This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virus Help, Tomk please help

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Tomk, sorry that I haven't posted this earlier then now, but as you mention in my last post real life gets in our ways and it sure does. Hopefully you can still help me out with my problem. So here are my ComboFix.txt, Kaspersky report and the new Hijackthis log, that you wanted me to post after I ran them. Once again sorry for the delay, but real life got in my way before I could post this



ComboFix 08-10-05.10 - Kevin 2008-10-06 10:47:50.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.229 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\My Documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\Kevin\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

—– BITS: Possible infected sites —–

hxxp://patch.everquest.com:7001
.
((((((((((((((((((((((((( Files Created from 2008-09-06 to 2008-10-06 )))))))))))))))))))))))))))))))
.

2008-09-26 22:54 . 2008-10-06 09:05 d——– C:\Documents and Settings\LocalService\Application Data\SACore
2008-09-13 11:19 . 2008-09-13 11:19 d——– C:\Temp
2008-09-12 21:54 . 2008-09-12 21:54 d——– C:\Documents and Settings\Kevin\Application Data\Malwarebytes
2008-09-12 21:53 . 2008-09-12 21:53 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-12 21:53 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-12 21:53 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-12 21:52 . 2008-09-12 21:54 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-12 21:52 . 2008-09-12 21:52 d——– C:\Program Files\Common Files\Download Manager
2008-09-09 11:44 . 2008-09-09 11:44 d——– C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-09-09 11:43 . 2008-09-09 11:44 d——– C:\Program Files\Dell Support Center
2008-09-09 11:42 . 2008-09-09 11:43 d——– C:\Program Files\Common Files\supportsoft
2008-09-08 11:53 . 2008-09-08 11:53 dr-h—– C:\Documents and Settings\Gooz\Application Data\yahoo!
2008-09-07 14:50 . 2008-09-13 00:51 d——– C:\Documents and Settings\All Users\Application Data\Dell

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-06 15:35 ——— d—–w C:\Program Files\PartyGaming
2008-10-06 13:59 ——— d—–w C:\Program Files\McAfee
2008-09-16 04:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-09-10 06:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-07 21:11 ——— d—–w C:\Program Files\Common Files\AOL
2008-09-07 21:09 ——— d—–w C:\Program Files\Common Files\Nullsoft
2008-09-07 19:50 ——— d—–w C:\Documents and Settings\Gooz\Application Data\Gtek
2008-09-06 04:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-09-05 04:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-01 19:07 ——— d—–w C:\Program Files\MSN Messenger
2008-09-01 19:02 ——— d—–w C:\Program Files\MSN Games
2008-08-06 18:45 ——— d—–w C:\Documents and Settings\Kevin\Application Data\acccore
2008-08-06 18:39 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-08-06 18:37 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-30 02:03 61,480 —-a-w C:\Documents and Settings\Kevin\GoToAssistDownloadHelper.exe
.

((((((((((((((((((((((((((((( snapshot@2008-09-18_ 1.06.04.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-15 14:24:00 1,013,552 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_bcont.exe
+ 2007-11-15 14:24:00 1,013,552 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_bcont_nm.exe
+ 2007-11-15 14:24:00 1,017,240 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_dsc.exe
+ 2007-11-15 14:23:56 1,069,056 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_libeay32.dll
+ 2007-09-06 18:16:24 421,888 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_pcdr2d3dvideodx9.dll
+ 2007-11-15 14:23:56 202,544 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtcmd.exe
+ 2007-11-15 14:23:56 378,408 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtevent.dll
+ 2007-11-15 14:23:56 398,624 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtfod.dll
+ 2007-11-15 14:23:56 116,264 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprthook.dll
+ 2007-11-15 14:23:56 73,728 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtmessage.dll
+ 2007-11-15 14:23:56 873,760 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtsched.dll
+ 2007-11-15 14:23:56 202,544 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtsvc.exe
+ 2007-11-15 14:23:56 337,448 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprttrigger.dll
+ 2007-11-15 14:23:56 374,048 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtui.dll
+ 2007-11-15 14:23:56 341,280 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtupdate.dll
+ 2007-11-15 14:23:56 200,704 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_ssleay32.dll
+ 2007-11-15 14:23:56 20,480 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_SupportSoft.Agent.Sprocket.dll
+ 2007-11-15 14:23:56 24,576 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_SupportSoft.Agent.Sprocket.SupportMessage.dll
- 2008-09-18 01:36:21 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-10-06 14:00:00 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-09-18 01:36:21 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-10-06 14:00:00 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-15 05:58:07 2,516 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
+ 2008-09-24 16:22:32 2,516 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-06-07 4670968]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 59392]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-29 339968]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-17 135168]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-10-09 26112]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2006-01-17 53248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-20 282624]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 C:\WINDOWS\stsystra.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2005-10-09 156784]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=nibizi.dll rsjnpr.dll bvmmxm.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-09-08 198944]
S2 0086501223301591mcinstcleanup;McAfee Application Installer Cleanup (0086501223301591);C:\WINDOWS\TEMP\008650~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini [ ]

*Newly Created Service* - 0086501223301591MCINSTCLEANUP
.
Contents of the 'Scheduled Tasks' folder

2008-09-15 C:\WINDOWS\Tasks\McDefragTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2008-10-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-06 10:54:35
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\ehome\ehRecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\McAfee\MSK\msksrver.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
C:\PROGRA~1\McAfee\MSC\mcuimgr.exe
C:\ComboFix\pv.cfexe
.
**************************************************************************
.
Completion time: 2008-10-06 11:01:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-06 16:01:13
ComboFix2.txt 2008-09-18 06:06:47

Pre-Run: 51,985,027,072 bytes free
Post-Run: 51,974,770,688 bytes free

179 — E O F — 2008-09-13 03:24:07



——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, October 6, 2008
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, October 06, 2008 13:05:11
Records in database: 1294374
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 106156
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 01:59:27


File name / Threat name / Threats count
C:\Documents and Settings\Kevin\My Documents\CursorManiaSetup2.2.60.4.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.av 1

The selected area was scanned.




Logfile of HijackThis v1.99.1
Scan saved at 12:33:49 AM, on 10/20/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sports.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.87.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,9…pdatePortal.cab
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://cdn2.zone.msn.com/binframework/v10/…gr.cab31267.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (ZPA_TexasHoldem Object) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab43895.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} (AstoundLauncher Control) - http://zone.msn.com/bingame/jobo/default/A…ersion=1,0,0,10
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/default/SproutLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/cnma/default/cinematycoon.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://sympatico.zone.msn.com/bingame/dash…sh.1.0.0.98.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: nibizi.dll rsjnpr.dll bvmmxm.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
Kqueb,


Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
Tomk, here's my Lop S&D log


——————–\\ Lop S&D 4.2.4-6 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Pentium® 4 CPU 3.00GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A00
USER : Kevin ( Administrator )
BOOT : Normal boot
Antivirus : McAfee VirusScan (Not Activated)
Firewall : McAfee Personal Firewall (Activated)
C:\ (Local Disk) - NTFS - Total : 69 Go Free : 48 Go
D:\ (CD or DVD)
E:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 20-10-2008|20:35 )
Option : [1] ( Wed 10/22/2008|11:59 )

——————–\\ Listing folders in APPLIC~1

[08/19/2004|04:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Identities
[10/09/2005|09:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Jasc Software Inc
[10/09/2005|09:29] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[10/09/2005|09:23] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Sun

[05/06/2008|11:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[08/06/2008|01:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL
[08/06/2008|01:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL OCP
[12/29/2007|10:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Citrix
[09/13/2008|12:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Dell
[05/29/2006|10:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ DIGStream
[11/06/2005|04:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ GameHouse
[10/09/2005|09:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ GTek
[10/09/2005|09:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield
[10/09/2005|09:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Intuit
[09/12/2008|09:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[02/10/2006|04:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ MCA177.tmp
[09/04/2008|11:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ McAfee
[02/05/2007|02:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[12/04/2005|03:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ MumboJumbo
[06/14/2006|12:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ MVTLogs
[06/01/2007|01:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PlayFirst
[01/14/2008|02:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PopCap
[02/28/2006|02:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ QuickTime
[03/30/2007|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sandlot Games
[08/19/2004|04:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SBSI
[09/05/2008|11:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SiteAdvisor
[09/10/2008|01:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Spybot - Search & Destroy
[09/09/2008|11:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SupportSoft
[08/19/2007|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[09/15/2008|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Viewpoint
[01/07/2006|12:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[12/15/2006|01:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ yahoo!

[01/11/2007|11:31] C:\DOCUME~1\APPLIC~1\APPLIC~1\ Microsoft

[08/19/2004|04:14] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Identities
[10/09/2005|09:30] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Jasc Software Inc
[10/09/2005|09:29] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[10/09/2005|09:23] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Sun

[06/28/2008|01:08] C:\DOCUME~1\Gooz\APPLIC~1\ Adobe
[02/10/2006|04:24] C:\DOCUME~1\Gooz\APPLIC~1\ Corel
[09/07/2008|02:50] C:\DOCUME~1\Gooz\APPLIC~1\ Gtek
[08/19/2004|04:14] C:\DOCUME~1\Gooz\APPLIC~1\ Identities
[10/09/2005|09:30] C:\DOCUME~1\Gooz\APPLIC~1\ Jasc Software Inc
[11/03/2005|05:35] C:\DOCUME~1\Gooz\APPLIC~1\ Macromedia
[06/13/2007|12:44] C:\DOCUME~1\Gooz\APPLIC~1\ Microsoft
[06/13/2007|12:44] C:\DOCUME~1\Gooz\APPLIC~1\ MySpace
[10/09/2005|09:23] C:\DOCUME~1\Gooz\APPLIC~1\ Sun
[09/08/2008|11:53] C:\DOCUME~1\Gooz\APPLIC~1\ yahoo!

[08/06/2008|01:45] C:\DOCUME~1\Kevin\APPLIC~1\ acccore
[02/15/2008|12:21] C:\DOCUME~1\Kevin\APPLIC~1\ Adobe
[12/23/2006|01:08] C:\DOCUME~1\Kevin\APPLIC~1\ AdobeUM
[04/06/2008|02:24] C:\DOCUME~1\Kevin\APPLIC~1\ Corel
[02/08/2006|05:16] C:\DOCUME~1\Kevin\APPLIC~1\ ESPN
[04/13/2007|11:35] C:\DOCUME~1\Kevin\APPLIC~1\ Gtek
[10/26/2005|01:55] C:\DOCUME~1\Kevin\APPLIC~1\ Help
[08/19/2004|04:14] C:\DOCUME~1\Kevin\APPLIC~1\ Identities
[01/02/2006|02:25] C:\DOCUME~1\Kevin\APPLIC~1\ Jasc Software Inc
[10/23/2005|03:02] C:\DOCUME~1\Kevin\APPLIC~1\ Leadertech
[12/03/2005|04:17] C:\DOCUME~1\Kevin\APPLIC~1\ Macromedia
[09/12/2008|09:54] C:\DOCUME~1\Kevin\APPLIC~1\ Malwarebytes
[09/20/2008|10:09] C:\DOCUME~1\Kevin\APPLIC~1\ Microsoft
[09/06/2007|12:36] C:\DOCUME~1\Kevin\APPLIC~1\ Mozilla
[04/13/2006|12:26] C:\DOCUME~1\Kevin\APPLIC~1\ Musicmatch
[08/08/2006|01:51] C:\DOCUME~1\Kevin\APPLIC~1\ MySpace
[07/16/2008|12:55] C:\DOCUME~1\Kevin\APPLIC~1\ PlayFirst
[06/21/2008|07:33] C:\DOCUME~1\Kevin\APPLIC~1\ Skype
[10/23/2005|03:02] C:\DOCUME~1\Kevin\APPLIC~1\ Sonic
[02/19/2008|01:52] C:\DOCUME~1\Kevin\APPLIC~1\ Sony Online Entertainment
[10/09/2005|09:23] C:\DOCUME~1\Kevin\APPLIC~1\ Sun
[11/18/2006|04:36] C:\DOCUME~1\Kevin\APPLIC~1\ teamspeak2
[12/29/2007|10:45] C:\DOCUME~1\Kevin\APPLIC~1\ Yahoo!

[11/12/2005|12:43] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Macromedia
[08/19/2004|03:57] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[10/19/2008|08:02] C:\DOCUME~1\LOCALS~1\APPLIC~1\ SACore

[08/19/2004|03:57] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[10/15/2008 01:13 AM][–a——] C:\WINDOWS\tasks\McDefragTask.job
[10/01/2008 01:00 AM][–a——] C:\WINDOWS\tasks\McQcTask.job
[10/21/2008 11:35 PM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/10/2004 05:00 AM][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[10/23/2005|02:14] C:\Program Files\ 1602 A.D
[05/06/2008|11:26] C:\Program Files\ Adobe
[12/04/2005|11:41] C:\Program Files\ America Online 9.0
[10/09/2005|09:33] C:\Program Files\ AOL Companion
[10/09/2005|09:28] C:\Program Files\ ATI Technologies
[10/06/2008|10:50] C:\Program Files\ Common Files
[08/19/2004|04:02] C:\Program Files\ ComPlus Applications
[10/09/2005|09:28] C:\Program Files\ CyberLink
[04/13/2006|12:27] C:\Program Files\ Dell
[10/09/2005|09:31] C:\Program Files\ Dell Inc
[09/09/2008|11:44] C:\Program Files\ Dell Support Center
[04/13/2007|01:50] C:\Program Files\ DellSupport
[10/09/2005|09:33] C:\Program Files\ EarthLink Setup
[08/19/2004|04:16] C:\Program Files\ EnglishOtto
[01/25/2007|03:37] C:\Program Files\ FriendFinder
[10/20/2008|12:33] C:\Program Files\ Hijackthis
[02/19/2008|12:16] C:\Program Files\ InstallShield Installation Information
[10/09/2005|09:28] C:\Program Files\ Intel
[10/16/2008|12:49] C:\Program Files\ Internet Explorer
[10/09/2005|09:34] C:\Program Files\ Intuit
[10/09/2005|09:31] C:\Program Files\ Jasc Software Inc
[08/02/2008|04:52] C:\Program Files\ Java
[10/09/2005|09:33] C:\Program Files\ Learn2.com
[11/09/2005|02:59] C:\Program Files\ Magelo Update
[10/06/2008|12:32] C:\Program Files\ Malwarebytes' Anti-Malware
[10/21/2008|01:23] C:\Program Files\ McAfee
[12/29/2007|10:53] C:\Program Files\ McAfee.com
[08/26/2008|12:26] C:\Program Files\ Messenger
[08/19/2004|04:07] C:\Program Files\ microsoft frontpage
[10/09/2005|09:30] C:\Program Files\ Microsoft Plus! Digital Media Edition
[10/09/2005|09:30] C:\Program Files\ Microsoft Plus! Photo Story 2 LE
[10/09/2005|09:28] C:\Program Files\ Modem Helper
[10/09/2005|09:28] C:\Program Files\ Modem On Hold
[08/26/2008|12:15] C:\Program Files\ Movie Maker
[08/19/2004|04:01] C:\Program Files\ MSN
[09/01/2008|02:02] C:\Program Files\ MSN Games
[08/19/2004|04:01] C:\Program Files\ MSN Gaming Zone
[09/01/2008|02:07] C:\Program Files\ MSN Messenger
[11/18/2006|09:23] C:\Program Files\ MSXML 4.0
[10/09/2005|09:31] C:\Program Files\ MUSICMATCH
[08/08/2006|01:50] C:\Program Files\ MySpace
[10/09/2005|09:31] C:\Program Files\ MyWaySA
[08/26/2008|12:11] C:\Program Files\ NetMeeting
[10/09/2005|09:29] C:\Program Files\ NetZeroInstallers
[08/19/2004|04:02] C:\Program Files\ Online Services
[08/26/2008|12:11] C:\Program Files\ Outlook Express
[10/06/2008|10:35] C:\Program Files\ PartyGaming
[03/16/2007|05:07] C:\Program Files\ PartyPoker
[12/20/2006|02:33] C:\Program Files\ QuickTime
[10/09/2005|09:33] C:\Program Files\ Real
[08/19/2004|04:20] C:\Program Files\ RGB
[10/09/2005|09:25] C:\Program Files\ Sigmatel
[12/26/2005|01:46] C:\Program Files\ Sonic
[02/19/2008|12:16] C:\Program Files\ Sony
[01/13/2006|02:21] C:\Program Files\ tcpo
[12/03/2006|04:05] C:\Program Files\ Teamspeak2_RC2
[08/19/2004|04:14] C:\Program Files\ Uninstall Information
[06/18/2006|06:39] C:\Program Files\ USChessLive4
[10/09/2005|09:38] C:\Program Files\ WebCyberCoach
[11/07/2005|12:16] C:\Program Files\ Windows Media Player
[08/26/2008|12:11] C:\Program Files\ Windows NT
[08/19/2004|04:02] C:\Program Files\ Windows Plus
[08/19/2004|04:05] C:\Program Files\ WindowsUpdate
[10/09/2005|09:36] C:\Program Files\ WordPerfect Office 12
[08/19/2004|04:07] C:\Program Files\ xerox
[05/20/2007|11:44] C:\Program Files\ Yahoo!

——————–\\ Listing Folders in C:\Program Files\Common Files

[07/16/2007|08:16] C:\Program Files\Common Files\ Adobe
[10/09/2005|09:34] C:\Program Files\Common Files\ AnswerWorks 4.0
[09/07/2008|04:11] C:\Program Files\Common Files\ AOL
[10/09/2005|09:33] C:\Program Files\Common Files\ aolshare
[10/09/2005|09:35] C:\Program Files\Common Files\ Borland Shared
[10/09/2005|09:35] C:\Program Files\Common Files\ Corel
[09/12/2008|09:52] C:\Program Files\Common Files\ Download Manager
[10/09/2005|09:36] C:\Program Files\Common Files\ InstallShield
[10/09/2005|09:34] C:\Program Files\Common Files\ Intuit
[10/09/2005|09:30] C:\Program Files\Common Files\ Jasc Software Inc
[10/09/2005|09:23] C:\Program Files\Common Files\ Java
[06/12/2008|11:38] C:\Program Files\Common Files\ McAfee
[12/31/2006|04:48] C:\Program Files\Common Files\ Microsoft Shared
[08/19/2004|04:04] C:\Program Files\Common Files\ MSSoap
[09/07/2008|04:09] C:\Program Files\Common Files\ Nullsoft
[08/19/2004|03:57] C:\Program Files\Common Files\ ODBC
[10/09/2005|09:33] C:\Program Files\Common Files\ Real
[06/06/2007|01:50] C:\Program Files\Common Files\ Sandlot Shared
[08/19/2004|04:04] C:\Program Files\Common Files\ Services
[06/17/2008|11:43] C:\Program Files\Common Files\ Sonic Shared
[08/19/2004|03:57] C:\Program Files\Common Files\ SpeechEngines
[09/09/2008|11:43] C:\Program Files\Common Files\ supportsoft
[10/23/2005|03:09] C:\Program Files\Common Files\ SWF Studio
[08/26/2008|12:11] C:\Program Files\Common Files\ System

——————–\\ Process

( 51 Processes )

iexplore.exe ~ [PID:4076]

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-22 12:01:13
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

——————–\\ Cracks & Keygens ..

C:\DOCUME~1\Kevin\Favorites\pics to get\dawson miller\I'm Crackin' A Cold One And Shog Off My Boobs Again For You!.url
C:\DOCUME~1\Kevin\Favorites\pics to get\dawson miller\I'm Crackin' A Cold One And Showing Off My Boobs Again For You!.url


[F:884][D:12]-> C:\DOCUME~1\Kevin\LOCALS~1\Temp
[F:143][D:0]-> C:\DOCUME~1\Kevin\Cookies
[F:2629][D:7]-> C:\DOCUME~1\Kevin\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Wed 10/22/2008|12:02 - Option : [1]

——————–\\ Scan completed at 12:02:44
Kqueb,

Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

Please re-enable any security that was disabled.

Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.

For a tutorial on Firewalls and a listing of some available ones see the link below:

Understanding and Using Firewalls

Keep Microsoft Windows Updated - This will ensure your computer has always the latest security updates available installed on your computer. The easiest way to do this is to turn on Automatic Updates. Do this by:
  • From your desktop, right-click on My Computer,
  • click on Properties
  • Select the Automatic Updates tab
  • Click on Automatic
  • Click on Apply button
  • Click on OK to exit.
If there are new updates to install, install them immediately, until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware

Download and install the free version of WinPatrol - This program protects your computer in a variety of ways and will work well with your existing security software.
Winpatrol


Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.


Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI