This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Serious issues

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:pullhair: Please help I am at a loss AVG is reporting 7 viruses that it will not remove! Lst nite I lost control of being able to access Task Manager and my desktop background disappeared! I am getting all these pop up messages giving me Warnings and my system every now and again just shuts down!
I had run a HJT Log as shown!

Please help before my system shuts down for good!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:34:57, on 10/6/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\PROGRA~1\DELLSU~1\DSAgnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\Pelmiced.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqDIREC.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG7\avgwb.dat
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070521
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [Make A Voozie] "C:\Documents and Settings\All Users\Application Data\Make A Voozie\VoozieMaker.exe" /startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [bc619ff5] rundll32.exe "C:\WINDOWS\system32\ylxotrqb.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [DellSupport] "C:\PROGRA~1\DELLSU~1\DSAgnt.exe" /startup
O4 - HKCU\..\Policies\Explorer\Run: [NT Printing Services6] dllhosts.exe
O4 - HKCU\..\Policies\Explorer\Run: [Windows Printing Driver] doskeys.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Palm Registration.lnk = C:\Program Files\Palm\register.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Palo Alto Software Update Manager 8.0.lnk = C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://pccheckup.dellfix.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {3BA3B159-7533-4F96-A2CE-EE5894BBD3D5} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scanner/SYSSCANNER.cab
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) - http://connect.comcast.com/dl/Comcast%20Ac…%20Controls.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqcpqdktp/downloads/sysinfo.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://messenger.zone.msn.com/EN-US/a-LUXR/mjolauncher.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://pcpitstop.com/antivirus/PitPav.cab
O20 - AppInit_DLLs: zhaqth.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 11042 bytes

Thank you in advance! :notworthy:
Hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.



Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
Ok I think I messed up.
I logged in under Safe Mode and began running the SDFix. Thpage displays this will run up to 20 minutes. We; it appeared to have frozen an no activty was taking place after about 45 minutes, so I manually shut down and restarted in normal mode.
When I rearted the SDFix was till running. The following report is from that test.

SDFix Report


SDFix: Version 1.233
Run by [removed] on Wed 10/07/2009 at 19:23

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\user\Desktop\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\system32\lphcnmfj0e37v.exe - Deleted
C:\WINDOWS\system32\rqRKAPGy.dll - Deleted
C:\Setup_ver1.1358.0.exe - Deleted
C:\Documents and Settings\user\Favorites\Malware Defender.url - Deleted
C:\Documents and Settings\user\Favorites\Protect Your Privacy.url - Deleted
C:\Documents and Settings\user\Favorites\System Error Fixer.url - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\.tt12.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\.tt13.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\.tt15.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\.tt1F.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\.tt21.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\.tt23.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\.tt25.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\.tt27.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\.tt9.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\.tt12.tmp.vbs - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\.tt9.tmp.vbs - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\TMP9.tmp - Deleted
C:\DOCUME~1\user\LOCALS~1\Temp\removalfile.bat - Deleted
C:\WINDOWS\system32\TDSSerrors.log - Deleted
C:\WINDOWS\system32\tdssl.dll - Deleted
C:\WINDOWS\system32\tdssservers.dat - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-07 20:10:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-350846322-370844861-420069996-1006]
"RefCount"=dword:00000020

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"="C:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe:*:Enabled:BearShare"
"C:\\WINDOWS\\system32\\fxsclnt.exe"="C:\\WINDOWS\\system32\\fxsclnt.exe:*:Enabled:Microsoft Fax Console"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"="C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice"
"C:\\Documents and Settings\\user\\Local Settings\\Temp\\~osD.tmp\\ossproxy.exe"="C:\\Documents and Settings\\user\\Local Settings\\Temp\\~osD.tmp\\ossproxy.exe:*:Enabled:ossproxy.exe"
"c:\\windows\\system32\\rlvknlg.exe"="c:\\windows\\system32\\rlvknlg.exe:*:Enabled:rlvknlg.exe"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"="C:\\Program Files\\Winamp Remote\\bin\\Orb.exe:*:Enabled:Orb"
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe:*:Enabled:OrbTray"
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. Take a deep breath "
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty® 4 - Modern Warfare™"
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

Remaining Files :


File Backups: - C:\DOCUME~1\user\Desktop\SDFix\backups\backups.zip

Files with Hidden Attributes :

Sun 13 Apr 2008 1,695,232 ..SH. — "C:\Program Files\Messenger\msmsgs.exe"
Sun 13 Apr 2008 60,416 A.SH. — "C:\Program Files\Outlook Express\msimn.exe"
Sun 13 Apr 2008 4,639 A.SH. — "C:\Program Files\Windows Media Player\mplayer2.exe"
Wed 18 Oct 2006 64,000 A.SH. — "C:\Program Files\Windows Media Player\wmplayer.exe"
Sun 16 Sep 2007 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 5 Jul 2007 146,432 ..SHR — "C:\Program Files\Verizon Wireless\V CAST Music Manager\Setup.exe"
Mon 7 May 2007 53,248 A.SHR — "C:\Program Files\Verizon Wireless\V CAST Music Manager\_Setupx.dll"
Sat 8 Sep 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Mon 21 May 2007 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"
Mon 21 May 2007 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp"
Mon 21 May 2007 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp"
Mon 21 May 2007 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp"
Mon 21 May 2007 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
Mon 21 May 2007 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch6\lock.tmp"
Tue 7 Aug 2007 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch7\lock.tmp"

Finished!



The send test LOP S&D.exe; Report is as follows…


——————–\\ Lop S&D; 4.2.4-5 XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : AMD Athlon™ 64 X2 Dual-Core Processor TK-53 )
BIOS : BIOS Version 2.4.1
USER : user ( Administrator )
BOOT : Normal boot
Antivirus : AVG Anti-Virus Free 8.0 (Activated)
Firewall : Norton Internet Worm Protection 2006 (Not Activated)
C:\ (Local Disk) - NTFS - Total : 108 Go Free : 70 Go
D:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( Wed 10/07/2009|20:38 )

——————–\\ Listing folders in APPLIC~1

[03/18/2008|04:39] C:\DOCUME~1\ADMINI~1\APPLIC~1\Gtek
[03/18/2008|04:39] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

[05/21/2007|14:04] C:\DOCUME~1\ADMINI~1.TRA\APPLIC~1\ATI
[05/21/2007|14:13] C:\DOCUME~1\ADMINI~1.TRA\APPLIC~1\Gtek
[08/10/2004|13:08] C:\DOCUME~1\ADMINI~1.TRA\APPLIC~1\Identities
[05/21/2007|13:59] C:\DOCUME~1\ADMINI~1.TRA\APPLIC~1\InstallShield
[10/07/2009|15:52] C:\DOCUME~1\ADMINI~1.TRA\APPLIC~1\Microsoft

[10/05/2007|21:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[08/07/2007|17:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[08/07/2007|18:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[10/07/2009|13:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Autodesk
[10/07/2009|16:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg8
[08/20/2007|12:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Citrix
[12/22/2007|09:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Dell
[02/13/2008|21:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[08/07/2007|22:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GTek
[08/05/2007|23:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HotSync
[08/22/2007|22:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[05/21/2007|14:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[10/05/2008|19:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[10/07/2009|17:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[04/29/2008|18:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[10/04/2008|06:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
[03/23/2008|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[08/09/2007|14:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Office Genuine Advantage
[01/12/2008|00:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Palo Alto Software
[01/12/2008|00:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PAS
[08/10/2004|13:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[10/05/2008|20:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[05/21/2007|14:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
[08/22/2007|23:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
[10/03/2008|19:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SupportSoft
[08/22/2007|19:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[10/05/2008|18:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[08/06/2007|23:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[04/29/2008|18:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[10/07/2009|14:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!

[05/21/2007|14:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ATI
[05/21/2007|14:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Gtek
[08/10/2004|13:08] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[05/21/2007|13:59] C:\DOCUME~1\DEFAUL~1\APPLIC~1\InstallShield
[08/10/2004|12:57] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[10/07/2009|15:52] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[10/07/2009|15:52] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft


[03/30/2008|21:33] C:\DOCUME~1\user\APPLIC~1\Adobe
[10/05/2007|21:49] C:\DOCUME~1\user\APPLIC~1\AdobeUM
[08/16/2007|16:10] C:\DOCUME~1\user\APPLIC~1\Apple Computer
[05/21/2007|14:04] C:\DOCUME~1\user\APPLIC~1\ATI
[10/07/2009|07:30] C:\DOCUME~1\user\APPLIC~1\Autodesk
[10/07/2009|16:46] C:\DOCUME~1\user\APPLIC~1\AVGTOOLBAR
[09/23/2007|18:16] C:\DOCUME~1\user\APPLIC~1\CyberLink
[08/05/2007|23:16] C:\DOCUME~1\user\APPLIC~1\FUJIFILM
[08/07/2007|09:07] C:\DOCUME~1\user\APPLIC~1\Google
[05/21/2007|14:13] C:\DOCUME~1\user\APPLIC~1\Gtek
[08/20/2007|12:37] C:\DOCUME~1\user\APPLIC~1\Help
[02/16/2008|09:42] C:\DOCUME~1\user\APPLIC~1\Hewlett-Packard
[08/05/2007|23:00] C:\DOCUME~1\user\APPLIC~1\HotSync
[08/10/2004|13:08] C:\DOCUME~1\user\APPLIC~1\Identities
[05/21/2007|13:59] C:\DOCUME~1\user\APPLIC~1\InstallShield
[01/21/2008|00:22] C:\DOCUME~1\user\APPLIC~1\Jasc
[08/05/2007|23:04] C:\DOCUME~1\user\APPLIC~1\Leadertech
[10/05/2008|14:37] C:\DOCUME~1\user\APPLIC~1\LimeWire
[08/06/2007|14:45] C:\DOCUME~1\user\APPLIC~1\Macromedia
[10/07/2009|17:53] C:\DOCUME~1\user\APPLIC~1\Malwarebytes
[10/07/2009|15:52] C:\DOCUME~1\user\APPLIC~1\Microsoft
[12/16/2007|23:19] C:\DOCUME~1\user\APPLIC~1\Mozilla
[08/09/2007|18:46] C:\DOCUME~1\user\APPLIC~1\MSNInstaller
[01/12/2008|01:03] C:\DOCUME~1\user\APPLIC~1\Palo Alto Software
[03/22/2008|11:34] C:\DOCUME~1\user\APPLIC~1\Real
[10/05/2008|15:27] C:\DOCUME~1\user\APPLIC~1\skypePM
[09/13/2007|23:24] C:\DOCUME~1\user\APPLIC~1\Sonic
[08/18/2007|23:20] C:\DOCUME~1\user\APPLIC~1\Sun
[10/05/2008|18:47] C:\DOCUME~1\user\APPLIC~1\SUPERAntiSpyware.com
[12/16/2007|23:22] C:\DOCUME~1\user\APPLIC~1\Talkback
[08/08/2007|20:04] C:\DOCUME~1\user\APPLIC~1\Template
[10/05/2008|16:16] C:\DOCUME~1\user\APPLIC~1\TmpRecentIcons
[10/05/2008|20:12] C:\DOCUME~1\user\APPLIC~1\VoozieMaker
[03/01/2008|23:30] C:\DOCUME~1\user\APPLIC~1\Winamp
[12/23/2007|02:21] C:\DOCUME~1\user\APPLIC~1\WinRAR
[04/08/2008|23:27] C:\DOCUME~1\user\APPLIC~1\Yahoo!
[10/05/2008|14:43] C:\DOCUME~1\user\APPLIC~1\zweitgeist

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[10/07/2009 16:08][–a——] C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1223327208.job
[10/07/2009 18:55][–a——] C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1209599663.job
[10/07/2009 18:37][–a——] C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1203172893.job
[10/07/2009 17:40][–a——] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[10/07/2009 20:20][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 05:00][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[01/19/2008|22:38] C:\Program Files\Activision
[05/21/2007|14:13] C:\Program Files\Adobe
[05/21/2007|14:00] C:\Program Files\AMD
[09/16/2007|11:53] C:\Program Files\Apple Software Update
[05/21/2007|13:58] C:\Program Files\ATI Technologies
[10/07/2009|13:28] C:\Program Files\AutoCAD 2008
[10/07/2009|13:15] C:\Program Files\Autodesk
[10/07/2009|16:09] C:\Program Files\AVG
[05/21/2007|14:12] C:\Program Files\BAE
[01/12/2008|08:23] C:\Program Files\BlackAngel Software
[05/21/2007|13:59] C:\Program Files\Broadcom
[10/07/2009|13:15] C:\Program Files\Common Files
[08/10/2004|13:02] C:\Program Files\ComPlus Applications
[05/21/2007|14:02] C:\Program Files\CONEXANT
[10/07/2009|14:04] C:\Program Files\CyberLink
[01/18/2008|23:14] C:\Program Files\Dcads Games Collection
[03/18/2008|06:37] C:\Program Files\Dell
[05/21/2007|14:13] C:\Program Files\Dell Support
[12/28/2007|16:46] C:\Program Files\EA GAMES
[10/07/2009|15:50] C:\Program Files\eMule
[10/05/2008|20:54] C:\Program Files\Enigma Software Group
[08/05/2007|23:09] C:\Program Files\FinePixViewer
[01/18/2008|23:33] C:\Program Files\FLStudio4
[10/06/2008|01:12] C:\Program Files\Fox
[10/04/2008|17:11] C:\Program Files\Google
[08/22/2007|14:56] C:\Program Files\Grisoft
[02/16/2008|09:38] C:\Program Files\Hewlett-Packard
[09/12/2007|23:30] C:\Program Files\HP
[02/27/2008|23:22] C:\Program Files\InstallShield Installation Information
[10/04/2008|00:33] C:\Program Files\Internet Explorer
[11/09/2007|02:24] C:\Program Files\iPod
[11/09/2007|02:24] C:\Program Files\iTunes
[04/29/2008|19:33] C:\Program Files\Java
[10/05/2008|19:35] C:\Program Files\Lavasoft
[10/03/2007|00:04] C:\Program Files\LG Electronics
[10/07/2009|17:54] C:\Program Files\Malwarebytes' Anti-Malware
[10/05/2008|17:31] C:\Program Files\Messenger
[08/10/2004|13:04] C:\Program Files\microsoft frontpage
[10/07/2009|07:23] C:\Program Files\Microsoft Office
[05/21/2007|14:06] C:\Program Files\Microsoft Plus! Digital Media Edition
[05/21/2007|14:06] C:\Program Files\Microsoft Plus! Photo Story 2 LE
[10/03/2008|21:25] C:\Program Files\Microsoft Works
[08/13/2007|16:23] C:\Program Files\Microsoft.NET
[10/05/2008|17:24] C:\Program Files\Movie Maker
[12/18/2007|23:50] C:\Program Files\Mozilla Firefox
[09/29/2007|23:09] C:\Program Files\MSBuild
[08/09/2007|18:46] C:\Program Files\MSN
[08/10/2004|13:01] C:\Program Files\MSN Gaming Zone
[08/07/2007|22:36] C:\Program Files\MSXML 4.0
[09/29/2007|23:09] C:\Program Files\MSXML 6.0
[05/21/2007|14:05] C:\Program Files\MUSICMATCH
[02/12/2008|06:36] C:\Program Files\Native Instruments
[10/05/2008|17:18] C:\Program Files\NetMeeting
[05/21/2007|14:04] C:\Program Files\NetWaiting
[08/10/2004|13:01] C:\Program Files\Online Services
[10/05/2008|17:18] C:\Program Files\Outlook Express
[12/10/2007|06:06] C:\Program Files\Palm
[03/18/2008|06:37] C:\Program Files\PCCheckupOnline
[10/07/2009|14:03] C:\Program Files\PCPitstop
[02/05/2008|00:47] C:\Program Files\Plus!
[11/09/2007|02:23] C:\Program Files\QuickTime
[12/16/2007|23:18] C:\Program Files\Real
[09/29/2007|23:05] C:\Program Files\Reference Assemblies
[05/21/2007|14:11] C:\Program Files\Roxio
[05/21/2007|14:02] C:\Program Files\Sigmatel
[05/21/2007|14:12] C:\Program Files\Sonic
[05/21/2007|13:59] C:\Program Files\Synaptics
[04/29/2008|23:10] C:\Program Files\Three Rings Design
[10/06/2008|19:34] C:\Program Files\Trend Micro
[10/07/2009|07:27] C:\Program Files\Uninstall Information
[10/04/2007|13:42] C:\Program Files\Verizon Wireless
[08/07/2007|22:30] C:\Program Files\WebCyberCoach
[02/20/2008|00:22] C:\Program Files\Winamp
[04/29/2008|18:53] C:\Program Files\Windows Live
[09/07/2007|12:55] C:\Program Files\Windows Media Connect 2
[10/05/2008|17:18] C:\Program Files\Windows Media Player
[10/05/2008|17:18] C:\Program Files\Windows NT
[08/10/2004|13:02] C:\Program Files\WindowsUpdate
[12/23/2007|02:20] C:\Program Files\WinRAR
[10/06/2008|09:47] C:\Program Files\World of Warcraft Trial
[08/10/2004|13:04] C:\Program Files\xerox
[10/07/2009|14:09] C:\Program Files\Yahoo!

——————–\\ Listing Folders in C:\Program Files\Common Files

[10/05/2007|21:51] C:\Program Files\Common Files\Adobe
[08/07/2007|17:59] C:\Program Files\Common Files\Apple
[10/07/2009|13:28] C:\Program Files\Common Files\Autodesk Shared
[10/06/2008|01:54] C:\Program Files\Common Files\Blizzard Entertainment
[10/07/2009|07:23] C:\Program Files\Common Files\DESIGNER
[08/22/2007|22:30] C:\Program Files\Common Files\Hewlett-Packard
[05/21/2007|14:11] C:\Program Files\Common Files\InstallShield
[01/12/2008|01:00] C:\Program Files\Common Files\Intuit
[05/21/2007|13:55] C:\Program Files\Common Files\Java
[10/07/2009|16:07] C:\Program Files\Common Files\Microsoft Shared
[08/10/2004|13:02] C:\Program Files\Common Files\MSSoap
[02/20/2008|00:43] C:\Program Files\Common Files\NSV
[08/10/2004|12:57] C:\Program Files\Common Files\ODBC
[01/12/2008|00:59] C:\Program Files\Common Files\Palo Alto Software
[12/16/2007|23:18] C:\Program Files\Common Files\Real
[05/21/2007|14:11] C:\Program Files\Common Files\Roxio Shared
[01/17/2008|23:49] C:\Program Files\Common Files\Scanner
[08/10/2004|13:02] C:\Program Files\Common Files\Services
[05/21/2007|14:11] C:\Program Files\Common Files\Sonic Shared
[08/10/2004|12:57] C:\Program Files\Common Files\SpeechEngines
[08/22/2007|19:46] C:\Program Files\Common Files\Symantec Shared
[10/05/2008|17:18] C:\Program Files\Common Files\System
[05/21/2007|14:10] C:\Program Files\Common Files\TiVo Shared
[04/29/2008|18:52] C:\Program Files\Common Files\WindowsLiveInstaller
[10/05/2008|19:34] C:\Program Files\Common Files\Wise Installation Wizard
[12/16/2007|23:18] C:\Program Files\Common Files\xing shared

——————–\\ Process

( 57 Processes )

iexplore.exe ~ [PID:1228]

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

C:\DOCUME~1\user\LOCALS~1\Temp\nso6A.tmp

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-07 20:44:18
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

C:\WINDOWS\system32\LTAKnnmp.ini
C:\WINDOWS\system32\LTAKnnmp.ini2
==> VUNDO <==

——————–\\ ROOTKIT !!

Rootkit Tibs ! .. [HKLM\..\ControlSet001\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKLM\..\ControlSet001\Services\tdssserv]
Rootkit Tibs ! .. [HKLM\..\ControlSet001\Enum\Root\tdssserv]

——————–\\ Cracks & Keygens ..

C:\DOCUME~1\user\Incomplete\T-799964162-Autodesk_Autocad_2008__(full_version_with_crack).rar
C:\DOCUME~1\user\Local Settings\Application Data\ApplicationHistory\KeyGenerator.exe.7268a55b.ini
C:\DOCUME~1\user\Local Settings\Application Data\ApplicationHistory\KeyGenerator.exe.fc25c691.ini
C:\DOCUME~1\user\Local Settings\Temp\Rar$EX05.969\AutoCAD.2008.Keygen.Only-XFORCE
C:\DOCUME~1\user\Local Settings\Temp\Rar$EX05.969\AutoCAD.2008.Keygen.Only-XFORCE\AutoCAD-2008-keygen.exe
C:\DOCUME~1\user\Local Settings\Temp\Rar$EX05.969\AutoCAD.2008.Keygen.Only-XFORCE\install.txt
C:\DOCUME~1\user\Local Settings\Temp\Rar$EX05.969\AutoCAD.2008.Keygen.Only-XFORCE\x-force.nfo
C:\DOCUME~1\user\Local Settings\Temp\Rar$EX19.9094\AutoCAD.2008.Keygen.Only-XFORCE
C:\DOCUME~1\user\Local Settings\Temp\Rar$EX19.9094\AutoCAD.2008.Keygen.Only-XFORCE\AutoCAD-2008-keygen.exe
C:\DOCUME~1\user\Local Settings\Temp\Rar$EX19.9094\AutoCAD.2008.Keygen.Only-XFORCE\install.txt
C:\DOCUME~1\user\Local Settings\Temp\Rar$EX19.9094\AutoCAD.2008.Keygen.Only-XFORCE\x-force.nfo
C:\DOCUME~1\user\Recent\Autocad 2008 Serial And Keygen English (2).lnk
C:\DOCUME~1\user\Recent\Autocad 2008 Serial And Keygen English.lnk


[F:2637][D:321]-> C:\DOCUME~1\user\LOCALS~1\Temp
[F:33][D:0]-> C:\DOCUME~1\user\Cookies
[F:1399][D:6]-> C:\DOCUME~1\user\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Wed 10/07/2009|20:47 - Option : [1]

——————–\\ Scan completed at 20:47:44


My boyfriend tried to fix the problem today (I think his downloads are the reson this has occurred!), I am having no better luck since his efforts!
I will say that the photo I had on my desktop was a white background, but is now dark blue!
This can NOT b good!

:pullhair:
You got infected because you used cracks and keygens

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\system32\LTAKnnmp.ini
    C:\WINDOWS\system32\LTAKnnmp.ini2
    C:\DOCUME~1\user\Incomplete\T-799964162-Autodesk_Autocad_2008__(full_version_with_crack).rar
    C:\DOCUME~1\user\Local Settings\Application Data\ApplicationHistory\KeyGenerator.exe.7268a55b.ini
    C:\DOCUME~1\user\Local Settings\Application Data\ApplicationHistory\KeyGenerator.exe.fc25c691.ini
    C:\DOCUME~1\user\Local Settings\Temp\Rar$EX05.969\AutoCAD.2008.Keygen.Only-XFORCE
    C:\DOCUME~1\user\Recent\Autocad 2008 Serial And Keygen English (2).lnk
    C:\DOCUME~1\user\Recent\Autocad 2008 Serial And Keygen English.lnk
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Please visit this web page for instructions for downloading and running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.
Ok, this is insane! idk how you do this! You ARE The Man! lol

Anywho, following is the log from "Move It" Report, I am in process of completing the tasks as you have advised and will be posting the "Combo Fix" Report.
I was a lil confused the directions for installing and running Combo Fix refer to moving information from Windows Recovery Console into Combo Fix, yet your directions dont say to do so! So I will be posting ComboFix Report only so far along with a new Hijack this file.
If this is wrong and I need to go back and do this, please advise.

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\WINDOWS\system32\LTAKnnmp.ini moved successfully.
C:\WINDOWS\system32\LTAKnnmp.ini2 moved successfully.
C:\DOCUME~1\user\Incomplete\T-799964162-Autodesk_Autocad_2008__(full_version_with_crack).rar moved successfully.
C:\DOCUME~1\user\Local Settings\Application Data\ApplicationHistory\KeyGenerator.exe.7268a55b.ini moved successfully.
C:\DOCUME~1\user\Local Settings\Application Data\ApplicationHistory\KeyGenerator.exe.fc25c691.ini moved successfully.
C:\DOCUME~1\user\Local Settings\Temp\Rar$EX05.969\AutoCAD.2008.Keygen.Only-XFORCE moved successfully.
C:\DOCUME~1\user\Recent\Autocad 2008 Serial And Keygen English (2).lnk moved successfully.
C:\DOCUME~1\user\Recent\Autocad 2008 Serial And Keygen English.lnk moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\user\LOCALS~1\Temp\fla20.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\user\LOCALS~1\Temp\Perflib_Perfdata_4d0.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\user\LOCALS~1\Temp\Perflib_Perfdata_d48.dat scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_710.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.4.2 log created on 10082009_184113

Files moved on Reboot…
File C:\DOCUME~1\user\LOCALS~1\Temp\fla20.tmp not found!
File C:\DOCUME~1\user\LOCALS~1\Temp\Perflib_Perfdata_4d0.dat not found!
File C:\DOCUME~1\user\LOCALS~1\Temp\Perflib_Perfdata_d48.dat not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\Perflib_Perfdata_710.dat not found!


Send Combo Fix & new HJT Log soon!
Following are the ComboFix Reports (without the Windows Console Recovery) and HJT Report.

Combo Fix

ComboFix 08-10-08.02 - user 2009-10-08 20:56:28.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.443 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active

.
- REDUCED FUNCTIONALITY MODE -
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\INSTALL.LOG
C:\WINDOWS\system32\drivers\spoolsv.exe
C:\WINDOWS\system32\ldpackage.dll
C:\WINDOWS\system32\model.dat
C:\WINDOWS\system32\silc_dll.dll
C:\xcrashdump.dat

.
((((((((((((((((((((((((( Files Created from 2009-09-09 to 2009-10-09 )))))))))))))))))))))))))))))))
.

2009-10-08 21:02 . 2009-10-08 14:56 81,920 –a—— C:\WINDOWS\system32\drivers\dllhst3g.exe
2009-10-08 18:42 . 2009-10-08 18:42 1,065,292 —hs—- C:\WINDOWS\system32\qbrojyeu.ini
2009-10-08 18:42 . 2009-10-08 18:42 78,336 –a—— C:\WINDOWS\system32\ueyjorbq.dll
2009-10-08 18:41 . 2009-10-08 18:41 d——– C:\_OTMoveIt
2009-10-08 18:41 . 2009-10-08 18:43 888,294 –ahs—- C:\WINDOWS\system32\LTAKnnmp.ini
2009-10-08 18:41 . 2009-10-08 18:41 345 –ahs—- C:\WINDOWS\system32\LTAKnnmp.ini2
2009-10-08 15:08 . 2009-10-08 16:07 1,065,301 —hs—- C:\WINDOWS\system32\ydnaeqlv.ini
2009-10-08 15:08 . 2009-10-08 15:08 112,128 –a—— C:\WINDOWS\system32\nyhjxpqv.dll
2009-10-08 15:08 . 2009-10-08 15:08 112,128 –a—— C:\WINDOWS\system32\nxvguj.dll
2009-10-08 14:56 . 2009-10-08 14:56 81,920 –a—— C:\WINDOWS\system\comrepl.exe
2009-10-08 14:56 . 2009-10-08 14:56 81,920 –a—— C:\WINDOWS\dllhst3g.exe
2009-10-07 20:37 . 2009-10-07 20:47 d——– C:\Lop SD
2009-10-07 20:26 . 2009-10-07 20:26 1,046,792 —hs—- C:\WINDOWS\system32\tcwikvjy.ini
2009-10-07 20:23 . 2009-10-07 20:23 110,592 –a—— C:\WINDOWS\system32\supjhg.dll
2009-10-07 20:23 . 2009-10-07 20:23 110,592 –a—— C:\WINDOWS\system32\bxfrlngc.dll
2009-10-07 19:19 . 2009-10-07 19:19 578,560 –a—— C:\WINDOWS\system32\dllcache\user32.dll
2009-10-07 19:07 . 2009-10-07 19:08 d——– C:\WINDOWS\ERUNT
2009-10-07 19:05 . 2008-10-07 22:54 d——– C:\SDFix
2009-10-07 18:54 . 2009-10-07 18:54 110,592 –a—— C:\WINDOWS\system32\xiikqz.dll
2009-10-07 18:54 . 2009-10-07 18:54 110,592 –a—— C:\WINDOWS\system32\nurvpjnr.dll
2009-10-07 18:51 . 2009-10-07 18:51 1,046,792 —hs—- C:\WINDOWS\system32\skiagfdc.ini
2009-10-07 18:50 . 2009-10-07 18:50 77,824 –a—— C:\WINDOWS\system32\cdfgaiks.dll
2009-10-07 17:53 . 2009-10-07 17:54 d——– C:\Program Files\Malwarebytes' Anti-Malware
2009-10-07 17:53 . 2009-10-07 17:53 d——– C:\Documents and Settings\user\Application Data\Malwarebytes
2009-10-07 17:53 . 2009-10-07 17:53 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-10-07 17:53 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2009-10-07 17:53 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2009-10-07 17:36 . 2009-10-07 17:36 1,056,677 —hs—- C:\WINDOWS\system32\kvrkbcmo.ini
2009-10-07 17:36 . 2009-10-07 17:36 312,832 –a—— C:\WINDOWS\system32\pjbjiagy.exe
2009-10-07 17:36 . 2009-10-07 17:36 77,824 –a—— C:\WINDOWS\system32\omcbkrvk.dll
2009-10-07 16:19 . 2009-10-08 15:08 d–h—– C:\$AVG8.VAULT$
2009-10-07 16:09 . 2009-10-08 14:04 d——– C:\WINDOWS\system32\drivers\Avg
2009-10-07 16:09 . 2009-10-07 16:09 d——– C:\Program Files\AVG
2009-10-07 16:09 . 2009-10-07 16:46 d——– C:\Documents and Settings\user\Application Data\AVGTOOLBAR
2009-10-07 16:09 . 2009-10-07 16:09 d——– C:\Documents and Settings\All Users\Application Data\avg8
2009-10-07 16:09 . 2009-10-07 16:09 97,928 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2009-10-07 16:09 . 2009-10-07 16:09 76,040 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2009-10-07 16:09 . 2009-10-07 16:09 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2009-10-07 16:01 . 2009-10-07 16:26 1,056,686 —hs—- C:\WINDOWS\system32\febwimup.ini
2009-10-07 15:58 . 2009-10-07 15:58 110,592 –a—— C:\WINDOWS\system32\kdhcpv.dll
2009-10-07 15:58 . 2009-10-07 15:58 110,592 –a—— C:\WINDOWS\system32\gdlibgvy.dll
2009-10-07 15:31 . 2009-10-07 15:31 42,496 –a—— C:\WINDOWS\system32\nnnkJyXQ.dll
2009-10-07 15:31 . 2009-10-07 15:31 42,496 –a—— C:\WINDOWS\system32\iifCUKaw.dll
2009-10-07 14:43 . 2009-10-07 15:59 1,056,686 —hs—- C:\WINDOWS\system32\pfxpjqnn.ini
2009-10-07 14:39 . 2009-10-08 15:38 d——– C:\Program Files\eMule
2009-10-07 14:37 . 2009-10-07 14:37 110,592 –a—— C:\WINDOWS\system32\yudybg.dll
2009-10-07 14:37 . 2009-10-07 14:37 110,592 –a—— C:\WINDOWS\system32\ubrtbgnh.dll
2009-10-07 14:34 . 2009-10-07 14:34 42,496 –a—— C:\WINDOWS\system32\cbXRHwtU.dll
2009-10-07 14:34 . 2009-10-07 14:34 42,496 –a—— C:\WINDOWS\system32\byXOifdE.dll
2009-10-07 13:58 . 2007-05-21 13:59 d——– C:\Documents and Settings\Administrator.TRACEY\Application Data\InstallShield
2009-10-07 13:58 . 2007-05-21 14:13 d–h—– C:\Documents and Settings\Administrator.TRACEY\Application Data\Gtek
2009-10-07 13:58 . 2007-05-21 14:04 d——– C:\Documents and Settings\Administrator.TRACEY\Application Data\ATI
2009-10-07 13:58 . 2009-10-07 16:10 d——– C:\Documents and Settings\Administrator.TRACEY
2009-10-07 13:50 . 2009-10-07 13:51 1,056,686 —hs—- C:\WINDOWS\system32\okvnjoss.ini
2009-10-07 13:34 . 2009-10-07 13:34 42,496 –a—— C:\WINDOWS\system32\ssqQihIc.dll
2009-10-07 13:34 . 2009-10-07 13:34 42,496 –a—— C:\WINDOWS\system32\mlJBTnoo.dll
2009-10-07 13:20 . 2009-10-07 13:28 d——– C:\Program Files\AutoCAD 2008
2009-10-07 13:15 . 2009-10-07 13:28 d——– C:\Program Files\Common Files\Autodesk Shared
2009-10-07 13:15 . 2009-10-07 13:15 d——– C:\Program Files\Autodesk
2009-10-07 07:30 . 2009-10-07 07:30 d——– C:\Documents and Settings\user\Application Data\Autodesk
2009-10-07 07:30 . 2009-10-07 13:20 d——– C:\Documents and Settings\All Users\Application Data\Autodesk
2009-10-07 07:14 . 2009-10-07 13:49 1,046,974 —hs—- C:\WINDOWS\system32\hqwpxrlo.ini
2009-10-07 07:12 . 2009-10-07 07:12 110,592 –a—— C:\WINDOWS\system32\mdtawk.dll
2009-10-07 07:12 . 2009-10-07 07:12 110,592 –a—— C:\WINDOWS\system32\logsqdeq.dll
2009-10-07 07:10 . 2009-10-07 07:10 1,046,956 —hs—- C:\WINDOWS\system32\cdiprjyd.ini
2009-10-07 07:10 . 2009-10-07 07:10 110,592 –a—— C:\WINDOWS\system32\gqcsio.dll
2009-10-07 07:10 . 2009-10-07 07:10 110,592 –a—— C:\WINDOWS\system32\bvuwrpru.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-08 19:56 81,920 —-a-w C:\WINDOWS\system32\drivers\spoolsv.exe
2009-10-07 20:15 2,698 —-a-w C:\WINDOWS\system32\tmp.reg
2009-10-07 19:09 ——— d—–w C:\Program Files\Yahoo!
2009-10-07 19:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2009-10-07 19:04 ——— d—–w C:\Program Files\CyberLink
2009-10-07 19:03 ——— d—–w C:\Program Files\PCPitstop
2008-10-06 20:26 22,328 —-a-w C:\Documents and Settings\user\Application Data\PnkBstrK.sys
2008-04-04 11:01 32 —-a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-09-15 06:45 2,884 —-a-w C:\Documents and Settings\user\Application Data\wklnhst.dat
2007-08-20 17:18 60,968 —-a-w C:\Documents and Settings\user\GoToAssistDownloadHelper.exe
2008-10-05 23:23 32,768 –sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008100520081006\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{12fe2f08-0d13-440b-a5fb-9418f110da00}]
2009-10-08 15:08 112128 –a—— C:\WINDOWS\system32\nxvguj.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2006-08-28 395776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-16 185896]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-09-22 761947]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 267048]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-01 1392640]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2009-10-07 1234712]
"bc619ff5"="C:\WINDOWS\system32\ueyjorbq.dll" [2009-10-08 78336]
"SigmatelSysTrayApp"="stsystra.exe" [2006-09-22 C:\WINDOWS\stsystra.exe]
"Mouse Suite 98 Daemon"="ICO.EXE" [2004-07-14 C:\WINDOWS\system32\ICO.EXE]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"ClipSrv"="C:\DOCUME~1\user\LOCALS~1\APPLIC~1\MICROS~1\clipsrv.exe" [2009-10-08 81920]

[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"ComRepl"="C:\WINDOWS\System\comrepl.exe" [2009-10-08 81920]
"NT Printing Services6"="dllhosts.exe" [2008-10-05 C:\WINDOWS\system32\dllhosts.exe]

[HKEY_USERS\.DEFAULT\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Spool"="C:\WINDOWS\System32\drivers\spoolsv.exe" [2009-10-08 81920]

C:\Documents and Settings\user\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
Palm Registration.lnk - C:\Program Files\Palm\register.exe [2005-08-08 2494464]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-09 147456]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-09 28672]
Palo Alto Software Update Manager 8.0.lnk - C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.exe [2005-11-16 122880]

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\System32\drivers\dllhst3g.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=,avgrsstx.dll nxvguj.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\pmnnKATL

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\eMule\\emule.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2009-10-07 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-10-07 875288]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-10-07 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2009-10-07 76040]
S3 BEHRINGER_2902;usb-audio.de driver for BEHRINGER USB AUDIO;C:\WINDOWS\system32\Drivers\BUSB2902.sys [2006-07-03 110272]
S3 MBAMSwissArmy;MBAMSwissArmy;C:\WINDOWS\system32\drivers\mbamswissarmy.sys [2008-09-10 38528]
S3 pelmouse;Mouse Suite Driver;C:\WINDOWS\system32\DRIVERS\pelmouse.sys [2005-11-23 16512]
S3 pelusblf;USB Mouse Low Filter Driver;C:\WINDOWS\system32\DRIVERS\pelusblf.sys [2006-04-04 13824]
.
Contents of the 'Scheduled Tasks' folder

2009-10-07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]

2009-10-07 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1203172893.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-09 17:56]

2009-10-07 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1209599663.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-09 17:56]

2009-10-07 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1223327208.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-09 17:56]
.
- - - - ORPHANS REMOVED - - - -

BHO-{0165CF1F-C034-474F-9E78-B270DDF4F35c} - C:\WINDOWS\system32\llxlfeld.dll
BHO-{77D4B7E5-72C0-4CC4-978C-6DD2C5CE682A} - C:\WINDOWS\system32\pmnnKATL.dll
HKCU-Run-msnmsgr - C:\Program Files\Windows Live\Messenger\msnmsgr.exe
HKCU-Run-Yahoo! Pager - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
HKCU-Run-Orb - C:\Program Files\Winamp Remote\bin\OrbTray.exe
HKCU-Run-Messenger (Yahoo!) - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
HKLM-Run-REGSHAVE - C:\Program Files\REGSHAVE\REGSHAVE.EXE
HKLM-Run-Make A Voozie - C:\Documents and Settings\All Users\Application Data\Make A Voozie\VoozieMaker.exe
HKLM-Run-ddoctorv2 - C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
Notify-__c005948 - C:\WINDOWS\system32\__c005948.dat


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\x6q805lb.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-08 21:03:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\WLTRYSVC.EXE
C:\WINDOWS\system32\BCMWLTRY.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2009-10-08 21:12:38 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-09 02:12:30

Pre-Run: 76,098,297,856 bytes free
Post-Run: 76,249,161,728 bytes free

237 — E O F — 2009-10-09 02:09:20


Hijack This Report


Logfile of HijackThis v1.99.1
Scan saved at 21:20:11, on 10/8/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\DOCUME~1\user\LOCALS~1\APPLIC~1\MICROS~1\clipsrv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe

Lemme know whats next…

:wavey:
You seem to either be using an old version of ComboFix or running it in reduced mode yourself Can you re-download it from the link I gave you and run it again please

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI