This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] remove antivirus 2009

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm pretty sure I have antivirus 2009, need help removing it. I know I need to download malwarebytes malware remover but the problem is that I can't even get online without having issues. I have another computer and downloaded malwarebytes program to a flash drive. Please let me know what I need to do first. I will be using my other laptop to check for responses to fix my infected one.
:welcome:

My name is BHowett and I will be helping you to get sorted. If for any reason you do not understand any of the instructions, or are just unsure then please do not guess , simply post back with your question, and we will go through it again.

Please do the following…. From you clean computer download the following tools to your flash drive. Also Print out or save these instructions into note pad on your flash drive. (so you can see how to run the tools)

ATF Cleaner

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

===============================================


Malwarebytes' Anti-Malware
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Once you have them on your flash drive, plug it into the infected computer. First try saving the tools to your desktop and running them. If you have any trouble doing that just run them right off the flash drive. When your done please post the Malwarebytes log and let me know if you can get on line., :thumbup:
I was able to save and run the programs from my infected computer's desktop. I still am unable to start IE, it pops up for half a second then disappears. Here is the malwarebyte log: Malwarebytes' Anti-Malware 1.30 Database version: 1306 Windows 5.1.2600 Service Pack 3 10/29/2008 3:16:43 PM mbam-log-2008-10-29 (15-16-43).txt Scan type: Quick Scan Objects scanned: 60718 Time elapsed: 14 minute(s), 31 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 146 Registry Values Infected: 13 Registry Data Items Infected: 0 Folders Infected: 3 Files Infected: 23 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\cdmyidd.securitytoolbar (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{cd24eb02-9831-4838-99d0-726d411b1328} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{f20da564-9254-49fe-a678-cc3cef172252} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\cdmyidd.securitytoolbar.1 (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.datacontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.datacontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.htmlmenu (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.2 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.outlookaddin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.outlookaddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{0f8ecf4f-3646-4c3a-8881-8e138ffcaf70} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{53ced2d0-5e9a-4761-9005-648404e6f7e5} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{7473d296-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{8e6f1832-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{938aa51a-996c-4884-98ce-80dd16a5c9da} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a9571378-68a1-443d-b082-284f960c6d17} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{adb01e81-3c79-4272-a0f1-7b2be7a782dc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{b813095c-81c0-4e40-aa14-67520372b987} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{c9d7be3e-141a-4c85-8cd6-32461f3df2c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{cff4ce82-3aa2-451f-9b77-7165605fb835} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{d9fffb27-d62a-4d64-8cec-1ff006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\antispywarexp2009 (Rogue.AntispywareXP) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\my web search bar search scope monitor (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antispywarexp 2009 (Rogue.AntispywareXP) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Plugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\brastk (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Delete on reboot. C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Delete on reboot. C:\Program Files\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> Delete on reboot. Files Infected: C:\Documents and Settings\Owner\Local Settings\Application Data\CyberDefender\cdmyidd.dll (Trojan.BHO) -> Quarantined and deleted successfully. C:\WINDOWS\karna.dat (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\WINDOWS\system32\karna.dat (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> Delete on reboot. C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\AntiSpywareXP2009.lnk (Rogue.Antispyware) -> Quarantined and deleted successfully. C:\WINDOWS\system32\delself.bat (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\system32\drivers\beep.sys (Fake.Beep.Sys) -> Quarantined and deleted successfully. C:\WINDOWS\system32\dllcache\beep.sys (Fake.Beep.Sys) -> Quarantined and deleted successfully. C:\WINDOWS\brastk.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\_scui.cpl (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wini10801.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\brastk.exe (Trojan.FakeAlert) -> Delete on reboot. C:\RECYCLER\ADAPT_Installer.exe (Heuristics.Malware) -> Quarantined and deleted successfully. C:\Documents and Settings\Owner\Desktop\AntiSpywareXP2009.lnk (Rogue.Antispyware) -> Quarantined and deleted successfully. C:\WINDOWS\system32\TDSScfub.dll (Rootkit.Agent) -> Delete on reboot. C:\WINDOWS\system32\TDSSfpmp.dll (Rootkit.Agent) -> Delete on reboot. C:\WINDOWS\system32\TDSSnrsr.dll (Rootkit.Agent) -> Delete on reboot. C:\WINDOWS\system32\TDSSoexh.dll (Rootkit.Agent) -> Delete on reboot. C:\WINDOWS\system32\TDSSoiqh.dll (Rootkit.Agent) -> Delete on reboot. C:\WINDOWS\system32\TDSSrhym.dll (Rootkit.Agent) -> Delete on reboot. C:\WINDOWS\system32\TDSSriqp.dll (Rootkit.Agent) -> Delete on reboot. C:\WINDOWS\system32\drivers\TDSSpaxt.sys (Rootkit.Agent) -> Delete on reboot.
Hi cookjs,

You got some pretty nasty stuff there, from you clean computer download the following tool to your flash drive. Also Print out or save these instructions into note pad on your flash drive. (so you can see how to run the tool)

ComboFix

Please ownload ComboFix from Here or Here

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Do not mouse-click Combofix's window while it is running. That may cause it to stall.

===============================================


Once you have them on your flash drive, plug it into the infected computer. First try saving the tools to your desktop and running them. If you have any trouble doing that just run them right off the flash drive. When your done please post the Combofix log and let me know how things are running :)
I did need to install the Microsoft Windows Recovery Console, then ran the ComboFix. Thanks for the help!

Here is the log:

ComboFix 08-10-30.09 - Owner 2008-10-30 16:51:02.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.967 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\Documents and Settings\Owner\Application Data\FunWebProducts
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\dizeqi.sys
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\ijylofal.vbs
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\miwo.com
C:\test.txt
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\_000009_.tmp.dll
C:\WINDOWS\system32\_000010_.tmp.dll
C:\WINDOWS\system32\_000011_.tmp.dll
C:\WINDOWS\system32\_000013_.tmp.dll
C:\WINDOWS\system32\av.dat
E:\autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_MYWEBSEARCHSERVICE
——-\Legacy_TDSSSERV.SYS)
——-\Service_MyWebSearchService
——-\Service_TDSSserv.sys
——-\Service_TDSSserv.sys)


((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-30 )))))))))))))))))))))))))))))))
.

2008-10-30 16:13 . 2008-10-30 16:13 d——– C:\Documents and Settings\All Users\Application Data\GoBoingo
2008-10-29 14:57 . 2008-10-29 18:18 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-29 14:57 . 2008-10-29 14:57 d——– C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-10-29 14:57 . 2008-10-29 14:57 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-29 14:57 . 2008-10-22 16:27 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-29 14:57 . 2008-10-22 16:27 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-29 09:48 . 2008-10-30 16:13 d——– C:\Program Files\Alltel
2008-10-27 11:22 . 2008-10-27 11:22 18,016 –a—— C:\Documents and Settings\Owner\Application Data\efezupy.vbs
2008-10-27 11:22 . 2008-10-27 11:22 12,120 –a—— C:\Documents and Settings\All Users\Application Data\efibod.dat
2008-10-24 11:00 . 2008-10-27 14:13 d——– C:\Documents and Settings\All Users\Application Data\Trymedia
2008-10-24 11:00 . 2008-10-24 11:00 0 –a—— C:\WINDOWS\popcinfo.dat
2008-10-24 10:25 . 2008-10-24 16:12 d——– C:\Documents and Settings\Owner\Application Data\Wildfire
2008-10-24 10:25 . 2008-10-24 10:25 4,096 –a—— C:\WINDOWS\d3dx.dat
2008-10-24 08:19 . 2008-10-15 12:34 337,408 —–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-21 09:06 . 2008-10-21 09:06 d——– C:\Documents and Settings\All Users\Application Data\NOS
2008-10-16 09:51 . 2008-09-15 08:12 1,846,400 —–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-16 09:51 . 2008-09-08 06:41 333,824 —–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-16 09:50 . 2008-08-14 06:11 2,189,184 —–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-16 09:50 . 2008-08-14 06:09 2,145,280 —–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-16 09:50 . 2008-08-14 05:33 2,066,048 —–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-16 09:50 . 2008-08-14 05:33 2,023,936 —–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 08:45 . 2008-10-15 08:45 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-10-15 08:45 . 2008-10-15 08:45 1,409 –a—— C:\WINDOWS\QTFont.for
2008-10-02 10:00 . 2008-10-02 10:01 d——– C:\Documents and Settings\Owner\Application Data\Snapfish
2008-09-20 14:59 . 2008-10-24 16:18 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-06 16:59 . 2008-09-07 12:24 d——– C:\WINDOWS\system32\Adobe
2008-09-04 12:28 . 2004-08-04 08:00 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-09-04 09:36 . 2008-09-04 09:36 d——– C:\WINDOWS\system32\scripting
2008-09-04 09:36 . 2008-09-04 09:36 d——– C:\WINDOWS\system32\en
2008-09-04 09:36 . 2008-09-04 09:36 d——– C:\WINDOWS\system32\bits
2008-09-04 09:36 . 2008-09-04 09:36 d——– C:\WINDOWS\l2schemas
2008-09-04 09:32 . 2008-09-04 09:37 d——– C:\WINDOWS\ServicePackFiles
2008-09-04 09:23 . 2008-09-04 09:23 d——– C:\WINDOWS\EHome
2008-09-04 09:12 . 2008-04-13 20:12 3,558,912 –a–c— C:\WINDOWS\system32\dllcache\moviemk.exe
2008-09-04 09:11 . 2008-04-13 20:11 1,888,992 ——— C:\WINDOWS\system32\ati3duag.dll
2008-09-02 14:35 . 2008-09-02 15:28 d——– C:\Documents and Settings\Owner\Application Data\LimeWire
2008-09-02 14:34 . 2008-09-02 14:34 d——– C:\WINDOWS\Sun
2008-09-02 14:30 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-02 14:29 . 2008-09-02 14:30 d——– C:\Program Files\Java
2008-09-01 08:31 . 2008-10-26 20:35 d——– C:\Documents and Settings\All Users\Application Data\Google Updater

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-29 19:18 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-10-27 18:02 ——— d—–w C:\Program Files\WordPerfect Office 11
2008-10-27 18:02 ——— d—–w C:\Program Files\THQ
2008-10-27 18:02 ——— d—–w C:\Program Files\Sonic
2008-10-27 18:01 ——— d—–w C:\Program Files\Norton AntiVirus
2008-10-27 18:01 ——— d—–w C:\Program Files\Microsoft Works
2008-10-27 18:00 ——— d—–w C:\Program Files\Google
2008-10-27 18:00 ——— d—–w C:\Program Files\ewido anti-malware
2008-10-27 18:00 ——— d—–w C:\Program Files\Edmark
2008-10-27 18:00 ——— d—–w C:\Program Files\Common Files\Real
2008-10-27 18:00 ——— d—–w C:\Program Files\Common Files\aolshare
2008-10-27 17:59 ——— d—–w C:\Program Files\CA
2008-10-27 17:59 ——— d—–w C:\Program Files\3DO
2008-10-27 15:22 17,191 —-a-w C:\WINDOWS\atubyrefi.reg
2008-10-27 15:22 16,329 —-a-w C:\WINDOWS\dupuqovite.bin
2008-10-27 15:22 15,214 —-a-w C:\WINDOWS\cyzyh.reg
2008-10-27 15:22 14,738 —-a-w C:\WINDOWS\migigije.pif
2008-10-27 15:22 10,749 —-a-w C:\WINDOWS\gytymelih.sys
2008-10-27 15:22 10,060 —-a-w C:\WINDOWS\mikyna.bin
2008-10-21 13:12 ——— d—–w C:\Program Files\Common Files\Adobe
2008-10-21 13:12 ——— d—–w C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-09-13 23:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-02 14:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-30 19:19 ——— d—–w C:\Program Files\Netflix
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-01 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-11-20 4866048]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2007-06-21 26112]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"GoBoingo"="C:\Program Files\Alltel\GoBoingo\AlltelWifi.exe" [2007-10-02 324912]
"nwiz"="nwiz.exe" [2003-11-20 C:\WINDOWS\system32\nwiz.exe]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 C:\WINDOWS\BCMSMMSG.exe]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= C:\Program Files\Ocean Aquarium 3D Deluxe\Active Desktop\Ocean_Aquarium_3D_Active_DT.html
FriendlyName= Ocean Aquarium Deluxe v1.0 Active Desktop

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.JDCT"= jl_jdct.drv

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R2 LogWatch;Event Log Watch;C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2005-02-23 53248]
R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2006-06-06 20096]
S1 ewido security suite driver;ewido security suite driver;C:\Program Files\ewido anti-malware\guard.sys [ ]
S2 LiveUpdate Notice;LiveUpdate Notice;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [ ]
S3 CA_LIC_CLNT;CA License Client;C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe [ ]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
S3 getPlus® Helper;getPlus® Helper;C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [ ]
S3 jdmboot;jdmboot;C:\DOCUME~1\Owner\LOCALS~1\Temp\jdmboot.sys [ ]
S3 JL2005C;Dual Mode Camera;C:\WINDOWS\system32\Drivers\jl2005c.sys [2007-01-26 68954]
S3 ssecdrv;ssecdrv;C:\DOCUME~1\Owner\LOCALS~1\Temp\ssecdrv.sys [ ]
S3 xraspptp;xraspptp;C:\DOCUME~1\Owner\LOCALS~1\Temp\xraspptp.sys [ ]
S3 yfs_rec;yfs_rec;C:\DOCUME~1\Owner\LOCALS~1\Temp\yfs_rec.sys [ ]
.
Contents of the 'Scheduled Tasks' folder

2008-09-26 C:\WINDOWS\Tasks\At1.job
- c:\program files\norton pc checkup\pc_checkup.exe []

2008-10-04 C:\WINDOWS\Tasks\At2.job
- c:\program files\norton pc checkup\pc_checkup.exe []

2008-09-02 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Owner.job
- C:\Program Files\Norton AntiVirus\Navw32.exe []
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-MsnMsgr - C:\Program Files\MSN Messenger\MsnMsgr.Exe
HKCU-Run-Sonic RecordNow! - (no file)
HKLM-Run-StorageGuard - C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
HKLM-Run-Microsoft Works Update Detection - C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
HKLM-Run-ccApp - C:\Program Files\Common Files\Symantec Shared\ccApp.exe
HKLM-Run-osCheck - C:\Program Files\Norton AntiVirus\osCheck.exe


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R0 -: HKLM-Main,Start Page = hxxp://www.google.com
O8 -: &Search
O8 -: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 -: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 -: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 -: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 -: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O17 -: HKLM\CCS\Interface\{14F14835-5C89-4BD2-AC9A-76FB25EF333E}: NameServer = 166.102.165.11 166.102.165.13
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-30 16:54:35
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
.
**************************************************************************
.
Completion time: 2008-10-30 16:56:48 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-10-30 20:56:43

Pre-Run: 79,943,532,544 bytes free
Post-Run: 80,203,550,720 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

210 — E O F — 2008-10-24 13:00:50
Hi cookjs,

Please do the following…

ComboFix Script

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Documents and Settings\Owner\Application Data\efezupy.vbs
C:\Documents and Settings\All Users\Application Data\efibod.dat
C:\WINDOWS\popcinfo.dat
C:\WINDOWS\d3dx.dat
C:\WINDOWS\atubyrefi.reg
C:\WINDOWS\dupuqovite.bin
C:\WINDOWS\cyzyh.reg
C:\WINDOWS\migigije.pif
C:\WINDOWS\gytymelih.sys
C:\WINDOWS\mikyna.bin
Folder::
C:\Documents and Settings\All Users\Application Data\Trymedia
C:\Documents and Settings\Owner\Application Data\Wildfire


Save this as CFScript.txt in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

This will cause Combofix to run again. When finished, it shall produce a log for you at C:\ComboFix.txt which I will require you to post in your next reply.

================================================================

HijackThis

Click here to download HJTInstall.exe
  • Save HJTInstall.exe to your desktop.
  • Doubleclick on the HJTInstall.exe icon on your desktop.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed, it will launch Hijackthis.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

================================================================


Needed in your next reply:

Combofix log
fresh HijackThis log

And let me know how things are running now :thumbup:
ComboFix log:
ComboFix 08-10-30.09 - Owner 2008-10-30 19:50:44.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.970 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: E:\CFScript.txt
* Created a new restore point

FILE ::
C:\Documents and Settings\All Users\Application Data\efibod.dat
C:\Documents and Settings\Owner\Application Data\efezupy.vbs
C:\WINDOWS\atubyrefi.reg
C:\WINDOWS\cyzyh.reg
C:\WINDOWS\d3dx.dat
C:\WINDOWS\dupuqovite.bin
C:\WINDOWS\gytymelih.sys
C:\WINDOWS\migigije.pif
C:\WINDOWS\mikyna.bin
C:\WINDOWS\popcinfo.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\efibod.dat
C:\Documents and Settings\All Users\Application Data\Trymedia
C:\Documents and Settings\All Users\Application Data\Trymedia\data\{24071EB7-F0F8-4B13-C097-9D0585C21237}
C:\Documents and Settings\All Users\Application Data\Trymedia\data\{44280896-83D6-22C2-B8C2-B01974047348}
C:\Documents and Settings\All Users\Application Data\Trymedia\data\{7052D080-2867-2330-AF43-50E7FC87F552}
C:\Documents and Settings\Owner\Application Data\efezupy.vbs
C:\Documents and Settings\Owner\Application Data\Wildfire
C:\Documents and Settings\Owner\Application Data\Wildfire\griffinArcade.xml
C:\Documents and Settings\Owner\Application Data\Wildfire\TBConfig.xml
C:\Documents and Settings\Owner\Application Data\Wildfire\TumbleBugs_Stats.txt
C:\Documents and Settings\Owner\Application Data\Wildfire\wfdebug.log
C:\WINDOWS\atubyrefi.reg
C:\WINDOWS\cyzyh.reg
C:\WINDOWS\d3dx.dat
C:\WINDOWS\dupuqovite.bin
C:\WINDOWS\gytymelih.sys
C:\WINDOWS\migigije.pif
C:\WINDOWS\mikyna.bin
C:\WINDOWS\popcinfo.dat

.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-30 )))))))))))))))))))))))))))))))
.

2008-10-30 16:13 . 2008-10-30 16:13 d——– C:\Documents and Settings\All Users\Application Data\GoBoingo
2008-10-29 14:57 . 2008-10-29 18:18 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-29 14:57 . 2008-10-29 14:57 d——– C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-10-29 14:57 . 2008-10-29 14:57 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-29 14:57 . 2008-10-22 16:27 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-29 14:57 . 2008-10-22 16:27 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-29 09:48 . 2008-10-30 16:13 d——– C:\Program Files\Alltel
2008-10-27 11:22 . 2008-10-27 11:22 19,435 –a—— C:\WINDOWS\uhiwyqy.inf
2008-10-27 11:22 . 2008-10-27 11:22 17,157 –a—— C:\WINDOWS\system32\dipuzyryvi.ban
2008-10-27 11:22 . 2008-10-27 11:22 14,602 –a—— C:\WINDOWS\saxado._sy
2008-10-27 11:22 . 2008-10-27 11:22 11,733 –a—— C:\WINDOWS\system32\muneso.pif
2008-10-27 11:22 . 2008-10-27 11:22 11,209 –a—— C:\WINDOWS\zexyv._dl
2008-10-27 11:22 . 2008-10-27 11:22 11,102 –a—— C:\WINDOWS\jezilosi.inf
2008-10-27 11:22 . 2008-10-27 11:22 10,155 –a—— C:\WINDOWS\mocyji.db
2008-10-24 08:19 . 2008-10-15 12:34 337,408 —–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-21 09:06 . 2008-10-21 09:06 d——– C:\Documents and Settings\All Users\Application Data\NOS
2008-10-16 09:51 . 2008-09-15 08:12 1,846,400 —–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-16 09:51 . 2008-09-08 06:41 333,824 —–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-16 09:50 . 2008-08-14 06:11 2,189,184 —–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-16 09:50 . 2008-08-14 06:09 2,145,280 —–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-16 09:50 . 2008-08-14 05:33 2,066,048 —–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-16 09:50 . 2008-08-14 05:33 2,023,936 —–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 08:45 . 2008-10-15 08:45 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-10-15 08:45 . 2008-10-15 08:45 1,409 –a—— C:\WINDOWS\QTFont.for
2008-10-02 10:00 . 2008-10-02 10:01 d——– C:\Documents and Settings\Owner\Application Data\Snapfish
2008-09-20 14:59 . 2008-10-24 16:18 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-06 16:59 . 2008-09-07 12:24 d——– C:\WINDOWS\system32\Adobe
2008-09-04 12:28 . 2004-08-04 08:00 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-09-04 09:36 . 2008-09-04 09:36 d——– C:\WINDOWS\system32\scripting
2008-09-04 09:36 . 2008-09-04 09:36 d——– C:\WINDOWS\system32\en
2008-09-04 09:36 . 2008-09-04 09:36 d——– C:\WINDOWS\system32\bits
2008-09-04 09:36 . 2008-09-04 09:36 d——– C:\WINDOWS\l2schemas
2008-09-04 09:32 . 2008-09-04 09:37 d——– C:\WINDOWS\ServicePackFiles
2008-09-04 09:23 . 2008-09-04 09:23 d——– C:\WINDOWS\EHome
2008-09-04 09:12 . 2008-04-13 20:12 3,558,912 –a–c— C:\WINDOWS\system32\dllcache\moviemk.exe
2008-09-04 09:11 . 2008-04-13 20:11 1,888,992 ——— C:\WINDOWS\system32\ati3duag.dll
2008-09-02 14:35 . 2008-09-02 15:28 d——– C:\Documents and Settings\Owner\Application Data\LimeWire
2008-09-02 14:34 . 2008-09-02 14:34 d——– C:\WINDOWS\Sun
2008-09-02 14:30 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-02 14:29 . 2008-09-02 14:30 d——– C:\Program Files\Java
2008-09-01 08:31 . 2008-10-26 20:35 d——– C:\Documents and Settings\All Users\Application Data\Google Updater

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-29 19:18 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-10-27 18:02 ——— d—–w C:\Program Files\WordPerfect Office 11
2008-10-27 18:02 ——— d—–w C:\Program Files\THQ
2008-10-27 18:02 ——— d—–w C:\Program Files\Sonic
2008-10-27 18:01 ——— d—–w C:\Program Files\Norton AntiVirus
2008-10-27 18:01 ——— d—–w C:\Program Files\Microsoft Works
2008-10-27 18:00 ——— d—–w C:\Program Files\Google
2008-10-27 18:00 ——— d—–w C:\Program Files\ewido anti-malware
2008-10-27 18:00 ——— d—–w C:\Program Files\Edmark
2008-10-27 18:00 ——— d—–w C:\Program Files\Common Files\Real
2008-10-27 18:00 ——— d—–w C:\Program Files\Common Files\aolshare
2008-10-27 17:59 ——— d—–w C:\Program Files\CA
2008-10-27 17:59 ——— d—–w C:\Program Files\3DO
2008-10-21 13:12 ——— d—–w C:\Program Files\Common Files\Adobe
2008-10-21 13:12 ——— d—–w C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-09-15 12:12 1,846,400 ——w C:\WINDOWS\system32\win32k.sys
2008-09-13 23:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-02 14:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-30 19:19 ——— d—–w C:\Program Files\Netflix
2008-08-26 07:24 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-08-24 18:24 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-08-14 10:11 2,189,184 ——w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:33 2,066,048 ——w C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-19 02:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 02:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 02:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-01 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-11-20 4866048]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2007-06-21 26112]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"GoBoingo"="C:\Program Files\Alltel\GoBoingo\AlltelWifi.exe" [2007-10-02 324912]
"nwiz"="nwiz.exe" [2003-11-20 C:\WINDOWS\system32\nwiz.exe]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 C:\WINDOWS\BCMSMMSG.exe]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= C:\Program Files\Ocean Aquarium 3D Deluxe\Active Desktop\Ocean_Aquarium_3D_Active_DT.html
FriendlyName= Ocean Aquarium Deluxe v1.0 Active Desktop

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.JDCT"= jl_jdct.drv

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R2 LogWatch;Event Log Watch;C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2005-02-23 53248]
R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2006-06-06 20096]
S1 ewido security suite driver;ewido security suite driver;C:\Program Files\ewido anti-malware\guard.sys [ ]
S2 LiveUpdate Notice;LiveUpdate Notice;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [ ]
S3 CA_LIC_CLNT;CA License Client;C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe [ ]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
S3 getPlus® Helper;getPlus® Helper;C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [ ]
S3 jdmboot;jdmboot;C:\DOCUME~1\Owner\LOCALS~1\Temp\jdmboot.sys [ ]
S3 JL2005C;Dual Mode Camera;C:\WINDOWS\system32\Drivers\jl2005c.sys [2007-01-26 68954]
S3 ssecdrv;ssecdrv;C:\DOCUME~1\Owner\LOCALS~1\Temp\ssecdrv.sys [ ]
S3 xraspptp;xraspptp;C:\DOCUME~1\Owner\LOCALS~1\Temp\xraspptp.sys [ ]
S3 yfs_rec;yfs_rec;C:\DOCUME~1\Owner\LOCALS~1\Temp\yfs_rec.sys [ ]
.
Contents of the 'Scheduled Tasks' folder

2008-09-26 C:\WINDOWS\Tasks\At1.job
- c:\program files\norton pc checkup\pc_checkup.exe []

2008-10-04 C:\WINDOWS\Tasks\At2.job
- c:\program files\norton pc checkup\pc_checkup.exe []

2008-09-02 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Owner.job
- C:\Program Files\Norton AntiVirus\Navw32.exe []
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-30 19:52:24
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-10-30 19:53:22
ComboFix-quarantined-files.txt 2008-10-30 23:53:15
ComboFix2.txt 2008-10-30 20:56:49

Pre-Run: 80,240,746,496 bytes free
Post-Run: 80,230,039,552 bytes free

195 — E O F — 2008-10-24 13:00:50





Hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:55:30 PM, on 10/30/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Alltel\GoBoingo\AlltelWifi.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Alltel\QuickLink Mobile\QuickLink Mobile.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll (file missing)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [GoBoingo] C:\Program Files\Alltel\GoBoingo\AlltelWifi.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jd…ows-i586-jc.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.35.18/ttinst.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{14F14835-5C89-4BD2-AC9A-76FB25EF333E}: NameServer = 166.102.165.11 166.102.165.13
O17 - HKLM\System\CS1\Services\Tcpip\..\{14F14835-5C89-4BD2-AC9A-76FB25EF333E}: NameServer = 166.102.165.11 166.102.165.13
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (file missing)
O23 - Service: CA License Client (CA_LIC_CLNT) - Unknown owner - C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: getPlus® Helper - Unknown owner - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (file missing)
O23 - Service: LiveUpdate - Unknown owner - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (file missing)
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)
O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)
O24 - Desktop Component 1: Ocean Aquarium Deluxe v1.0 Active Desktop - C:\Program Files\Ocean Aquarium 3D Deluxe\Active Desktop\Ocean_Aquarium_3D_Active_DT.html

–
End of file - 8060 bytes
Hi cookjs,

Please do the following…..

Combofix Script.txt
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\uhiwyqy.inf
C:\WINDOWS\system32\dipuzyryvi.ban
C:\WINDOWS\saxado._sy
C:\WINDOWS\system32\muneso.pif
C:\WINDOWS\zexyv._dl
C:\WINDOWS\jezilosi.inf
C:\WINDOWS\mocyji.db


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Also let me know how your system is running now :thumbup:
Here are the new logs:

ComboFix:
ComboFix 08-10-30.09 - Owner 2008-10-31 11:41:11.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.938 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: E:\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-31 )))))))))))))))))))))))))))))))
.

2008-10-31 09:00 . 2008-10-31 09:00 d——– C:\WINDOWS\LastGood
2008-10-30 19:55 . 2008-10-30 19:55 d——– C:\Program Files\Trend Micro
2008-10-30 16:13 . 2008-10-30 16:13 d——– C:\Documents and Settings\All Users\Application Data\GoBoingo
2008-10-29 14:57 . 2008-10-29 18:18 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-29 14:57 . 2008-10-29 14:57 d——– C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-10-29 14:57 . 2008-10-29 14:57 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-29 14:57 . 2008-10-22 16:27 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-29 14:57 . 2008-10-22 16:27 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-29 09:48 . 2008-10-30 16:13 d——– C:\Program Files\Alltel
2008-10-27 11:22 . 2008-10-27 11:22 19,435 –a—— C:\WINDOWS\uhiwyqy.inf
2008-10-27 11:22 . 2008-10-27 11:22 17,157 –a—— C:\WINDOWS\system32\dipuzyryvi.ban
2008-10-27 11:22 . 2008-10-27 11:22 14,602 –a—— C:\WINDOWS\saxado._sy
2008-10-27 11:22 . 2008-10-27 11:22 11,733 –a—— C:\WINDOWS\system32\muneso.pif
2008-10-27 11:22 . 2008-10-27 11:22 11,209 –a—— C:\WINDOWS\zexyv._dl
2008-10-27 11:22 . 2008-10-27 11:22 11,102 –a—— C:\WINDOWS\jezilosi.inf
2008-10-27 11:22 . 2008-10-27 11:22 10,155 –a—— C:\WINDOWS\mocyji.db
2008-10-24 08:19 . 2008-10-15 12:34 337,408 —–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-21 09:06 . 2008-10-21 09:06 d——– C:\Documents and Settings\All Users\Application Data\NOS
2008-10-16 09:51 . 2008-09-15 08:12 1,846,400 —–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-16 09:51 . 2008-09-08 06:41 333,824 —–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-16 09:50 . 2008-08-14 06:11 2,189,184 —–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-16 09:50 . 2008-08-14 06:09 2,145,280 —–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-16 09:50 . 2008-08-14 05:33 2,066,048 —–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-16 09:50 . 2008-08-14 05:33 2,023,936 —–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 08:45 . 2008-10-15 08:45 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-10-15 08:45 . 2008-10-15 08:45 1,409 –a—— C:\WINDOWS\QTFont.for
2008-10-02 10:00 . 2008-10-02 10:01 d——– C:\Documents and Settings\Owner\Application Data\Snapfish
2008-09-20 14:59 . 2008-10-24 16:18 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-06 16:59 . 2008-09-07 12:24 d——– C:\WINDOWS\system32\Adobe
2008-09-04 12:28 . 2004-08-04 08:00 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-09-04 09:36 . 2008-09-04 09:36 d——– C:\WINDOWS\system32\scripting
2008-09-04 09:36 . 2008-09-04 09:36 d——– C:\WINDOWS\system32\en
2008-09-04 09:36 . 2008-09-04 09:36 d——– C:\WINDOWS\system32\bits
2008-09-04 09:36 . 2008-09-04 09:36 d——– C:\WINDOWS\l2schemas
2008-09-04 09:32 . 2008-09-04 09:37 d——– C:\WINDOWS\ServicePackFiles
2008-09-04 09:23 . 2008-09-04 09:23 d——– C:\WINDOWS\EHome
2008-09-04 09:12 . 2008-04-13 20:12 3,558,912 –a–c— C:\WINDOWS\system32\dllcache\moviemk.exe
2008-09-04 09:11 . 2008-04-13 20:11 1,888,992 ——— C:\WINDOWS\system32\ati3duag.dll
2008-09-02 14:35 . 2008-09-02 15:28 d——– C:\Documents and Settings\Owner\Application Data\LimeWire
2008-09-02 14:34 . 2008-09-02 14:34 d——– C:\WINDOWS\Sun
2008-09-02 14:30 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-02 14:29 . 2008-09-02 14:30 d——– C:\Program Files\Java
2008-09-01 08:31 . 2008-10-26 20:35 d——– C:\Documents and Settings\All Users\Application Data\Google Updater

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-29 19:18 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-10-27 18:02 ——— d—–w C:\Program Files\WordPerfect Office 11
2008-10-27 18:02 ——— d—–w C:\Program Files\THQ
2008-10-27 18:02 ——— d—–w C:\Program Files\Sonic
2008-10-27 18:01 ——— d—–w C:\Program Files\Norton AntiVirus
2008-10-27 18:01 ——— d—–w C:\Program Files\Microsoft Works
2008-10-27 18:00 ——— d—–w C:\Program Files\Google
2008-10-27 18:00 ——— d—–w C:\Program Files\ewido anti-malware
2008-10-27 18:00 ——— d—–w C:\Program Files\Edmark
2008-10-27 18:00 ——— d—–w C:\Program Files\Common Files\Real
2008-10-27 18:00 ——— d—–w C:\Program Files\Common Files\aolshare
2008-10-27 17:59 ——— d—–w C:\Program Files\CA
2008-10-27 17:59 ——— d—–w C:\Program Files\3DO
2008-10-21 13:12 ——— d—–w C:\Program Files\Common Files\Adobe
2008-10-21 13:12 ——— d—–w C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-09-15 12:12 1,846,400 ——w C:\WINDOWS\system32\win32k.sys
2008-09-13 23:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-02 14:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-30 19:19 ——— d—–w C:\Program Files\Netflix
2008-08-26 07:24 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-08-24 18:24 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-08-14 10:11 2,189,184 ——w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:33 2,066,048 ——w C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-19 02:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 02:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 02:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-01 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-11-20 4866048]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2007-06-21 26112]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"GoBoingo"="C:\Program Files\Alltel\GoBoingo\AlltelWifi.exe" [2007-10-02 324912]
"nwiz"="nwiz.exe" [2003-11-20 C:\WINDOWS\system32\nwiz.exe]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 C:\WINDOWS\BCMSMMSG.exe]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= C:\Program Files\Ocean Aquarium 3D Deluxe\Active Desktop\Ocean_Aquarium_3D_Active_DT.html
FriendlyName= Ocean Aquarium Deluxe v1.0 Active Desktop

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.JDCT"= jl_jdct.drv

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R2 LogWatch;Event Log Watch;C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2005-02-23 53248]
R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2006-06-06 20096]
S1 ewido security suite driver;ewido security suite driver;C:\Program Files\ewido anti-malware\guard.sys [ ]
S2 LiveUpdate Notice;LiveUpdate Notice;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [ ]
S3 CA_LIC_CLNT;CA License Client;C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe [ ]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
S3 getPlus® Helper;getPlus® Helper;C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [ ]
S3 jdmboot;jdmboot;C:\DOCUME~1\Owner\LOCALS~1\Temp\jdmboot.sys [ ]
S3 JL2005C;Dual Mode Camera;C:\WINDOWS\system32\Drivers\jl2005c.sys [2007-01-26 68954]
S3 ssecdrv;ssecdrv;C:\DOCUME~1\Owner\LOCALS~1\Temp\ssecdrv.sys [ ]
S3 xraspptp;xraspptp;C:\DOCUME~1\Owner\LOCALS~1\Temp\xraspptp.sys [ ]
S3 yfs_rec;yfs_rec;C:\DOCUME~1\Owner\LOCALS~1\Temp\yfs_rec.sys [ ]

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder

2008-10-31 C:\WINDOWS\Tasks\At1.job
- c:\program files\norton pc checkup\pc_checkup.exe []

2008-10-04 C:\WINDOWS\Tasks\At2.job
- c:\program files\norton pc checkup\pc_checkup.exe []

2008-09-02 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Owner.job
- C:\Program Files\Norton AntiVirus\Navw32.exe []
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-31 11:41:57
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-10-31 11:42:29
ComboFix-quarantined-files.txt 2008-10-31 15:42:26
ComboFix2.txt 2008-10-30 23:55:06
ComboFix3.txt 2008-10-30 20:56:49

Pre-Run: 80,198,316,032 bytes free
Post-Run: 80,187,449,344 bytes free

166 — E O F — 2008-10-31 13:00:42


HiJack this
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:44:00 AM, on 10/31/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Alltel\GoBoingo\AlltelWifi.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll (file missing)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [GoBoingo] C:\Program Files\Alltel\GoBoingo\AlltelWifi.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows; Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jd…ows-i586-jc.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.35.18/ttinst.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (file missing)
O23 - Service: CA License Client (CA_LIC_CLNT) - Unknown owner - C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: getPlus® Helper - Unknown owner - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (file missing)
O23 - Service: LiveUpdate - Unknown owner - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (file missing)
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)
O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)
O24 - Desktop Component 1: Ocean Aquarium Deluxe v1.0 Active Desktop - C:\Program Files\Ocean Aquarium 3D Deluxe\Active Desktop\Ocean_Aquarium_3D_Active_DT.html

–
End of file - 7684 bytes


No real changes in the infected laptop, the internet won't even try to connect now. :huh:
Hi cookjs,

ewido security suite is an old program, ewido is now part of the AVG Technologies family, so you can remove any ewido programs through Add/Remove programs.

Do you use the poker program? If so, leave it alone. If not, then uninstall Party Poker via Add/Remove Programs. Reboot after you uninstall.

If you uninstalled it, then run HijackThis and click "Scan." Place checks next to the following entries, if present::

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)

Close all browsers and other windows except for HijackThis!, and click "Fix checked".

Delete the following folder :

E:\Program Files\PartyGaming

Reboot your computer.

===============================================

OTMoveIt3 by OldTimer

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Files
    C:\WINDOWS\uhiwyqy.inf
    C:\WINDOWS\system32\dipuzyryvi.ban
    C:\WINDOWS\saxado._sy
    C:\WINDOWS\system32\muneso.pif
    C:\WINDOWS\zexyv._dl
    C:\WINDOWS\jezilosi.inf
    C:\WINDOWS\mocyji.db
    :Reg
    :Commands
    [purity]
    [emptytemp]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

===============================================

RSIT
  • Download random's system information tool (RSIT) by random/random from here.
  • It is important that is saved to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
===============================================

Needed in your next reply:

OTMoveIt3 log
RSIT log

And let me know how things are running :thumbup:
Moveit log after rebooting:
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
========== REGISTRY ==========
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 10312008_153254

Files moved on Reboot…
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.



RSIT log & info text:
Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-31 15:40:03
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 76 GB (80%) free of 95 GB
Total RAM: 1279 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:40:08 PM, on 10/31/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Alltel\GoBoingo\AlltelWifi.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Owner\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Owner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll (file missing)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [GoBoingo] C:\Program Files\Alltel\GoBoingo\AlltelWifi.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jd…ows-i586-jc.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.35.18/ttinst.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (file missing)
O23 - Service: CA License Client (CA_LIC_CLNT) - Unknown owner - C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: getPlus® Helper - Unknown owner - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (file missing)
O23 - Service: LiveUpdate - Unknown owner - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (file missing)
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)
O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)
O24 - Desktop Component 1: Ocean Aquarium Deluxe v1.0 Active Desktop - C:\Program Files\Ocean Aquarium 3D Deluxe\Active Desktop\Ocean_Aquarium_3D_Active_DT.html

–
End of file - 7728 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\At1.job
C:\WINDOWS\tasks\At2.job
C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Owner.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll []
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll []
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll []
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2008-09-01 2549368]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2003-11-20 4866048]
"nwiz"=nwiz.exe /installquiet []
"BCMSMMSG"=C:\WINDOWS\BCMSMMSG.exe [2003-08-29 122880]
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe [2003-08-06 114741]
"RealTray"=C:\Program Files\Real\RealPlayer\RealPlay.exe [2007-06-21 26112]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"GoBoingo"=C:\Program Files\Alltel\GoBoingo\AlltelWifi.exe [2007-10-02 324912]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-09-01 39408]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2006-06-19 702768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"=C:\Program Files\ewido anti-malware\shellhook.dll [2004-09-30 39488]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceClassicControlPanel"=1
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"NoDrives"=
"NoDriveAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\Program Files\MSN Messenger\msncall.exe"="C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"

======List of files/folders created in the last 1 months======

2008-10-31 15:40:03 —-D—- C:\rsit
2008-10-31 15:05:52 —-SHD—- C:\RECYCLER
2008-10-31 15:05:48 —-D—- C:\_OTMoveIt
2008-10-31 11:42:32 —-D—- C:\WINDOWS\temp
2008-10-31 11:42:31 —-A—- C:\ComboFix.txt
2008-10-31 11:40:47 —-D—- C:\ComboFix
2008-10-30 19:56:08 —-A—- C:\hijackthis log1.txt
2008-10-30 19:55:24 —-D—- C:\Program Files\Trend Micro
2008-10-30 16:38:00 —-A—- C:\Boot.bak
2008-10-30 16:37:53 —-RASHD—- C:\cmdcons
2008-10-30 16:13:16 —-D—- C:\Documents and Settings\All Users\Application Data\GoBoingo
2008-10-30 15:53:36 —-A—- C:\WINDOWS\zip.exe
2008-10-30 15:53:36 —-A—- C:\WINDOWS\VFIND.exe
2008-10-30 15:53:36 —-A—- C:\WINDOWS\SWXCACLS.exe
2008-10-30 15:53:36 —-A—- C:\WINDOWS\SWSC.exe
2008-10-30 15:53:36 —-A—- C:\WINDOWS\SWREG.exe
2008-10-30 15:53:36 —-A—- C:\WINDOWS\sed.exe
2008-10-30 15:53:36 —-A—- C:\WINDOWS\NIRCMD.exe
2008-10-30 15:53:36 —-A—- C:\WINDOWS\grep.exe
2008-10-30 15:53:36 —-A—- C:\WINDOWS\fdsv.exe
2008-10-30 15:53:35 —-D—- C:\WINDOWS\ERDNT
2008-10-30 15:53:35 —-AD—- C:\Qoobox
2008-10-29 15:24:47 —-A—- C:\WINDOWS\ModemLog_HUAWEI Mobile Connect - 3G Modem #2.txt
2008-10-29 14:57:47 —-D—- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-10-29 14:57:42 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-29 14:57:42 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-29 09:48:53 —-D—- C:\Program Files\Alltel
2008-10-24 09:00:40 —-HDC—- C:\WINDOWS\$NtUninstallKB958644$
2008-10-21 09:06:28 —-D—- C:\Documents and Settings\All Users\Application Data\NOS
2008-10-16 20:19:55 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2008-10-16 20:19:48 —-HDC—- C:\WINDOWS\$NtUninstallKB956391$
2008-10-16 20:19:40 —-HDC—- C:\WINDOWS\$NtUninstallKB957095$
2008-10-16 20:18:54 —-HDC—- C:\WINDOWS\$NtUninstallKB954211$
2008-10-16 20:18:36 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
2008-10-02 10:00:50 —-D—- C:\Documents and Settings\Owner\Application Data\Snapfish

======List of files/folders modified in the last 1 months======

2008-10-31 15:40:00 —-D—- C:\WINDOWS\Prefetch
2008-10-31 15:33:04 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-31 15:02:32 —-A—- C:\WINDOWS\ModemLog_HUAWEI Mobile Connect - 3G Modem.txt
2008-10-31 11:52:37 —-D—- C:\WINDOWS
2008-10-31 11:42:33 —-D—- C:\WINDOWS\system32
2008-10-31 11:41:54 —-A—- C:\WINDOWS\system.ini
2008-10-31 11:41:35 —-D—- C:\WINDOWS\system32\drivers
2008-10-31 11:41:34 —-D—- C:\WINDOWS\AppPatch
2008-10-31 11:41:34 —-D—- C:\Program Files\Common Files
2008-10-31 09:02:20 —-D—- C:\WINDOWS\system32\CatRoot
2008-10-31 09:00:42 —-HD—- C:\WINDOWS\inf
2008-10-30 19:55:24 —-RD—- C:\Program Files
2008-10-30 19:52:45 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-30 16:52:55 —-D—- C:\WINDOWS\system32\config
2008-10-30 16:38:00 —-RASH—- C:\boot.ini
2008-10-30 16:13:35 —-SHD—- C:\WINDOWS\Installer
2008-10-29 15:24:47 —-A—- C:\WINDOWS\ModemLog_BCM V.92 56K Modem.txt
2008-10-29 15:18:55 —-D—- C:\Program Files\Common Files\Symantec Shared
2008-10-29 15:16:43 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-29 10:17:09 —-A—- C:\WINDOWS\win.ini
2008-10-27 14:13:33 —-D—- C:\WINDOWS\system32\Restore
2008-10-27 14:02:33 —-D—- C:\Program Files\Windows NT
2008-10-27 14:02:32 —-D—- C:\Program Files\Windows Media Player
2008-10-27 14:02:29 —-D—- C:\Program Files\WordPerfect Office 11
2008-10-27 14:02:19 —-D—- C:\Program Files\THQ
2008-10-27 14:02:14 —-D—- C:\Program Files\Sonic
2008-10-27 14:02:06 —-D—- C:\Program Files\Outlook Express
2008-10-27 14:02:01 —-D—- C:\Program Files\NetMeeting
2008-10-27 14:01:56 —-D—- C:\Program Files\Movie Maker
2008-10-27 14:01:41 —-D—- C:\Program Files\Norton AntiVirus
2008-10-27 14:01:40 —-D—- C:\Program Files\Microsoft Works
2008-10-27 14:00:48 —-D—- C:\Program Files\Internet Explorer
2008-10-27 14:00:40 —-D—- C:\Program Files\Google
2008-10-27 14:00:33 —-D—- C:\Program Files\Common Files\System
2008-10-27 14:00:09 —-D—- C:\Program Files\ewido anti-malware
2008-10-27 14:00:09 —-D—- C:\Program Files\Edmark
2008-10-27 14:00:04 —-D—- C:\Program Files\Common Files\Real
2008-10-27 14:00:03 —-D—- C:\Program Files\Common Files\Microsoft Shared
2008-10-27 14:00:02 —-D—- C:\Program Files\Common Files\aolshare
2008-10-27 13:59:59 —-D—- C:\Program Files\CA
2008-10-27 13:59:53 —-D—- C:\Program Files\Adobe
2008-10-27 13:59:52 —-D—- C:\Program Files\3DO
2008-10-26 20:35:06 —-D—- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-24 16:18:21 —-AD—- C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-24 09:00:21 —-HD—- C:\WINDOWS\$hf_mig$
2008-10-21 09:12:35 —-D—- C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-10-21 09:12:31 —-D—- C:\Program Files\Common Files\Adobe
2008-10-21 09:06:29 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-10-16 20:19:59 —-A—- C:\WINDOWS\imsins.BAK
2008-10-15 12:34:24 —-A—- C:\WINDOWS\system32\netapi32.dll
2008-10-15 09:50:32 —-D—- C:\WINDOWS\network diagnostic
2008-10-07 15:19:40 —-A—- C:\WINDOWS\system32\MRT.exe
2008-10-06 18:56:10 —-A—- C:\DVDPATH.TXT
2008-10-04 18:37:22 —-A—- C:\WINDOWS\system32\DEBUG_LOG.txt
2008-10-03 13:41:15 —-A—- C:\WINDOWS\system32\ieframe.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 OMCI;OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [2001-08-22 13632]
R1 SRTSPX;SRTSPX; C:\WINDOWS\System32\Drivers\SRTSPX.SYS [2007-11-30 43696]
R1 sscdbhk5;sscdbhk5; C:\WINDOWS\system32\drivers\sscdbhk5.sys [2003-07-14 5621]
R1 ssrtln;ssrtln; C:\WINDOWS\system32\drivers\ssrtln.sys [2003-07-14 23219]
R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2008-06-13 184240]
R2 ASCTRM;ASCTRM; C:\WINDOWS\system32\drivers\ASCTRM.sys [2007-06-21 8552]
R2 drvnddm;drvnddm; C:\WINDOWS\system32\drivers\drvnddm.sys [2003-06-20 40448]
R2 symlcbrd;symlcbrd; \??\C:\WINDOWS\system32\drivers\symlcbrd.sys []
R2 tfsnboio;tfsnboio; C:\WINDOWS\system32\dla\tfsnboio.sys [2003-08-06 25685]
R2 tfsncofs;tfsncofs; C:\WINDOWS\system32\dla\tfsncofs.sys [2003-08-06 34837]
R2 tfsndrct;tfsndrct; C:\WINDOWS\system32\dla\tfsndrct.sys [2003-08-06 4117]
R2 tfsndres;tfsndres; C:\WINDOWS\system32\dla\tfsndres.sys [2003-08-06 2233]
R2 tfsnifs;tfsnifs; C:\WINDOWS\system32\dla\tfsnifs.sys [2003-08-06 83284]
R2 tfsnopio;tfsnopio; C:\WINDOWS\system32\dla\tfsnopio.sys [2003-08-06 14229]
R2 tfsnpool;tfsnpool; C:\WINDOWS\system32\dla\tfsnpool.sys [2003-08-06 6357]
R2 tfsnudf;tfsnudf; C:\WINDOWS\system32\dla\tfsnudf.sys [2003-08-06 98068]
R2 tfsnudfa;tfsnudfa; C:\WINDOWS\system32\dla\tfsnudfa.sys [2003-08-06 100373]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2002-12-17 42368]
R3 BCMModem;BCM V.92 56K Modem; C:\WINDOWS\system32\DRIVERS\BCMSM.sys [2003-08-29 1101696]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2007-10-10 101120]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2003-11-20 1378172]
R3 PCASp50;PCASp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PCASp50.sys [2006-06-06 20096]
R3 STAC97;Audio Driver (WDM) - SigmaTel CODEC; C:\WINDOWS\system32\drivers\STAC97.sys [2003-04-25 220176]
R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 SymIMMP;SymIMMP; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-06-13 31280]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
S1 ewido security suite driver;ewido security suite driver; \??\C:\Program Files\ewido anti-malware\guard.sys []
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 COH_Mon;COH_Mon; \??\C:\WINDOWS\system32\Drivers\COH_Mon.sys []
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 jdmboot;jdmboot; \??\C:\DOCUME~1\Owner\LOCALS~1\Temp\jdmboot.sys []
S3 JL2005C;Dual Mode Camera; C:\WINDOWS\System32\Drivers\jl2005c.sys [2007-01-26 68954]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081026.016\NAVENG.SYS []
S3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081026.016\NAVEX15.SYS []
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
S3 SRTSP;SRTSP; C:\WINDOWS\System32\Drivers\SRTSP.SYS [2007-11-30 279088]
S3 SRTSPL;SRTSPL; C:\WINDOWS\System32\Drivers\SRTSPL.SYS [2007-11-30 317616]
S3 ssecdrv;ssecdrv; \??\C:\DOCUME~1\Owner\LOCALS~1\Temp\ssecdrv.sys []
S3 StillCam;Still Serial Digital Camera Driver; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-08-17 6784]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 SYMDNS;SYMDNS; C:\WINDOWS\System32\Drivers\SYMDNS.SYS [2008-06-13 13616]
S3 SYMFW;SYMFW; C:\WINDOWS\System32\Drivers\SYMFW.SYS [2008-06-13 96432]
S3 SYMIDS;SYMIDS; C:\WINDOWS\System32\Drivers\SYMIDS.SYS [2008-06-13 38576]
S3 SYMIDSCO;SYMIDSCO; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\ipsdefs\20081023.002\SymIDSCo.sys []
S3 SymIM;Symantec Network Security Intermediate Filter Service; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-06-13 31280]
S3 SYMNDIS;SYMNDIS; C:\WINDOWS\System32\Drivers\SYMNDIS.SYS [2008-06-13 37424]
S3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2008-06-13 22320]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys []
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 xraspptp;xraspptp; \??\C:\DOCUME~1\Owner\LOCALS~1\Temp\xraspptp.sys []
S3 yfs_rec;yfs_rec; \??\C:\DOCUME~1\Owner\LOCALS~1\Temp\yfs_rec.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ewido security suite control;ewido security suite control; C:\Program Files\ewido anti-malware\ewidoctrl.exe [2005-11-30 13888]
R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-22 168432]
R2 LogWatch;Event Log Watch; C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2005-02-23 53248]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2003-11-20 77824]
S2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe []
S2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S2 LiveUpdate Notice;LiveUpdate Notice; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S2 Symantec Core LC;Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe []
S3 CA_LIC_CLNT;CA License Client; C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe []
S3 getPlus® Helper;getPlus® Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe []
S3 LiveUpdate;LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE []
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe []
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 ewido security suite guard;ewido security suite guard; C:\Program Files\ewido anti-malware\ewidoguard.exe []

—————–EOF—————–


info.txt logfile of random's system information tool 1.04 2008-10-31 15:40:10

======Uninstall list======

–>"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
–>C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
–>C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
–>C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com–>MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Adobe AIR–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR–>MsiExec.exe /I{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}
Adobe Flash Player ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.8–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70800000002}
Adobe Shockwave Player–>C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Alltel Wi-Fi Connection Software–>MsiExec.exe /X{CF2CE2A4-6A99-4F97-AD7C-302002A67B38}
America Online–>C:\Program Files\Common Files\aolshare\Aolunins_us.exe
AOL Coach Version 1.0(Build:20020823.1)–>C:\WINDOWS\AolCInUn.exe
AppCore–>MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
Barbie ® as Princess Bride ™–>C:\WINDOWS\ISUninst.exe -f"C:\Program Files\Mattel Interactive\Barbie ®\Barbie ® as Princess Bride ™\Uninst.isu"
Barbie™ Horse Adventures™–>C:\Program Files\Common Files\Vivendi Universal Games\Uninstall\HorseUn.exe
Barbie™ Mermaid Adventure™ CD-ROM–>C:\Program Files\Common Files\Vivendi Universal Games\Uninstall\MermaidUn.exe
BCM V.92 56K Modem–>C:\WINDOWS\BCMSMU.exe quiet
Blue's 123 Time Activities–>C:\WINDOWS\IsUninst.exe -fc:\hegames\Blues123\Uninst.isu -c"c:\hegames\Blues123\Uninst.dll
Blue's Preschool–>C:\WINDOWS\uninst.exe -f"C:\Program Files\Infogrames Interactive\Blue's Preschool\DeIsL1.isu"
Blue's Treasure Hunt–>C:\WINDOWS\IsUninst.exe -f"c:\hegames\Blues Treasure Hunt\Uninst.isu" -c"c:\hegames\Blues Treasure Hunt\Uninst.dll
Broadcom 440x Driver Installer–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{52504CE6-E909-4113-B232-4AFEC6543A61} /l1033
CA Desktop DNA Migrator–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{D45F478E-981B-414F-8D1D-B43F0049AFCC} /l1033
Canon Camera Window for ZoomBrowser EX–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{A29EA741-24F7-4C07-9B2C-06CB6491BE4A}
Canon i80–>C:\WINDOWS\system32\CNMCP5u.exe "-PRINTERNAMECanon i80" "-HELPERDLLC:\BJPrinter\CNMWINDOWS\Canon i80 Installer\Inst2\cnmis.dll" "-RCDLLC:\BJPrinter\CNMWINDOWS\Canon i80 Installer\Inst2\cnmi0409.dll"
Canon PhotoRecord–>MsiExec.exe /X{BEF56F2D-56ED-4176-BF72-7B68D4A3B98D}
Canon RAW Image Task for ZoomBrowser EX–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{FAF0DAD8-1EA7-4FEF-80E5-8D8D6EBD5A23}
Canon RemoteCapture Task for ZoomBrowser EX–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{2236B741-6631-49AE-B76E-3E14CA01CC87}
Canon Utilities Easy-PhotoPrint Plus–>C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Canon\Easy-PhotoPrint Plus\Uninst.isu" -c"C:\Program Files\Canon\Easy-PhotoPrint Plus\EZUNINST.DLL"
Canon Utilities PhotoStitch 3.1–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{03CDDD00-BD57-4326-9480-4C74449AF597}
Canon Utilities ZoomBrowser EX–>MsiExec.exe /X{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}
Care Bears Lets Have a Ball (remove only)–>"C:\Program Files\ValuSoft\Care Bears Lets Have a Ball\uninstall.exe"
Casper Activity Center–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Sound Source Interactive\Casper Activity Center\Uninst.isu"
Catz2 (remove only)–>"C:\Program Files\Ubisoft\Catz2\uninstall.exe" 1033
ccCommon–>MsiExec.exe /I{B24E05CC-46FF-4787-BBB8-5CD516AFB118}
Chuzzle Deluxe 1.0–>C:\Program Files\PopCap Games\Chuzzle Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Chuzzle Deluxe\Install.log"
Component Framework–>MsiExec.exe /I{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}
Curious George Downtown Adventure–>C:\Program Files\Common Files\Knowledge Adventure\Uninstall\UNCGTown.exe
Dell ResourceCD–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D78653C3-A8FF-415F-92E6-D774E634FF2D}\setup.exe"
Disciples 2–>C:\PROGRA~1\DISCIP~1\UNWISE.EXE C:\PROGRA~1\DISCIP~1\INSTALL.LOG
Disney Pirates of the Caribbean Online–>C:\Program Files\Disney\Disney Online\PiratesOnline\uninst.exe
Disneys Digital Coloring Book Featuring Pooh–>C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\DISNEY~1\DISNEY~2\DeIsL1.isu
Disney's Toontown Online–>C:\PROGRA~1\Disney\DISNEY~1\Toontown\UNWISE.EXE /A C:\PROGRA~1\Disney\DISNEY~1\Toontown\INSTALL.LOG
Disney's Winnie the Pooh Toddler–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Disney Interactive\Winnie the Pooh Toddler\DeIsL1.isu" -c"C:\Program Files\Disney Interactive\Winnie the Pooh Toddler\Uninst.dll
Dora the Explorer La Casa de Dora–>"C:\Program Files\Activision Value\Dora the Explorer La Casa de Dora\unins000.exe"
Dora the Explorer: Animal Adventures–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A34CCD1C-7738-47B9-863D-8E0C478FB8F7}\setup.exe" -l0x9 -uninst
Easy-WebPrint–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Canon\Easy-WebPrint\Uninst.isu"
Elmo's Deep Sea Adventure–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7BE8EBE8-90AA-11D5-BA72-0048546FEA44}\setup.exe"
Finding Nemo: Nemo's Underwater World of Fun Special Edition–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{77FCC1D4-E78E-46A4-80A6-7F456FA9AC90} NemoUWF2Uninstall
Fisher-Price® - Discovery Farm–>C:\WINDOWS\uninst.exe -f"C:\Program Files\Fisher-Price\FPFarm\DeIsL1.isu"
Fisher-Price® - Toddler–>C:\WINDOWS\UNINST.EXE
Fisher-Price® ABC/123–>C:\Program Files\Tlcwin\ABC123\uninstal.exe
Fisher-Price® Discovery Farm/Playhouse–>C:\Program Files\Tlcwin\Little\uninstal.exe
Full Tilt Poker–>"C:\Program Files\InstallShield Installation Information\{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}\setup.exe" -runfromtemp -l0x0009 -removeonly
Fun on the Farm with Barney–>C:\Program Files\Microsoft ActiMates\Barney\Farm\uninstal.exe
GameSpy Arcade–>C:\PROGRA~1\GAMESP~1\UNWISE.EXE C:\PROGRA~1\GAMESP~1\INSTALL.LOG
getPlus® for Adobe–>"C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1
Go Diego Go! Wolf Pup Rescue–>"C:\Program Files\Activision Value\Go Diego Go! Wolf Pup Rescue\unins000.exe"
Google Earth–>MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Google Toolbar for Internet Explorer–>MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer–>regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
Google Updater–>"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Heroes of Might and Magic® IV: Winds of War–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\3DO\Heroes of Might and Magic IV\Heroes of Might and Magic IV.isu" -c"C:\Program Files\Common Files\3DO Shared\3DOUnInst.dll -c"C:\Program Files\Common Files\3DO Shared\3DOUnInst.dll -c"C:\Program Files\Common Files\3DO Shared\3DOUnInst.dll
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)–>"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)–>"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hoyle Board Games 5–>C:\WINDOWS\IsUninst.exe -f"C:\SIERRA\Hoyle Board Games 5\Uninst.isu"
Hoyle Card Games 2003–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{9ABA26E1-843A-4A72-95AF-C72474E191F6}
Hoyle Casino 6–>C:\WINDOWS\IsUninst.exe -f"C:\SIERRA\Hoyle Casino 6\Uninst.isu"
I Can Be An Animal Doctor–>C:\WINDOWS\uninst.exe -fC:\Cloud9\DeIsL1.isu
i80 Setup Utility–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CFA679D8-5216-4E10-B7D3-BA4033A6991E}\setup.exe" /SUUninstall
IBM ViaVoice Command and Control Runtime 5.3–>C:\ViaVoice\Bin\vunUS.exe ProdRunControl Dc En_US 'IBM ViaVoice™ Command and Control Runtime' C:\WINDOWS\IsUninst.exe -fC:\ViaVoice\DeIsL3.isu
IBM ViaVoice Outloud Runtime - US English–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ViaVoice Outloud\DeIsL2.isu"
InterActual Player–>C:\Program Files\InterActual\InterActual Player\inuninst.exe
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Jimmy Neutron Boy Genius–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\THQ\Jimmy Neutron\Jimmy Neutron Boy Genius\Uninst.isu"
JumpStart Parent Resource Center v1.0–>C:\WINDOWS\IsUninst.exe -fC:\KA\PRC\DeIsL1.isu
JumpStart Preschool v2.0–>C:\WINDOWS\IsUninst.exe -fC:\KA\PRSCHL99\DeIsL1.isu
Kitty Luv v1.6–>"C:\Program Files\Kitty Luv\unins000.exe"
Leap Ahead Kindergarten–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\The Learning Company\Leap Ahead Kindergarten\Uninst.isu"
LEGO Creator–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\LEGO Media\Constructive\CREATOR\Uninst.isu"
LimeWire 4.18.6–>"C:\Program Files\LimeWire\uninstall.exe"
Little Mermaid II Return to the Sea–>C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\DISNEY~1\DISNEY~1\DeIsL1.isu
Little People® Discovery Airport–>C:\Program Files\Common Files\Knowledge Adventure\Uninstall\FPAirportUn.exe
LiveUpdate (Symantec Corporation)–>MsiExec.exe /x {E80F62FF-5D3C-4A19-8409-9721F2928206} /l*v "C:\Documents and Settings\All Users\Application Data\LuUninstall.LiveUpdate"
LiveUpdate (Symantec Corporation)–>MsiExec.exe /X{E80F62FF-5D3C-4A19-8409-9721F2928206}
Mad Caps–>"C:\Program Files\Mad Caps\unins000.exe"
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Math 3 & 5–>C:\Program Files\InstallShield Installation Information\{645AA7D1-2EDC-4F4F-A66A-AC9E7291B520}\setup.exe -runfromtemp -l0x0009 -removeonly
MathPlayer–>C:\Program Files\Design Science\MathPlayer\Setup.exe -u
MathQuest–>C:\WINDOWS\uninst.exe -fC:\Disney\MathQuest\DeIsL1.isu
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Encarta Encyclopedia Standard 2004–>MsiExec.exe /I{04410044-9149-45C6-A806-F2BF9CFCE762}
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft Money 2004 System Pack–>MsiExec.exe /I{8C64E145-54BA-11D6-91B1-00500462BE80}
Microsoft Money 2004–>MsiExec.exe /I{1D643CD7-4DD6-11D7-A4E0-000874180BB3}
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft User-Mode Driver Framework Feature Pack 1.0–>"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Works 7.0–>MsiExec.exe /I{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}
Millie's Math House (Remove only)–>C:\WINDOWS\edmkuni2.exe "C:\Program Files\Edmark\Millie's Math House "
Miss Spider–>C:\MISSSP~1\UNINST~1.EXE C:\MISSSP~1\INSTALL.LOG
MSXML 4.0 SP2 (KB927978)–>MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
Muppet Babies - Sorting and Thinking–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D91EBEEC-700D-44A1-A394-6EBD1D93F281}\setup.exe"
MyIdentityDefender Toolbar (CyberDefender Corporation)–>C:\Documents and Settings\Owner\Local Settings\Application Data\CyberDefender\cdinstx.exe /u
MyLearnExpress–>C:\Program Files\InstallShield Installation Information\{0F956834-2785-4E63-A2AB-C1CB6359191B}\setup.exe -runfromtemp -l0x0009 -removeonly
Netflix Movie Viewer–>MsiExec.exe /X{BCE72AED-3332-4863-9567-C5DCB9052CA2}
NetWaiting–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\Setup.exe" -l0x9 ControlPanelAnyText
Norton AntiVirus (Symantec Corporation)–>"C:\Program Files\Common Files\Symantec Shared\SymSetup\{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}_15_0_0_58\Setup.exe" /X
Norton AntiVirus Help–>MsiExec.exe /I{34EEB1F5-E939-40A1-A6BA-957282A4B2C8}
Norton AntiVirus–>MsiExec.exe /X{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}
Norton PC Checkup–>C:\Program Files\Norton PC Checkup\uninstall.exe
Norton Protection Center–>MsiExec.exe /I{62120008-8E1E-4807-860D-A8B48F8552DB}
Nutcracker Game 2.1–>"C:\Program Files\Games\Nutcracker\unins000.exe"
NVIDIA Windows 2000/XP Display Drivers–>rundll32.exe C:\WINDOWS\system32\nvinstnt.dll,NvUninstallNT4 nvdm.inf
Ocean Aquarium 3D Deluxe v1 Screen Saver–>C:\WINDOWS\Ocean Aquarium 3D Deluxe v1.scr /u
Ocean Aquarium 3D Deluxe–>C:\WINDOWS\iun6002.exe "C:\Program Files\Ocean Aquarium 3D Deluxe\irunin.ini"
OpenOffice.org Installer 1.0–>MsiExec.exe /X{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
Operation–>C:\WINDOWS\uninst.exe -f"C:\Program Files\Hasbro Interactive\Operation\DeIsL1.isu"
PartyPoker–>"C:\Program Files\PartyGaming\PartyPoker\Uninstall.exe" "C:\Program Files\PartyGaming\PartyPoker\install.log"
Pet Vet 2–>"C:\Program Files\Pet Vet 2\unins000.exe"
PowerDVD–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
QuickLink Mobile–>C:\PROGRA~1\Alltel\QUICKL~1\UNWISE.EXE C:\PROGRA~1\Alltel\QUICKL~1\INSTALL.LOG
QuickTime–>C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
Reader Rabbit Learn To Read With Phonics–>C:\Program Files\The Learning Company\Reader Rabbit Learn To Read With Phonics\uninstal.exe
Reader Rabbit's Reading Ages 6-9–>C:\WINDOWS\IsUninst.exe -fC:\Tlcwin\Rrread69\Uninst\DeIsL1.isu
Reading Rollercoaster (Remove only)–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Edmark\Reading Rollercoaster\Uninst.isu"
RealPlayer Basic–>C:\Program Files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
Scholastic's I SPY Junior–>C:\PROGRA~1\SCHOLA~1\ISPYJU~1\UNWISE.EXE C:\PROGRA~1\SCHOLA~1\ISPYJU~1\INSTALL.LOG
Security Update for Windows Internet Explorer 7 (KB929969)–>"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)–>"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127-v2)–>"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)–>"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB917734)–>"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)–>C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
SereneScene Marine Aquarium 2–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\SereneScreen\Marine Aquarium 2\Uninst.isu"
Shark Tale–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{A2C21F60-523D-4FC7-90AF-AE2707E45AFE}
Shockwave–>C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
SigmaTel AC97 Audio Drivers–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7959721D-8268-4565-9E0E-C41A9F4848A9}\setup.exe" -l0x9 -nodialog -uninstall
Smart Menus (Windows Live Toolbar)–>MsiExec.exe /X{95FC661A-A0C5-4B18-92CE-90347DA79CC9}
Sonic DLA–>MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
Sonic RecordNow!–>MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
Sonic Update Manager–>MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
SPBBC 32bit–>MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
Sponge Bob Collapse–>"C:\Program Files\Sponge Bob Collapse\unins000.exe"
SpongeBob SquarePants® Operation Krabby Patty–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\THQ\SpongeBob SquarePants\Operation Krabby Patty\Uninst.isu"
Strawberry Shortcake - Amazing Cookie Party–>C:\WINDOWS\TLCUninstall.exe -f "C:\Program Files\The Learning Company\Strawberry Shortcake - Amazing Cookie Party\Uninstall.xml"
Symantec KB-DocID:2003093015493306–>MsiExec.exe /I{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}
SymNet–>MsiExec.exe /I{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}
Tetris Worlds–>C:\PROGRA~1\TETRIS~1\UNWISE.EXE C:\PROGRA~1\TETRIS~1\INSTALL.LOG
Texas Hold'em Poker–>MsiExec.exe /I{92495AFF-ECFB-4560-AD90-65BD6327BFC4}
The Cat in the Hat–>C:\WINDOWS\uninst.exe -f"C:\Program Files\Living Books\DeIsL1.isu"
The ClueFinders 5th Grade Adventures–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\The Learning Company\The ClueFinders 5th Grade Adventures\Uninst.isu"
The Sims Unleashed–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7C32C567-DC0F-4C80-B06C-7873850A2E06}\setup.exe" -l0009
The Story of Creation–>C:\WINDOWS\uninst.exe -fC:\Ltl_Ark\DeIsL1.isu
The Three Little Pigs–>C:\WINDOWS\UNWISE.EXE /A C:\PROGRA~1\DKINTE~1\THREEL~1\INSTALL.LOG
Tumblebugs–>"C:\Program Files\Tumblebugs\unins000.exe"
Uninstall Dual Mode Camera–>"C:\Program Files\JL2005C\unins000.exe"
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Video Journal Version 1.4–>"C:\Program Files\GirlTech\Video Journal\unins000.exe"
Viewpoint Media Player (Remove Only)–>C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
Windows Live Sign-in Assistant–>MsiExec.exe /I{22B3CC30-77B8-419C-AA4B-F571FDF5D66D}
Windows Live Toolbar–>"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {9DA72A9F-4246-4C10-B0FA-D8C1037D45F8}
Windows Live Toolbar–>MsiExec.exe /X{9DA72A9F-4246-4C10-B0FA-D8C1037D45F8}
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WordPerfect Office 11–>MsiExec.exe /I{54F90B55-BEB3-4F0D-8802-228822FA5921}
Yahoo! Toolbar–>C:\PROGRA~1\Yahoo!\Common\unyt.exe
You Can Fly! with Tinker Bell–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B5071AC4-B0E3-11D5-AA2E-0008C760B784}\setup.exe"

======Security center information======

AV: Norton AntiVirus
FW: Norton AntiVirus

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=C:\WINDOWS\system32;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=0209
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

—————–EOF—————–

Sorry, spoke too soon, it tries to open the IE, but gets stuck and closes immediately.

Is internet explorer not opening at all, or are you just having a problem connecting to the internet?


Please do the following…

OTMoveIt3 by OldTimer

  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Files
    C:\WINDOWS\tasks\At1.job
    C:\WINDOWS\tasks\At2.job
    :Reg
    :Commands
    [purity]
    [emptytemp]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

===============================================

Malwarebytes' Anti-Malware

Please re-run Malwarebytes' Anti-Malware
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

===============================================

In your next reply post the MBAM, and OTmoveIt logs, and let me know about the internet explorer and internet connection :thumbup:
The IE is still not starting. I use alltel's cell phone internet access (alltel wireless) and that connects, so I should be able to get online. But when I click the IE icon or the IE shortcut icon, a white page pops up for half a second then disappears. My computer reads that it is connected, but no page will stay up. So I'm still using a second computer to do everything. Here are the latest results….

Moveit! log:

========== FILES ==========
C:\WINDOWS\tasks\At1.job moved successfully.
C:\WINDOWS\tasks\At2.job moved successfully.
========== REGISTRY ==========
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 11012008_230556

Files moved on Reboot…
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.



Malwarebyte anti-malware log:

Malwarebytes' Anti-Malware 1.30
Database version: 1306
Windows 5.1.2600 Service Pack 3

11/1/2008 11:13:43 PM
mbam-log-2008-11-01 (23-13-43).txt

Scan type: Quick Scan
Objects scanned: 41978
Time elapsed: 3 minute(s), 20 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI