sqmnoopt10.sqm
C:\sqmnoopt11.sqm
C:\sqmnoopt12.sqm
C:\sqmnoopt13.sqm
C:\sqmnoopt14.sqm
C:\sqmnoopt15.sqm
C:\sqmnoopt16.sqm
C:\sqmnoopt17.sqm
C:\WINDOWS\system32\lgpxqaon.ini
C:\WINDOWS\system32\lgpxqaon.ini2
C:\WINDOWS\system32\lgpxqaon.tmp
C:\WINDOWS\system32\ollpntke.dll
C:\WINDOWS\system32\qvvjvami.dll
C:\WINDOWS\system32\tjsywdle.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\sqmdata00.sqm
C:\sqmdata01.sqm
C:\sqmdata02.sqm
C:\sqmdata03.sqm
C:\sqmdata04.sqm
C:\sqmdata05.sqm
C:\sqmdata06.sqm
C:\sqmdata07.sqm
C:\sqmdata08.sqm
C:\sqmdata09.sqm
C:\sqmdata10.sqm
C:\sqmdata11.sqm
C:\sqmdata12.sqm
C:\sqmdata13.sqm
C:\sqmdata14.sqm
C:\sqmdata15.sqm
C:\sqmdata16.sqm
C:\sqmdata17.sqm
C:\sqmnoopt00.sqm
C:\sqmnoopt01.sqm
C:\sqmnoopt02.sqm
C:\sqmnoopt03.sqm
C:\sqmnoopt04.sqm
C:\sqmnoopt05.sqm
C:\sqmnoopt06.sqm
C:\sqmnoopt07.sqm
C:\sqmnoopt08.sqm
C:\sqmnoopt09.sqm
C:\sqmnoopt10.sqm
C:\sqmnoopt11.sqm
C:\sqmnoopt12.sqm
C:\sqmnoopt13.sqm
C:\sqmnoopt14.sqm
C:\sqmnoopt15.sqm
C:\sqmnoopt16.sqm
C:\sqmnoopt17.sqm
C:\WINDOWS\system32\lgpxqaon.ini
C:\WINDOWS\system32\lgpxqaon.ini2
C:\WINDOWS\system32\lgpxqaon.tmp
C:\WINDOWS\system32\ollpntke.dll
C:\WINDOWS\system32\qvvjvami.dll
C:\WINDOWS\system32\tjsywdle.dll

.
((((((((((((((((((((((((( Files Created from 2008-09-03 to 2008-10-03 )))))))))))))))))))))))))))))))
.

2008-10-01 17:57 . 2008-10-01 17:59 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-01 17:57 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-01 17:57 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-01 17:29 . 2008-10-01 17:29 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\AdobeUM
2008-10-01 05:23 . 2008-10-01 05:23 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\Template
2008-10-01 05:23 . 2008-10-02 19:57 484 –a—— C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\wklnhst.dat
2008-09-30 16:21 . 2008-09-30 16:21 d——– C:\Program Files\Panda Security
2008-09-30 16:21 . 2008-06-19 17:24 28,544 –a—— C:\WINDOWS\system32\drivers\pavboot.sys
2008-09-30 15:36 . 2008-09-30 15:36 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\Malwarebytes
2008-09-30 15:36 . 2008-09-30 15:36 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-29 15:43 . 2008-10-01 15:54 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Contacts
2008-09-29 05:12 . 2008-09-29 05:12 d——– C:\Program Files\Raxco
2008-09-29 05:12 . 2008-09-29 05:12 d——– C:\Documents and Settings\All Users\Application Data\Raxco
2008-09-29 05:11 . 2008-09-29 05:11 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\InstallShield
2008-09-27 22:34 . 2008-09-27 22:34 95 –a—— C:\WINDOWS\wininit.ini
2008-09-27 22:02 . 2008-09-28 14:25 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-27 12:53 . 2008-09-27 12:53 d——– C:\temp
2008-09-26 23:01 . 2008-09-26 23:01 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Yvonne
2008-09-26 21:30 . 2008-09-26 21:30 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\Bell
2008-09-26 21:29 . 2004-08-11 05:06 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\WINDOWS
2008-09-26 21:29 . 2008-08-19 00:52 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\SampleView
2008-09-26 21:29 . 2008-08-19 00:50 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\McAfee
2008-09-26 21:29 . 2008-09-29 15:43 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY
2008-09-23 20:32 . 2008-09-23 20:32 d——– C:\WINDOWS\Sun
2008-09-18 18:24 . 2008-09-26 21:38 d——– C:\Program Files\Pilates for Wimps Workout.xvid. DVDRip
2008-09-14 21:29 . 2008-09-14 21:29 89 –a—— C:\WINDOWS\system32\xi?
2008-09-07 22:22 . 2008-09-07 22:22 d——– C:\Program Files\Windows Media Connect 2
2008-09-06 22:20 . 2008-09-06 22:20 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-04 18:48 . 2008-09-04 18:48 d——– C:\Program Files\View22
2008-09-03 15:35 . 2008-09-03 15:35 940,794 –a—— C:\WINDOWS\system32\LoopyMusic.wav
2008-09-03 15:35 . 2008-09-03 15:35 146,650 –a—— C:\WINDOWS\system32\BuzzingBee.wav
2008-09-03 15:35 . 2008-09-17 05:00 73,728 –a—— C:\WINDOWS\ALCFDRTM.VER
2008-09-03 15:35 . 2008-09-03 15:35 73,728 –a—— C:\WINDOWS\ALCFDRTM.EXE

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-29 09:11 53,192 —-a-w C:\WINDOWS\system32\drivers\rp_skt32.sys
2008-09-28 18:48 ——— d—–w C:\Program Files\Common Files\Scanner
2008-09-27 01:39 ——— d—–w C:\Program Files\Symantec
2008-09-08 01:48 ——— d—–w C:\Program Files\CONEXANT
2008-09-02 17:34 ——— d—–w C:\Program Files\BigFix
2008-09-02 17:33 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-02 17:32 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-08-26 02:26 ——— d—–w C:\Documents and Settings\Melanie\Application Data\CyberLink
2008-08-25 17:15 ——— d—–w C:\Program Files\Windows Live
2008-08-25 17:14 ——— dcsh–w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-25 17:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-23 04:14 0 —ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2008-08-23 04:14 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_zumbus_01007.Wdf
2008-08-23 04:13 ——— d—–w C:\Program Files\Zune
2008-08-23 03:57 ——— d—–w C:\Program Files\Digital Media Reader
2008-08-23 03:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-08-22 08:58 ——— d—–w C:\Documents and Settings\Nicole\Application Data\Bell
2008-08-21 17:29 ——— d—–w C:\Program Files\Common Files\Adobe
2008-08-20 05:41 ——— d—–w C:\Documents and Settings\Melanie\Application Data\Bell
2008-08-19 19:43 ——— d—–w C:\Program Files\MSXML 4.0
2008-08-19 19:35 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-19 18:13 294,912 —-a-w C:\WINDOWS\HideWin.exe
2008-08-19 18:13 ——— d—–w C:\Program Files\Realtek
2008-08-19 05:45 ——— d—–w C:\Program Files\Personal Vault
2008-08-19 05:45 ——— d—–w C:\Program Files\Common Files\Authentium
2008-08-19 05:44 ——— d—–w C:\Program Files\CA
2008-08-19 05:44 ——— d—–w C:\Program Files\Bell
2008-08-19 05:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\Bell
2008-08-19 05:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-19 05:02 ——— d—–w C:\Program Files\Program Shortcuts
2008-08-19 04:52 ——— d—–w C:\Documents and Settings\Nicole\Application Data\SampleView
2008-08-19 04:52 ——— d—–w C:\Documents and Settings\Melanie\Application Data\SampleView
2008-08-19 04:51 ——— d—–w C:\Program Files\CyberLink
2008-08-19 04:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-08-19 04:50 ——— d—–w C:\Program Files\MSN Encarta Plus
2008-08-19 04:50 ——— d—–w C:\Program Files\Microsoft Money 2005
2008-08-19 04:50 ——— d—–w C:\Documents and Settings\Nicole\Application Data\McAfee
2008-08-19 04:50 ——— d—–w C:\Documents and Settings\Melanie\Application Data\McAfee
2008-08-19 04:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-08-19 04:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-19 04:47 ——— d—–w C:\Program Files\Google
2008-08-19 04:46 ——— d—–w C:\Program Files\Microsoft Works
2008-08-19 04:44 ——— d—–w C:\Program Files\Ahead
2008-08-19 04:43 ——— d—–w C:\Program Files\Microsoft Picture It! 10
2008-08-19 04:43 ——— d—–w C:\Program Files\Intel
2008-08-19 04:43 ——— d—–w C:\Program Files\Common Files\Ahead
2008-08-19 04:40 ——— d—–w C:\Program Files\Java
2008-08-19 04:40 ——— d—–w C:\Program Files\Common Files\New Boundary
2008-08-19 04:40 ——— d—–w C:\Program Files\Common Files\Java
2008-08-19 04:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Prism Deploy
2008-07-19 04:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 04:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 04:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 04:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 04:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 04:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 04:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 04:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 03:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 03:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"IndexCleaner"="C:\Program Files\Bell\Security Manager\IdxClnR.exe" [2008-03-10 61168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 212992]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"SSA.exe"="C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" [2007-03-27 2061816]
"Sympatico Security Manager"="C:\Program Files\Bell\Security Manager\Rps.exe" [2008-03-10 311024]
"AlcFDMonitor"="C:\WINDOWS\ALCFDRTM.EXE" [2008-09-03 73728]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2008-04-29 158624]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 C:\WINDOWS\system32\HdAShCut.exe]
"CHotkey"="zHotkey.exe" [2004-05-17 C:\WINDOWS\zHotkey.exe]
"ShowWnd"="ShowWnd.exe" [2003-09-19 C:\WINDOWS\ShowWnd.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-05-12 C:\WINDOWS\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2005-05-12 C:\WINDOWS\ALCWZRD.EXE]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\BigFix.exe [2008-08-19 2348584]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Digital Media Reader\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=

R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 28544]
R2 VaultClientUpgrade;Personal Vault Upgrade Service;C:\Program Files\Personal Vault\VaultClientUpgrade.exe [2008-03-07 53248]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-04-29 40704]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-04-29 61856]
S3 Radialpoint Security Services;Sympatico Security Manager;C:\Program Files\Bell\Security Manager\RpsSecurityAware.exe [2008-03-10 67824]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-04-29 245664]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-03 06:05:40
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-10-03 6:06:17
ComboFix-quarantined-files.txt 2008-10-03 10:06:13
ComboFix2.txt 2008-10-02 19:37:18

Pre-Run: 186,041,548,800 bytes free
Post-Run: 186,081,038,336 bytes free

255 — E O F — 2008-09-10 09:56:43


Thanks so much
Here's the Hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 8:47:59 PM, on 04/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Bell\Security Manager\Fws.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Personal Vault\VaultClientUpgrade.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Bell\Security Manager\rpsupdaterR.exe
C:\Program Files\Bell\Security Manager\RpsSecurityAware.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
C:\Program Files\Bell\Security Manager\Rps.exe
C:\WINDOWS\ALCFDRTM.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Bell\Sympatico Security Advisor\SSAComHandler.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.imdb.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
O4 - HKLM\..\Run: [Sympatico Security Manager] "C:\Program Files\Bell\Security Manager\Rps.exe"
O4 - HKLM\..\Run: [AlcFDMonitor] C:\WINDOWS\ALCFDRTM.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Security Manager\IdxClnR.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Security Manager\IdxClnR.exe"
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1219122505109
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://hgtv2.view22.com/view22/app/view22rte.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Sympatico Security Manager (Radialpoint Security Services) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\RpsSecurityAware.exe
O23 - Service: Sympatico Security Manager Update Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\rpsupdaterR.exe
O23 - Service: Sympatico Security Manager Firewall (RP_FWS) - Bell Sympatico - C:\Program Files\Bell\Security Manager\Fws.exe
O23 - Service: Personal Vault Upgrade Service (VaultClientUpgrade) - BELL - C:\Program Files\Personal Vault\VaultClientUpgrade.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe C:\Program Files\Bell\Security Manager Does all 3 of these include an Anti-Virus programs?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI