This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] NC605007.exe-Internet Explorer is being controlled by Ad

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I use Firefox for browsing. IE will open on its own with 2-3 tabs of ads running. I ran the recommended programs to self fix Adware and Malware and I am still having issues. This is the one that just opened now as I type this…http://track.internetbrandsurvey.com/?PromoID=17853&SID=CD8319&&subid1=booster2&
I ran hijack this, Malwarebytes' Anti-Malware and the ATF cleaner, but in the order it was listed on your site. Then Norton picked up a risk and did whatever Norton does, but I still have the same problem happening. I have added the log files below. I ran a second Malwarebytes' Anti-Malware and it found nothing. This is the most recent hijack log file. I cannot find the first one I ran this morning. What do I do now? Thanks in advance~TazzyGirl!

Malwarebytes' Anti-Malware 1.30
Database version: 1379
Windows 5.1.2600 Service Pack 2

11/10/2008 8:05:40 AM
mbam-log-2008-11-10 (08-04-37).txt

Scan type: Quick Scan
Objects scanned: 58325
Time elapsed: 23 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 13
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 1
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{09f1adac-76d8-4d0f-99a5-5c907dadb988} (Rogue.Multiple) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f8ea6827-1b82-494a-acac-a582a714dca8} (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{f8ea6827-1b82-494a-acac-a582a714dca8} (Adware.BHO) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Host Process (Worm.IRCBot) -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.115.82 85.255.112.25 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.115.82 85.255.112.25 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.115.82 85.255.112.25 -> No action taken.

Folders Infected:
C:\WINDOWS\Fonts\' (Trojan.Agent) -> Files: 36424 -> No action taken.

Files Infected:
C:\WINDOWS\system32\msnav32.ax (Malware.Trace) -> No action taken.
C:\WINDOWS\sbsHOHo.dll (Adware.BHO) -> No action taken.


Logfile of HijackThis v1.99.1
Scan saved at 3:57:37 PM, on 11/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\Logi_MwX.Exe
C:\PROGRA~1\KEMailKb\KEMailKb.EXE
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\rmctrl.exe
C:\Program Files\Say the Time\SayTime.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Sierra\Planner\Plnrnote.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\Program Files\MSI\TV@Anywhere Utilities\P3XRCtl.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\ppcbooster\ppcb_32.exe
C:\Program Files\Webshots\WebshotsTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cleveland.cox.net/cci/home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - (no file)
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [KEMailKb] C:\PROGRA~1\KEMailKb\KEMailKb.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Say the Time] C:\Program Files\Say the Time\SayTime.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04b\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [SansaDispatch] C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Startup: ppcb_32.lnk = C:\Program Files\ppcbooster\ppcb_32.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Event Planner Reminders Tray Icon.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O4 - Global Startup: TV Remote Control.lnk = C:\Program Files\MSI\TV@Anywhere Utilities\P3XRCtl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143530611687
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
Hi TazzyGirl,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

-> No action taken.

Please re-run Malwarebytes and this time choose Remove Selected
Please post the new report back here.

Then


Download and Run SmitfraudFix
Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Also please post a new HijackThis log.
I downloaded SmitfraudFix and opened the folder, but didn't find SmitfraudFix.cmd. I tried the .exe, but it said files missing. Then I tried the unzip file in the folder and nothing happened. I really don't think I am this stupid, but it sure looks that way right now LOL! What next?
Being that I am new to posting…I somehow lost my initial reply to you. I don't think fast reply and I will be getting along well. So here is the scan from this morning and there are 17 files in quarantine. I am assuming that I should delete these items, but will wait for your response first. Also, in IE options I blocked the sites that IE was being taken to. That put a band-aid on the boo boo for annoyance level at least. Malwarebytes' Anti-Malware 1.30 Database version: 1379 Windows 5.1.2600 Service Pack 2 11/13/2008 8:53:06 AM mbam-log-2008-11-13 (08-53-06).txt Scan type: Quick Scan Objects scanned: 57571 Time elapsed: 10 minute(s), 53 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
TazzyGirl,

Extract the contents (a folder named SmitfraudFix) to your Desktop.

You must do this first.

Then the 15th item should be smitfraudfix.cmd
Smitfraudfix , in the command window is saying… iedfix.exe file missing unzip all the archive in a folder Press any key to continue… :pullhair: I will be the first to admit that I am not good at all with the command prompts thing, but this has me going over the edge! What am I doing wrong with this file that it isn't running? I don't suppose we are able to give phone numbers so you can talk me through this? I use this computer for work…If I connect to a remote computer via "Log Me In" will my machine infect their machine or server? Again, I use FireFox and they do use IE.
TazzyGirl,

Let's try this instead.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://www.bleepingcomputer.com/forums/topic114351.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Tom K,
Ok! This one is more my speed…thank you! I would like to have the autorun restored on the machine. If you could help me with that after this other issue is finished I would appreciate it.
Here are the results…


ComboFix 08-11-16.05 - Carol 2008-11-17 11:02:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.179 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\ppcbooster
c:\program files\ppcbooster\ppcbu_32.exe
c:\windows\cor704836.exe
c:\windows\ee3362.exe
c:\windows\eo4.exe
c:\windows\Fonts\a.zip
c:\windows\h288.exe
c:\windows\j414.exe
c:\windows\lik02.exe
c:\windows\ndxq3074.exe
c:\windows\tj85.exe

.
((((((((((((((((((((((((( Files Created from 2008-10-17 to 2008-11-17 )))))))))))))))))))))))))))))))
.

2008-11-10 07:34 . 2008-11-10 07:34 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-10 07:34 . 2008-11-10 07:34 d——– c:\documents and settings\Carol\Application Data\Malwarebytes
2008-11-10 07:34 . 2008-11-10 07:34 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-10 07:34 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-10 07:34 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-09 12:35 . 2008-11-09 12:35 d——– c:\documents and settings\Carol\Application Data\Blackberry Desktop
2008-11-01 16:19 . 2008-11-01 16:19 430,080 –a—— c:\windows\system32\BSTIEPrintCtl1.dll
2008-10-25 20:49 . 2008-10-25 20:49 d——– c:\documents and settings\All Users\Application Data\MysteryChronicles
2008-10-24 20:35 . 2008-10-24 20:40 d——– c:\documents and settings\Carol\Application Data\W Photo Studio
2008-10-24 20:34 . 2008-10-24 20:34 d——– c:\program files\Walgreens
2008-10-24 20:34 . 2008-10-24 20:34 d——– c:\documents and settings\Carol\Application Data\Walgreens
2008-10-24 20:34 . 2008-10-24 20:34 d——– c:\documents and settings\All Users\Application Data\Walgreens
2008-10-24 20:24 . 2008-10-24 20:33 d——– c:\documents and settings\Carol\Application Data\W Photo Studio Viewer

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-17 15:44 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-11-15 16:37 ——— d—–w c:\documents and settings\Carol\Application Data\LimeWire
2008-11-10 05:21 ——— d—–w c:\documents and settings\Carol\Application Data\Move Networks
2008-11-10 05:11 ——— d—–w c:\program files\Norton 360
2008-11-09 17:27 ——— d—–w c:\program files\Webshots
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-14 23:14 ——— d—–w c:\documents and settings\Carol\Application Data\Roxio
2008-10-12 00:48 ——— d—–w c:\program files\LimeWire
2008-10-07 00:24 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-06 07:00 ——— d—–w c:\program files\MSXML 6.0
2008-10-05 18:14 ——— d—–w c:\documents and settings\NetworkService\Application Data\Roxio
2008-10-05 18:08 ——— d—–w c:\documents and settings\Carol\Application Data\Research In Motion
2008-10-05 18:03 ——— d—–w c:\documents and settings\All Users\Application Data\Roxio
2008-10-05 17:58 ——— d—–w c:\program files\Common Files\Sonic Shared
2008-10-05 17:58 ——— d—–w c:\documents and settings\All Users\Application Data\Sonic
2008-10-05 17:57 ——— d—–w c:\program files\Roxio
2008-10-05 17:55 ——— d—–w c:\program files\Common Files\Roxio Shared
2008-10-05 17:41 ——— d—–w c:\program files\Common Files\Research In Motion
2008-10-05 17:40 ——— d—–w c:\program files\Research In Motion
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-27 00:35 ——— d—–w c:\documents and settings\Carol\Application Data\ScanSoft
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-04 16:42 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-09-01 11:57 60,800 —-a-w c:\windows\system32\S32EVNT1.DLL
2008-08-30 01:06 1,350,664 —-a-w c:\windows\system32\msxml6.dll
2008-08-26 07:24 826,368 —-a-w c:\windows\system32\wininet.dll
2008-02-28 18:30 8,784 —-a-w c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2008-02-28 18:33 245,408 —-a-w c:\program files\mozilla firefox\plugins\unicows.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@="{4433A54A-1AC8-432F-90FC-85F045CF383C}"
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-10-31 12:24 576352 –a—— c:\program files\Common Files\Symantec Shared\Backup\buShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@="{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}"
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-10-31 12:24 576352 –a—— c:\program files\Common Files\Symantec Shared\Backup\buShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@="{476D0EA3-80F9-48B5-B70B-05E677C9C148}"
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-10-31 12:24 576352 –a—— c:\program files\Common Files\Symantec Shared\Backup\buShell.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"="c:\program files\TGTSoft\StyleXP\StyleXP.exe" [2005-02-04 1159168]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KEMailKb"="c:\progra~1\KEMailKb\KEMailKb.EXE" [2002-12-31 253952]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"RemoteControl"="c:\windows\system32\rmctrl.exe" [2004-01-26 32768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
"Say the Time"="c:\program files\Say the Time\SayTime.exe" [2004-01-22 806912]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"SetDefPrt"="c:\program files\Brother\Brmfl04b\BrStDvPt.exe" [2004-05-25 49152]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 851968]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~2\mimboot.exe" [2006-01-19 11776]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-09-24 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]
"LiveMonitor"="c:\program files\MSI\Live Update 3\LMonitor.exe" [2006-09-05 497152]
"SansaDispatch"="c:\program files\SanDisk\Sansa Updater\SansaDispatch.exe" [2007-10-22 75584]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"nForce Tray Options"="sstray.exe" [2003-12-17 c:\windows\system32\sstray.exe]
"LTMSG"="LTMSG.exe" [2003-07-14 c:\windows\ltmsg.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 c:\windows\LOGI_MWX.EXE]
"nwiz"="nwiz.exe" [2006-03-09 c:\windows\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-12-14 c:\windows\soundman.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-11-29 c:\windows\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]

c:\documents and settings\Carol\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-08-21 147456]
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-04-19 64864]
Webshots.lnk - c:\program files\Webshots\WebshotsTray.exe [2006-03-28 196608]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-03-27 25214]
Event Planner Reminders Tray Icon.lnk - c:\program files\Sierra\Planner\Plnrnote.exe [2006-03-28 184320]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-09-24 282624]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-09-24 73728]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-03-27 789008]
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-04-19 64864]
PC Alert 4.lnk - c:\program files\MSI\PC Alert 4\PCAlert4.exe [2006-03-31 536576]
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2006-04-04 819200]
TV Remote Control.lnk - c:\program files\MSI\TV@Anywhere Utilities\P3XRCtl.exe [2006-03-28 94208]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\\Program Files\\TGTSoft\\StyleXP\\CurrentLogon.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-01-09 11:30 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIV3"= DIVXc32.dll
"vidc.DIV4"= DIVXc32f.dll
"vidc.ffds"= ffdshow.ax

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

R2 BCMNTIO;BCMNTIO;\??\c:\progra~1\CheckIt\DIAGNO~1\BCMNTIO.sys [2006-04-02 3744]
R2 LiveUpdate Notice;LiveUpdate Notice;"c:\program files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [2008-02-18 149352]
R2 MAPMEM;MAPMEM;\??\c:\progra~1\CheckIt\DIAGNO~1\MAPMEM.sys [2006-04-02 3904]
R3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;c:\windows\system32\Drivers\BrSerIf.sys [2004-06-12 51712]
R3 BrUsbSer;Brother MFC USB Serial WDM Driver;c:\windows\system32\Drivers\BrUsbSer.sys [2004-01-10 11648]
R3 Cap713x;Philips Cap713x Video Capture;c:\windows\system32\DRIVERS\Cap713x.sys [2006-03-28 686080]
R3 PCAlertDriver;PCAlertDriver;\??\c:\program files\MSI\PC Alert 4\NTGLM7X.sys [2006-03-31 21728]
S3 COH_Mon;COH_Mon;\??\c:\windows\system32\Drivers\COH_Mon.sys [2008-01-12 23888]
S3 CoolerXPDriver;CoolerXPDriver;\??\c:\program files\MSI\PC Alert 4\NTCooler.sys [2006-03-31 15345]

*Newly Created Service* - COMHOST
*Newly Created Service* - FLASHSYS
*Newly Created Service* - PROCEXP90
*Newly Created Service* - WEBNTACCESS
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Cmaudio - cmicnfg.cpl
HKLM-Run-1A:Stardock TrayMonitor - (no file)
HKLM-RunServices-1A:Stardock TrayMonitor - (no file)


.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\Carol\Application Data\Mozilla\Firefox\Profiles\hgjvbv5v.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/?p=1152626375
FF -: plugin - c:\documents and settings\Carol\Application Data\Mozilla\Firefox\Profiles\hgjvbv5v.default\extensions\[removed]\plugins\npRACtrl.dll
FF -: plugin - c:\documents and settings\Carol\Application Data\Mozilla\Firefox\Profiles\hgjvbv5v.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07100121.dll
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Acrobat\browser\nppdf32.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\NPcol305.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npcpbrk7.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npRACtrl.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-17 11:08:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-11-17 11:23:13
ComboFix-quarantined-files.txt 2008-11-17 16:23:05

Pre-Run: 81,418,997,760 bytes free
Post-Run: 81,479,880,704 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

213 — E O F — 2008-11-12 08:13:46
TazzyGirl,

I would like to have the autorun restored on the machine. If you could help me with that after this other issue is finished I would appreciate it.


Let me know in your next post if you really want to do this. This does leave a "window" open into your system for malware to enter. Also, the developer of ComboFix has written his program such that if autorun is restored after having run ComboFix, if you should have a problem in the future, Combofix will not be available because it will not run on you computer anymore.

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Tom K, Here is the scan from Kaspersky. I agree with you on not allowing autorun! Thanks for that info! Let me know what I need to do next. I really appreciate your help! Carol ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Tuesday, November 18, 2008 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Tuesday, November 18, 2008 01:54:36 Records in database: 1390598 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ Scan statistics: Files scanned: 206510 Threat name: 22 Infected objects: 35 Suspicious objects: 0 Duration of the scan: 07:04:13 File name / Threat name / Threats count C:\Documents and Settings\Carol\Desktop\SmitfraudFix\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1 C:\Documents and Settings\Carol\Desktop\SmitfraudFix\SmitfraudFix.zip Infected: not-a-virus:RiskTool.Win32.Reboot.f 1 C:\Documents and Settings\Carol\My Documents\LimeWire\Saved\dimonds on my dayam chain.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\Carol\My Documents\LimeWire\Saved\Gucci Mane ft Ludacris - Freaky girl (74 Bpm).mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\Carol\My Documents\LimeWire\Saved\solider boy sexy girl has shaking orgasm during sex.mp3 Infected: Trojan-Downloader.WMA.Wimad.o 1 C:\Documents and Settings\Carol\My Documents\LimeWire\Saved\tpain ft. chris brown- freeze.mp3 Infected: Trojan-Downloader.WMA.GetCodec.n 1 C:\Games\Chicken Invaders 3 Xmas\Chicken.Invaders.3.Christmas.Edition.v3.25.GAME-Lz0\CI3XmasSetup.exe Infected: Trojan-Dropper.Win32.Delf.xo 1 C:\Games\Chicken Invaders 3 Xmas\Chicken.Invaders.3.Christmas.Edition.v3.25.GAME-Lz0\nfoviewer.exe Infected: Trojan-Dropper.Win32.Delf.xo 1 C:\Games\Chicken Invaders 3 Xmas\Chicken.Invaders.3.Christmas.Edition.v3.25.GAME-Lz0.zip Infected: Trojan-Dropper.Win32.Delf.xo 2 C:\Games\Dream Day Wedding 2\Dream Day Wedding - Married in Manhattan.exe Infected: Trojan-Downloader.Win32.Agent.anbf 1 C:\Games\Hidden Expedition Amazon\Hidden Expedition Amazon.exe Infected: Trojan-Downloader.Win32.Agent.ajke 1 C:\Games\Hidden Expedition Everest\Hidden Expedition Everest.exe Infected: Trojan-Downloader.Win32.Agent.adqb 1 C:\Games\Mystery PI The Vegas Heist\MysteryPIVegas.exe Infected: Trojan-Downloader.Win32.Agent.aniy 1 C:\Games\Pat Sajaks Lucky Letters TV Guide Edition\Lucky_Letters_TVG.exe Infected: Trojan-Downloader.Win32.Agent.adpm 1 C:\Program Files\Musicmatch\Common\ComponentMgr\HoldingArea\WebSys\WebSys.mmz Infected: not-a-virus:RiskTool.Win32.Deleter.f 1 C:\Program Files\Musicmatch\Musicmatch Jukebox\WebSys\offline.mmz Infected: not-a-virus:RiskTool.Win32.Deleter.f 1 C:\Program Files\Musicmatch\Musicmatch Update\MMJB\WebSys\offline.mmz Infected: not-a-virus:RiskTool.Win32.Deleter.f 1 C:\Qoobox\Quarantine\C\WINDOWS\cor704836.exe.vir Infected: Trojan-Downloader.Win32.VB.iqv 1 C:\Qoobox\Quarantine\C\WINDOWS\ee3362.exe.vir Infected: Trojan-Downloader.Win32.VB.iqv 1 C:\Qoobox\Quarantine\C\WINDOWS\eo4.exe.vir Infected: Trojan-Downloader.Win32.VB.iqv 1 C:\Qoobox\Quarantine\C\WINDOWS\Fonts\a.zip.vir Infected: Trojan-Downloader.Win32.VB.dck 1 C:\Qoobox\Quarantine\C\WINDOWS\h288.exe.vir Infected: not-a-virus:AdWare.Win32.BHO.dwj 1 C:\Qoobox\Quarantine\C\WINDOWS\h288.exe.vir Infected: Trojan.Win32.Agent.amoy 1 C:\Qoobox\Quarantine\C\WINDOWS\j414.exe.vir Infected: Trojan-Downloader.Win32.VB.iqv 1 C:\Qoobox\Quarantine\C\WINDOWS\lik02.exe.vir Infected: Trojan-Downloader.Win32.VB.iqv 1 C:\Qoobox\Quarantine\C\WINDOWS\ndxq3074.exe.vir Infected: Trojan-Downloader.Win32.Agent.ante 1 C:\Qoobox\Quarantine\C\WINDOWS\tj85.exe.vir Infected: Trojan-Downloader.Win32.VB.iqv 1 C:\WINDOWS\system32\Robo\Themes\44068.exe Infected: not-a-virus:AdWare.Win32.Quick.a 1 C:\WINDOWS\system32\Robo\Themes\44068.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1 C:\WINDOWS\system32\Robo\Themes\44068.exe Infected: not-a-virus:AdWare.Win32.EZula.u 1 C:\WINDOWS\system32\Robo\Themes\44068.exe Infected: not-a-virus:AdWare.Win32.WebRebates.g 1 C:\WINDOWS\system32\Robo\Themes\44068.exe Infected: not-a-virus:AdWare.Win32.WebRebates.b 2 C:\WINDOWS\system32\Robo\Themes\44068.exe Infected: not-a-virus:AdWare.Win32.HelpExpress 1 The selected area was scanned.
TazzyGirl,

You have LimeWire, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005…cles/art053.htm
See Clean/Infected P2P Programs here

I would recommend that you uninstall LimeWire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    File::
    C:\Documents and Settings\Carol\My Documents\LimeWire\Saved\dimonds on my dayam chain.mp3
    C:\Documents and Settings\Carol\My Documents\LimeWire\Saved\Gucci Mane ft Ludacris - Freaky girl (74 Bpm).mp3
    C:\Documents and Settings\Carol\My Documents\LimeWire\Saved\solider boy sexy girl has shaking orgasm during sex.mp3
    C:\Documents and Settings\Carol\My Documents\LimeWire\Saved\tpain ft. chris brown- freeze.mp3
    C:\Games\Dream Day Wedding 2\Dream Day Wedding - Married in Manhattan.exe
    C:\Games\Hidden Expedition Amazon\Hidden Expedition Amazon.exe
    C:\Games\Hidden Expedition Everest\Hidden Expedition Everest.exe
    C:\Games\Mystery PI The Vegas Heist\MysteryPIVegas.exe
    C:\Games\Pat Sajaks Lucky Letters TV Guide Edition\Lucky_Letters_TVG.exe
    C:\WINDOWS\system32\Robo\Themes\44068.exe
    
    Folder::
    C:\Games\Chicken Invaders 3 Xmas
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)

And lastly, please post a new hijackThis log.
Here's the results after dragging that file into ComboFix…I'm on my way for the next one….

ComboFix 08-11-18.03 - Carol 2008-11-18 22:18:01.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.124 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Carol\Desktop\CFScript.txt
* Created a new restore point

FILE ::
c:\documents and settings\Carol\My Documents\LimeWire\Saved\dimonds on my dayam chain.mp3
c:\documents and settings\Carol\My Documents\LimeWire\Saved\Gucci Mane ft Ludacris - Freaky girl (74 Bpm).mp3
c:\documents and settings\Carol\My Documents\LimeWire\Saved\solider boy sexy girl has shaking orgasm during sex.mp3
c:\documents and settings\Carol\My Documents\LimeWire\Saved\tpain ft. chris brown- freeze.mp3
c:\games\Dream Day Wedding 2\Dream Day Wedding - Married in Manhattan.exe
c:\games\Hidden Expedition Amazon\Hidden Expedition Amazon.exe
c:\games\Hidden Expedition Everest\Hidden Expedition Everest.exe
c:\games\Mystery PI The Vegas Heist\MysteryPIVegas.exe
c:\games\Pat Sajaks Lucky Letters TV Guide Edition\Lucky_Letters_TVG.exe
c:\windows\system32\Robo\Themes\44068.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Carol\My Documents\LimeWire\Saved\Gucci Mane ft Ludacris - Freaky girl (74 Bpm).mp3
c:\documents and settings\Carol\My Documents\LimeWire\Saved\solider boy sexy girl has shaking orgasm during sex.mp3
c:\documents and settings\Carol\My Documents\LimeWire\Saved\tpain ft. chris brown- freeze.mp3
c:\games\Chicken Invaders 3 Xmas
c:\games\Chicken Invaders 3 Xmas\bass.dll
c:\games\Chicken Invaders 3 Xmas\Chicken.Invaders.3.Christmas.Edition.v3.25.GAME-Lz0.zip
c:\games\Chicken Invaders 3 Xmas\Chicken.Invaders.3.Christmas.Edition.v3.25.GAME-Lz0\.message
c:\games\Chicken Invaders 3 Xmas\Chicken.Invaders.3.Christmas.Edition.v3.25.GAME-Lz0\CI3XmasSetup.exe
c:\games\Chicken Invaders 3 Xmas\Chicken.Invaders.3.Christmas.Edition.v3.25.GAME-Lz0\Crack\CI3Xmas.exe
c:\games\Chicken Invaders 3 Xmas\Chicken.Invaders.3.Christmas.Edition.v3.25.GAME-Lz0\file_id.diz
c:\games\Chicken Invaders 3 Xmas\Chicken.Invaders.3.Christmas.Edition.v3.25.GAME-Lz0\linedraw.ttf
c:\games\Chicken Invaders 3 Xmas\Chicken.Invaders.3.Christmas.Edition.v3.25.GAME-Lz0\Lz0.nfo
c:\games\Chicken Invaders 3 Xmas\Chicken.Invaders.3.Christmas.Edition.v3.25.GAME-Lz0\nfoviewer.exe
c:\games\Chicken Invaders 3 Xmas\CI3Xmas 20070408 113.250.bmp
c:\games\Chicken Invaders 3 Xmas\CI3Xmas 20070408 119.393.bmp
c:\games\Chicken Invaders 3 Xmas\CI3Xmas 20070414 94.088.bmp
c:\games\Chicken Invaders 3 Xmas\CI3Xmas 20070415 5303.657.bmp
c:\games\Chicken Invaders 3 Xmas\CI3Xmas.cfg
c:\games\Chicken Invaders 3 Xmas\CI3Xmas.dat
c:\games\Chicken Invaders 3 Xmas\CI3Xmas.exe
c:\games\Chicken Invaders 3 Xmas\CI3Xmas.hst
c:\games\Chicken Invaders 3 Xmas\CI3Xmas.log
c:\games\Chicken Invaders 3 Xmas\CI3Xmas.pro
c:\games\Chicken Invaders 3 Xmas\CI3Xmas.pro.P48a71b3f
c:\games\Chicken Invaders 3 Xmas\CI3Xmas.pro.P4d401415
c:\games\Chicken Invaders 3 Xmas\CI3Xmas.pro.Pcab9ff7a
c:\games\Chicken Invaders 3 Xmas\CI3Xmas.pro.W48a71b3f
c:\games\Chicken Invaders 3 Xmas\CI3Xmas.pro.W4d401415
c:\games\Chicken Invaders 3 Xmas\CI3Xmas.pro.W550c0b1e
c:\games\Chicken Invaders 3 Xmas\CI3Xmas.pro.Wcab9ff7a
c:\games\Chicken Invaders 3 Xmas\CI3Xmasd.exe
c:\games\Chicken Invaders 3 Xmas\crash.CI3Xmas.net
c:\games\Chicken Invaders 3 Xmas\iastyle.css
c:\games\Chicken Invaders 3 Xmas\images\bg-top.gif
c:\games\Chicken Invaders 3 Xmas\images\bg.gif
c:\games\Chicken Invaders 3 Xmas\readme.htm
c:\games\Chicken Invaders 3 Xmas\Thumbs.db
c:\games\Chicken Invaders 3 Xmas\Uninstall.exe
c:\games\Dream Day Wedding 2\Dream Day Wedding - Married in Manhattan.exe
c:\games\Hidden Expedition Amazon\Hidden Expedition Amazon.exe
c:\games\Hidden Expedition Everest\Hidden Expedition Everest.exe
c:\games\Mystery PI The Vegas Heist\MysteryPIVegas.exe
c:\games\Pat Sajaks Lucky Letters TV Guide Edition\Lucky_Letters_TVG.exe
c:\windows\system32\Robo\Themes\44068.exe

.
((((((((((((((((((((((((( Files Created from 2008-10-19 to 2008-11-19 )))))))))))))))))))))))))))))))
.

2008-11-17 15:30 . 2008-11-17 15:30 d——– c:\windows\system32\N360_BACKUP
2008-11-10 07:34 . 2008-11-10 07:34 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-10 07:34 . 2008-11-10 07:34 d——– c:\documents and settings\Carol\Application Data\Malwarebytes
2008-11-10 07:34 . 2008-11-10 07:34 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-10 07:34 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-10 07:34 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-09 12:35 . 2008-11-09 12:35 d——– c:\documents and settings\Carol\Application Data\Blackberry Desktop
2008-11-01 16:19 . 2008-11-01 16:19 430,080 –a—— c:\windows\system32\BSTIEPrintCtl1.dll
2008-10-25 20:49 . 2008-10-25 20:49 d——– c:\documents and settings\All Users\Application Data\MysteryChronicles
2008-10-24 20:35 . 2008-10-24 20:40 d——– c:\documents and settings\Carol\Application Data\W Photo Studio
2008-10-24 20:34 . 2008-10-24 20:34 d——– c:\program files\Walgreens
2008-10-24 20:34 . 2008-10-24 20:34 d——– c:\documents and settings\Carol\Application Data\Walgreens
2008-10-24 20:34 . 2008-10-24 20:34 d——– c:\documents and settings\All Users\Application Data\Walgreens
2008-10-24 20:24 . 2008-10-24 20:33 d——– c:\documents and settings\Carol\Application Data\W Photo Studio Viewer

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 03:25 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-11-17 16:43 ——— d—–w c:\documents and settings\Carol\Application Data\LimeWire
2008-11-10 05:21 ——— d—–w c:\documents and settings\Carol\Application Data\Move Networks
2008-11-10 05:11 ——— d—–w c:\program files\Norton 360
2008-11-09 17:27 ——— d—–w c:\program files\Webshots
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-14 23:14 ——— d—–w c:\documents and settings\Carol\Application Data\Roxio
2008-10-12 00:48 ——— d—–w c:\program files\LimeWire
2008-10-07 00:24 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-06 07:00 ——— d—–w c:\program files\MSXML 6.0
2008-10-05 18:14 ——— d—–w c:\documents and settings\NetworkService\Application Data\Roxio
2008-10-05 18:08 ——— d—–w c:\documents and settings\Carol\Application Data\Research In Motion
2008-10-05 18:03 ——— d—–w c:\documents and settings\All Users\Application Data\Roxio
2008-10-05 17:58 ——— d—–w c:\program files\Common Files\Sonic Shared
2008-10-05 17:58 ——— d—–w c:\documents and settings\All Users\Application Data\Sonic
2008-10-05 17:57 ——— d—–w c:\program files\Roxio
2008-10-05 17:55 ——— d—–w c:\program files\Common Files\Roxio Shared
2008-10-05 17:41 ——— d—–w c:\program files\Common Files\Research In Motion
2008-10-05 17:40 ——— d—–w c:\program files\Research In Motion
2008-09-27 00:35 ——— d—–w c:\documents and settings\Carol\Application Data\ScanSoft
2008-02-28 18:30 8,784 —-a-w c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2008-02-28 18:33 245,408 —-a-w c:\program files\mozilla firefox\plugins\unicows.dll
.

((((((((((((((((((((((((((((( snapshot@2008-11-17_11.22.18.86 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-19 02:10:48 94,920 —-a-w c:\windows\system32\cdm.dll
+ 2008-10-16 19:09:44 92,696 —-a-w c:\windows\system32\cdm.dll
- 2008-07-19 02:10:48 94,920 -c–a-w c:\windows\system32\dllcache\cdm.dll
+ 2008-10-16 19:09:44 92,696 -c–a-w c:\windows\system32\dllcache\cdm.dll
- 2008-07-19 02:09:44 563,912 -c–a-w c:\windows\system32\dllcache\wuapi.dll
+ 2008-10-16 19:12:20 561,688 -c–a-w c:\windows\system32\dllcache\wuapi.dll
- 2008-07-19 02:10:42 53,448 -c–a-w c:\windows\system32\dllcache\wuauclt.exe
+ 2008-10-16 19:09:44 51,224 -c–a-w c:\windows\system32\dllcache\wuauclt.exe
- 2008-07-19 02:09:42 1,811,656 -c–a-w c:\windows\system32\dllcache\wuaueng.dll
+ 2008-10-16 19:13:40 1,809,944 -c–a-w c:\windows\system32\dllcache\wuaueng.dll
- 2008-07-19 02:09:46 325,832 -c–a-w c:\windows\system32\dllcache\wucltui.dll
+ 2008-10-16 19:12:22 323,608 -c–a-w c:\windows\system32\dllcache\wucltui.dll
- 2008-07-19 02:10:20 36,552 -c–a-w c:\windows\system32\dllcache\wups.dll
+ 2008-10-16 19:08:58 34,328 -c–a-w c:\windows\system32\dllcache\wups.dll
- 2008-07-19 02:09:44 205,000 -c–a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-10-16 19:13:40 202,776 -c–a-w c:\windows\system32\dllcache\wuweb.dll
- 2008-07-19 02:07:34 270,880 —-a-w c:\windows\system32\mucltui.dll
+ 2008-10-16 19:06:48 268,648 —-a-w c:\windows\system32\mucltui.dll
- 2008-07-19 02:07:32 210,976 —-a-w c:\windows\system32\muweb.dll
+ 2008-10-16 19:06:48 208,744 —-a-w c:\windows\system32\muweb.dll
+ 2008-10-16 19:08:58 34,328 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2008-10-16 19:09:44 43,544 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
- 2008-07-19 02:09:44 563,912 —-a-w c:\windows\system32\wuapi.dll
+ 2008-10-16 19:12:20 561,688 —-a-w c:\windows\system32\wuapi.dll
- 2008-07-19 02:10:42 53,448 —-a-w c:\windows\system32\wuauclt.exe
+ 2008-10-16 19:09:44 51,224 —-a-w c:\windows\system32\wuauclt.exe
- 2008-07-19 02:09:42 1,811,656 —-a-w c:\windows\system32\wuaueng.dll
+ 2008-10-16 19:13:40 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
- 2008-07-19 02:09:46 325,832 —-a-w c:\windows\system32\wucltui.dll
+ 2008-10-16 19:12:22 323,608 —-a-w c:\windows\system32\wucltui.dll
- 2008-07-19 02:10:20 36,552 —-a-w c:\windows\system32\wups.dll
+ 2008-10-16 19:08:58 34,328 —-a-w c:\windows\system32\wups.dll
- 2008-07-19 02:10:40 45,768 —-a-w c:\windows\system32\wups2.dll
+ 2008-10-16 19:09:44 43,544 —-a-w c:\windows\system32\wups2.dll
- 2008-07-19 02:09:44 205,000 —-a-w c:\windows\system32\wuweb.dll
+ 2008-10-16 19:13:40 202,776 —-a-w c:\windows\system32\wuweb.dll
+ 2008-11-19 03:25:03 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_75c.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@="{4433A54A-1AC8-432F-90FC-85F045CF383C}"
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-10-31 12:24 576352 –a—— c:\program files\Common Files\Symantec Shared\Backup\buShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@="{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}"
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-10-31 12:24 576352 –a—— c:\program files\Common Files\Symantec Shared\Backup\buShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@="{476D0EA3-80F9-48B5-B70B-05E677C9C148}"
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-10-31 12:24 576352 –a—— c:\program files\Common Files\Symantec Shared\Backup\buShell.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"="c:\program files\TGTSoft\StyleXP\StyleXP.exe" [2005-02-04 1159168]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KEMailKb"="c:\progra~1\KEMailKb\KEMailKb.EXE" [2002-12-31 253952]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"RemoteControl"="c:\windows\system32\rmctrl.exe" [2004-01-26 32768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
"Say the Time"="c:\program files\Say the Time\SayTime.exe" [2004-01-22 806912]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"SetDefPrt"="c:\program files\Brother\Brmfl04b\BrStDvPt.exe" [2004-05-25 49152]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 851968]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~2\mimboot.exe" [2006-01-19 11776]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-09-24 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]
"LiveMonitor"="c:\program files\MSI\Live Update 3\LMonitor.exe" [2006-09-05 497152]
"SansaDispatch"="c:\program files\SanDisk\Sansa Updater\SansaDispatch.exe" [2007-10-22 75584]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"nForce Tray Options"="sstray.exe" [2003-12-17 c:\windows\system32\sstray.exe]
"LTMSG"="LTMSG.exe" [2003-07-14 c:\windows\ltmsg.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 c:\windows\LOGI_MWX.EXE]
"nwiz"="nwiz.exe" [2006-03-09 c:\windows\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-12-14 c:\windows\soundman.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-11-29 c:\windows\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]

c:\documents and settings\Carol\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-08-21 147456]
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-04-19 64864]
Webshots.lnk - c:\program files\Webshots\WebshotsTray.exe [2006-03-28 196608]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-03-27 25214]
Event Planner Reminders Tray Icon.lnk - c:\program files\Sierra\Planner\Plnrnote.exe [2006-03-28 184320]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-09-24 282624]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-09-24 73728]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-03-27 789008]
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-04-19 64864]
PC Alert 4.lnk - c:\program files\MSI\PC Alert 4\PCAlert4.exe [2006-03-31 536576]
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2006-04-04 819200]
TV Remote Control.lnk - c:\program files\MSI\TV@Anywhere Utilities\P3XRCtl.exe [2006-03-28 94208]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\\Program Files\\TGTSoft\\StyleXP\\CurrentLogon.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-01-09 11:30 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIV3"= DIVXc32.dll
"vidc.DIV4"= DIVXc32f.dll
"vidc.ffds"= ffdshow.ax

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

R2 BCMNTIO;BCMNTIO;\??\c:\progra~1\CheckIt\DIAGNO~1\BCMNTIO.sys [2006-04-02 3744]
R2 LiveUpdate Notice;LiveUpdate Notice;"c:\program files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [2008-02-18 149352]
R2 MAPMEM;MAPMEM;\??\c:\progra~1\CheckIt\DIAGNO~1\MAPMEM.sys [2006-04-02 3904]
R3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;c:\windows\system32\Drivers\BrSerIf.sys [2004-06-12 51712]
R3 BrUsbSer;Brother MFC USB Serial WDM Driver;c:\windows\system32\Drivers\BrUsbSer.sys [2004-01-10 11648]
R3 Cap713x;Philips Cap713x Video Capture;c:\windows\system32\DRIVERS\Cap713x.sys [2006-03-28 686080]
R3 PCAlertDriver;PCAlertDriver;\??\c:\program files\MSI\PC Alert 4\NTGLM7X.sys [2006-03-31 21728]
S3 COH_Mon;COH_Mon;\??\c:\windows\system32\Drivers\COH_Mon.sys [2008-01-12 23888]
S3 CoolerXPDriver;CoolerXPDriver;\??\c:\program files\MSI\PC Alert 4\NTCooler.sys [2006-03-31 15345]

*Newly Created Service* - COMHOST
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-18 22:28:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\ccProxy.exe
c:\program files\Common Files\Symantec Shared\VAScanner\comHost.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\brss01a.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\windows\system32\Brmfrmps.exe
c:\windows\system32\dllhost.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\progra~1\MUSICM~1\MUSICM~2\MMDiag.exe
c:\program files\Musicmatch\Musicmatch Jukebox\mim.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
.
**************************************************************************
.
Completion time: 2008-11-18 22:53:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-19 03:52:46
ComboFix2.txt 2008-11-17 16:23:15

Pre-Run: 81,531,834,368 bytes free
Post-Run: 81,608,982,528 bytes free

288 — E O F — 2008-11-12 08:13:46
Here's the lop results…now on to Hijack this…


——————–\\ Lop S&D 4.2.4-9c XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Athlon™ XP )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Carol ( Administrator )
BOOT : Normal boot
Antivirus : Norton 360 2007 (Not Activated)
Firewall : Norton 360 2007 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:111 Go (Free:76 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
F:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( Wed 11/19/2008| 7:13 )

——————–\\ Listing folders in APPLIC~1

[10/06/2008|07:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[11/23/2007|08:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[03/27/2006|07:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe Systems
[08/13/2008|01:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL
[07/09/2007|10:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL Downloads
[07/09/2007|10:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL OCP
[02/24/2007|12:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[06/13/2008|11:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Astar Games
[04/23/2006|08:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Authentium
[04/04/2006|05:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Brother
[11/30/2007|07:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Christmasville
[03/28/2006|12:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ CyberLink
[03/28/2006|12:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ DVD Shrink
[04/06/2008|12:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ EscapeTheMuseum
[06/01/2008|06:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Flood Light Games
[05/19/2007|12:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ FloodLightGames
[08/08/2007|12:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ GameBlend
[11/26/2006|10:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Genimo
[05/01/2008|03:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Gogii
[06/15/2008|05:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Gogii Games
[03/01/2007|09:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HipSoft
[12/25/2006|08:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HP
[03/28/2006|12:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield
[04/04/2007|08:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InterAction studios
[03/12/2008|07:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ JollyBear
[12/24/2007|05:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Keepsoft
[02/26/2008|05:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ LogiShrd
[03/27/2008|05:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Logitech
[11/10/2008|07:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[08/06/2008|06:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[04/01/2008|10:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ MonteCristo
[06/19/2006|08:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ MSScanAppDataDir
[07/13/2008|11:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ MumboJumbo
[10/25/2008|08:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ MysteryChronicles
[11/09/2007|03:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ NeptunesAdve
[03/28/2006|01:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ nView_Profiles
[04/05/2006|03:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Oberon Media
[09/09/2007|11:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PlayFirst
[04/13/2008|09:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Playtonium Games
[11/22/2007|10:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Reflexive
[10/05/2008|01:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Roxio
[11/01/2006|08:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sandlot Games
[04/04/2006|05:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ ScanSoft
[03/28/2006|12:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sierra
[10/05/2008|12:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sonic
[06/06/2008|06:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SpinTop Games
[09/01/2008|06:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Symantec
[08/12/2007|04:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[08/18/2008|07:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TheRace_dev
[05/04/2006|09:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Trymedia
[08/13/2008|01:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Viewpoint
[10/24/2008|08:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Walgreens
[03/27/2006|04:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[05/20/2008|09:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo!
[08/09/2007|11:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Zylom

[03/29/2006|03:27] C:\DOCUME~1\Carol\APPLIC~1\ .ABC
[08/18/2007|10:26] C:\DOCUME~1\Carol\APPLIC~1\ 7Wonders
[11/25/2007|05:26] C:\DOCUME~1\Carol\APPLIC~1\ Abra Academy2
[03/23/2008|06:56] C:\DOCUME~1\Carol\APPLIC~1\ Adobe
[05/21/2008|03:52] C:\DOCUME~1\Carol\APPLIC~1\ AdobeUM
[07/09/2007|10:17] C:\DOCUME~1\Carol\APPLIC~1\ Aim
[01/27/2007|09:38] C:\DOCUME~1\Carol\APPLIC~1\ Apple Computer
[03/29/2006|02:02] C:\DOCUME~1\Carol\APPLIC~1\ Atari
[01/22/2008|07:15] C:\DOCUME~1\Carol\APPLIC~1\ Big Fish Games
[11/09/2008|12:35] C:\DOCUME~1\Carol\APPLIC~1\ Blackberry Desktop
[09/28/2007|09:25] C:\DOCUME~1\Carol\APPLIC~1\ Blippy Games
[01/27/2008|11:06] C:\DOCUME~1\Carol\APPLIC~1\ BloodTies
[04/04/2006|05:21] C:\DOCUME~1\Carol\APPLIC~1\ Brother
[09/20/2007|02:28] C:\DOCUME~1\Carol\APPLIC~1\ Chessmaster Challenge
[03/28/2006|12:48] C:\DOCUME~1\Carol\APPLIC~1\ Corel
[06/01/2008|06:26] C:\DOCUME~1\Carol\APPLIC~1\ Flood Light Games
[05/19/2007|12:23] C:\DOCUME~1\Carol\APPLIC~1\ FloodLightGames
[10/07/2007|12:09] C:\DOCUME~1\Carol\APPLIC~1\ ForgottenRiddles
[02/19/2008|06:57] C:\DOCUME~1\Carol\APPLIC~1\ funkitron
[05/22/2008|12:37] C:\DOCUME~1\Carol\APPLIC~1\ Gaijin Ent
[08/08/2007|12:29] C:\DOCUME~1\Carol\APPLIC~1\ GameBlend
[11/26/2006|10:01] C:\DOCUME~1\Carol\APPLIC~1\ Genimo
[06/15/2008|05:40] C:\DOCUME~1\Carol\APPLIC~1\ Gogii Games
[04/16/2006|05:14] C:\DOCUME~1\Carol\APPLIC~1\ Help
[12/25/2006|08:19] C:\DOCUME~1\Carol\APPLIC~1\ HP
[03/27/2006|08:18] C:\DOCUME~1\Carol\APPLIC~1\ Identities
[12/24/2007|02:32] C:\DOCUME~1\Carol\APPLIC~1\ InstallShield
[03/02/2008|07:16] C:\DOCUME~1\Carol\APPLIC~1\ iWin
[02/10/2008|07:03] C:\DOCUME~1\Carol\APPLIC~1\ Keepsoft
[03/29/2006|01:58] C:\DOCUME~1\Carol\APPLIC~1\ Leadertech
[10/14/2007|05:54] C:\DOCUME~1\Carol\APPLIC~1\ Legends of pirates
[11/18/2008|10:40] C:\DOCUME~1\Carol\APPLIC~1\ LimeWire
[03/27/2008|05:34] C:\DOCUME~1\Carol\APPLIC~1\ Logitech
[03/28/2006|01:11] C:\DOCUME~1\Carol\APPLIC~1\ Macromedia
[04/16/2007|07:20] C:\DOCUME~1\Carol\APPLIC~1\ Magic Academy
[11/10/2008|07:34] C:\DOCUME~1\Carol\APPLIC~1\ Malwarebytes
[09/13/2008|01:58] C:\DOCUME~1\Carol\APPLIC~1\ Microsoft
[11/10/2008|12:21] C:\DOCUME~1\Carol\APPLIC~1\ Move Networks
[08/26/2008|06:46] C:\DOCUME~1\Carol\APPLIC~1\ Mozilla
[04/09/2006|08:37] C:\DOCUME~1\Carol\APPLIC~1\ Musicmatch
[03/07/2008|08:12] C:\DOCUME~1\Carol\APPLIC~1\ My Games
[07/13/2007|12:33] C:\DOCUME~1\Carol\APPLIC~1\ MySpace
[07/01/2008|06:45] C:\DOCUME~1\Carol\APPLIC~1\ MysteryStudio
[08/21/2007|06:48] C:\DOCUME~1\Carol\APPLIC~1\ Mysteryville2
[09/09/2007|11:55] C:\DOCUME~1\Carol\APPLIC~1\ PlayFirst
[12/24/2007|02:23] C:\DOCUME~1\Carol\APPLIC~1\ Real
[10/05/2008|01:08] C:\DOCUME~1\Carol\APPLIC~1\ Research In Motion
[10/14/2008|06:14] C:\DOCUME~1\Carol\APPLIC~1\ Roxio
[09/26/2008|07:35] C:\DOCUME~1\Carol\APPLIC~1\ ScanSoft
[03/28/2008|07:16] C:\DOCUME~1\Carol\APPLIC~1\ SprillBermudeEng
[04/01/2006|07:05] C:\DOCUME~1\Carol\APPLIC~1\ Sun
[08/07/2008|05:12] C:\DOCUME~1\Carol\APPLIC~1\ Symantec
[07/31/2006|02:42] C:\DOCUME~1\Carol\APPLIC~1\ The Labyrinth Plus! Edition
[08/13/2008|02:56] C:\DOCUME~1\Carol\APPLIC~1\ Uniblue
[07/10/2007|12:21] C:\DOCUME~1\Carol\APPLIC~1\ Viewpoint
[10/24/2008|08:40] C:\DOCUME~1\Carol\APPLIC~1\ W Photo Studio
[10/24/2008|08:33] C:\DOCUME~1\Carol\APPLIC~1\ W Photo Studio Viewer
[10/24/2008|08:34] C:\DOCUME~1\Carol\APPLIC~1\ Walgreens
[06/24/2008|10:02] C:\DOCUME~1\Carol\APPLIC~1\ Yahoo!

[03/26/2006|08:59] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft

[10/21/2007|08:36] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft

[02/24/2007|12:41] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft
[10/05/2008|01:14] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Roxio

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[11/18/2008 10:25 PM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 07:00 AM][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[03/31/2006|10:40] C:\Program Files\ Acesoft
[03/27/2006|07:52] C:\Program Files\ Adobe
[03/27/2006|07:47] C:\Program Files\ Ahead
[07/09/2007|10:17] C:\Program Files\ AIM95
[08/13/2008|01:31] C:\Program Files\ BFG
[04/01/2006|01:41] C:\Program Files\ Bin to ISO
[04/04/2006|05:13] C:\Program Files\ Brother
[04/02/2006|11:54] C:\Program Files\ CheckIt
[04/29/2007|10:14] C:\Program Files\ Chicken Invaders 3
[03/28/2006|07:33] C:\Program Files\ C-Media 3D Audio
[11/18/2008|10:21] C:\Program Files\ Common Files
[03/26/2006|08:55] C:\Program Files\ ComPlus Applications
[03/28/2006|12:48] C:\Program Files\ Corel
[04/23/2006|08:52] C:\Program Files\ Cox
[03/28/2006|06:32] C:\Program Files\ cpu-z-132
[03/27/2006|05:55] C:\Program Files\ Customizer XP
[03/28/2006|12:12] C:\Program Files\ CyberLink
[03/28/2006|12:13] C:\Program Files\ DVD Decrypter
[03/28/2006|12:14] C:\Program Files\ DVD Shrink
[12/25/2006|08:02] C:\Program Files\ Hewlett-Packard
[11/10/2008|03:56] C:\Program Files\ Hijackthis
[12/25/2006|07:59] C:\Program Files\ HP
[03/27/2008|05:25] C:\Program Files\ InstallShield Installation Information
[05/02/2007|03:20] C:\Program Files\ InterActual
[10/15/2008|02:10] C:\Program Files\ Internet Explorer
[07/14/2008|05:17] C:\Program Files\ Java
[03/27/2006|05:50] C:\Program Files\ KEMailKb
[02/15/2007|03:26] C:\Program Files\ Learning Essentials
[10/11/2008|07:48] C:\Program Files\ LimeWire
[03/27/2008|05:25] C:\Program Files\ Logitech
[11/10/2008|07:34] C:\Program Files\ Malwarebytes' Anti-Malware
[08/14/2008|02:14] C:\Program Files\ Messenger
[03/27/2006|10:25] C:\Program Files\ Microsoft ActiveSync
[05/09/2007|02:22] C:\Program Files\ Microsoft CAPICOM 2.1.0.2
[03/26/2006|08:59] C:\Program Files\ microsoft frontpage
[03/28/2006|12:16] C:\Program Files\ Microsoft Location Finder
[03/28/2006|12:14] C:\Program Files\ Microsoft Office
[03/28/2006|12:40] C:\Program Files\ Microsoft Plus!
[03/28/2006|12:40] C:\Program Files\ Microsoft Plus! Digital Media Edition
[03/28/2006|12:15] C:\Program Files\ Microsoft Streets & Trips
[03/27/2006|11:20] C:\Program Files\ Microsoft Student
[03/27/2006|10:25] C:\Program Files\ Microsoft Visual Studio
[03/28/2006|02:36] C:\Program Files\ Microsoft Works
[03/27/2006|10:24] C:\Program Files\ Microsoft.NET
[03/27/2006|06:04] C:\Program Files\ Milsoft
[03/26/2006|08:56] C:\Program Files\ Movie Maker
[11/19/2008|07:02] C:\Program Files\ Mozilla Firefox
[01/28/2007|01:16] C:\Program Files\ MSI
[03/26/2006|08:55] C:\Program Files\ MSN
[03/26/2006|08:55] C:\Program Files\ MSN Gaming Zone
[01/02/2008|07:59] C:\Program Files\ MSN Messenger
[10/14/2006|02:01] C:\Program Files\ MSXML 4.0
[10/06/2008|02:00] C:\Program Files\ MSXML 6.0
[04/09/2006|08:38] C:\Program Files\ Musicmatch
[07/28/2007|09:47] C:\Program Files\ MySpace
[03/26/2006|08:57] C:\Program Files\ NetMeeting
[11/10/2008|12:11] C:\Program Files\ Norton 360
[12/16/2006|08:08] C:\Program Files\ NStorm
[03/28/2006|01:13] C:\Program Files\ NVIDIA
[06/14/2007|02:06] C:\Program Files\ Outlook Express
[03/28/2006|08:59] C:\Program Files\ Philips Semiconductors
[08/18/2007|09:58] C:\Program Files\ Punch! Pro - Platinum
[07/09/2008|01:39] C:\Program Files\ Quicken Lawyer 2003 Personal
[01/27/2007|09:37] C:\Program Files\ QuickTime
[03/28/2006|02:51] C:\Program Files\ Realtek AC97
[10/30/2006|08:21] C:\Program Files\ ReflexiveArcade
[10/05/2008|12:40] C:\Program Files\ Research In Motion
[10/05/2008|12:57] C:\Program Files\ Roxio
[12/24/2007|02:33] C:\Program Files\ SanDisk
[03/28/2006|01:18] C:\Program Files\ Say the Time
[04/04/2006|05:06] C:\Program Files\ ScanSoft
[01/21/2007|12:05] C:\Program Files\ Setup Files
[03/28/2006|12:56] C:\Program Files\ Sierra
[03/27/2006|07:46] C:\Program Files\ SiSoftware
[04/28/2006|06:04] C:\Program Files\ Smart Diary
[09/01/2008|06:57] C:\Program Files\ Symantec
[03/27/2006|06:06] C:\Program Files\ TGTSoft
[03/27/2006|08:18] C:\Program Files\ Uninstall Information
[03/28/2006|12:11] C:\Program Files\ VideoLAN
[03/28/2006|12:13] C:\Program Files\ vso
[10/24/2008|08:34] C:\Program Files\ Walgreens
[11/09/2008|12:27] C:\Program Files\ Webshots
[10/21/2007|07:11] C:\Program Files\ Windows Media Connect 2
[10/21/2007|07:11] C:\Program Files\ Windows Media Player
[03/26/2006|08:55] C:\Program Files\ Windows NT
[08/06/2008|08:02] C:\Program Files\ Windows Sidebar
[03/26/2006|08:57] C:\Program Files\ WindowsUpdate
[03/27/2006|07:50] C:\Program Files\ WinRAR
[03/26/2006|08:59] C:\Program Files\ xerox
[04/01/2006|02:50] C:\Program Files\ XP Codec Pack
[03/28/2006|12:02] C:\Program Files\ XviD
[07/13/2008|06:08] C:\Program Files\ Yahoo!

——————–\\ Listing Folders in C:\Program Files\Common Files

[05/18/2008|10:23] C:\Program Files\Common Files\ Adobe
[03/27/2006|07:54] C:\Program Files\Common Files\ Adobe Systems Shared
[03/27/2006|07:47] C:\Program Files\Common Files\ Ahead
[04/23/2006|08:46] C:\Program Files\Common Files\ Authentium Shared
[03/28/2006|12:49] C:\Program Files\Common Files\ Corel
[03/27/2006|10:25] C:\Program Files\Common Files\ DESIGNER
[10/28/2006|07:49] C:\Program Files\Common Files\ EasyInfo
[03/28/2006|12:58] C:\Program Files\Common Files\ HCS Common
[12/25/2006|08:03] C:\Program Files\Common Files\ HP
[04/04/2006|05:13] C:\Program Files\Common Files\ InstallShield
[03/28/2006|02:00] C:\Program Files\Common Files\ Java
[03/27/2006|10:26] C:\Program Files\Common Files\ L&H
[03/27/2008|05:26] C:\Program Files\Common Files\ Logishrd
[03/27/2006|05:36] C:\Program Files\Common Files\ Logitech
[08/09/2008|12:20] C:\Program Files\Common Files\ Microsoft Shared
[03/26/2006|08:57] C:\Program Files\Common Files\ MSSoap
[04/08/2006|05:18] C:\Program Files\Common Files\ Nullsoft
[03/26/2006|03:26] C:\Program Files\Common Files\ ODBC
[10/05/2008|12:41] C:\Program Files\Common Files\ Research In Motion
[10/05/2008|12:55] C:\Program Files\Common Files\ Roxio Shared
[04/04/2006|05:06] C:\Program Files\Common Files\ ScanSoft Shared
[03/26/2006|08:57] C:\Program Files\Common Files\ Services
[10/05/2008|12:58] C:\Program Files\Common Files\ Sonic Shared
[03/26/2006|03:26] C:\Program Files\Common Files\ SpeechEngines
[11/18/2008|10:25] C:\Program Files\Common Files\ Symantec Shared
[06/14/2007|02:06] C:\Program Files\Common Files\ System

——————–\\ Process

( 62 Processes )

… OK !

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-19 07:15:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

——————–\\ Cracks & Keygens ..

C:\DOCUME~1\Carol\Desktop\My software\7000 Serials cracks.txt
C:\DOCUME~1\Carol\Desktop\My software\alchemy.deluxe.1.2.keygen-tsrh.exe
C:\DOCUME~1\Carol\Desktop\My software\CRACKS & SERIALS - Hundreds Of Serial Numbers And Registration Codes (Kai Flaming Pear Eye Candy Adobe Extensis Plugin Xenofex Paintshop Psp Gif Boris Fx.txt
C:\DOCUME~1\Carol\Favorites\Cracks Serials
C:\DOCUME~1\Carol\Favorites\Cracks Serials\Absolutist - Archibaldgames - AxySoft - Silver Creek - Tibosoftware - Small Games v.3.0.url
C:\DOCUME~1\Carol\My Documents\Temp\2 Symantec All in one 2005\NIS_RETL\KEYGEN
C:\DOCUME~1\Carol\My Documents\Temp\2 Symantec All in one 2005\NIS_RETL\KEYGEN\KGNIS.EXE
C:\DOCUME~1\Carol\My Documents\Temp\2 Symantec All in one 2005\NSWP2005\KEYGEN
C:\DOCUME~1\Carol\My Documents\Temp\2 Symantec All in one 2005\NSWP2005\KEYGEN\KEYGEN.EXE
C:\DOCUME~1\Carol\My Documents\Temp\INTERNET HISTORY ERASER v5.6\keygen.exe


[F:6][D:0]-> C:\DOCUME~1\Carol\LOCALS~1\Temp
[F:25][D:0]-> C:\DOCUME~1\Carol\Cookies
[F:2][D:0]-> C:\DOCUME~1\Carol\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Wed 11/19/2008| 7:23 - Option : [1]

——————–\\ Scan completed at 7:23:18
And…Hijackthis results…. :yeah:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:35:19 AM, on 11/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\Logi_MwX.Exe
C:\PROGRA~1\KEMailKb\KEMailKb.EXE
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\rmctrl.exe
C:\Program Files\Say the Time\SayTime.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Sierra\Planner\Plnrnote.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\Program Files\MSI\TV@Anywhere Utilities\P3XRCtl.exe
C:\Program Files\Webshots\WebshotsTray.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cleveland.cox.net/cci/home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - (no file)
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [KEMailKb] C:\PROGRA~1\KEMailKb\KEMailKb.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Say the Time] C:\Program Files\Say the Time\SayTime.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04b\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [SansaDispatch] C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Event Planner Reminders Tray Icon.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O4 - Global Startup: TV Remote Control.lnk = C:\Program Files\MSI\TV@Anywhere Utilities\P3XRCtl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143530611687
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe

–
End of file - 14981 bytes
TazzyGirl,

You're infected because you download cracks!

Disable your protection programs as we did before.

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - (no file)
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - (no file)
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

Next

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    File::
    C:\DOCUME~1\Carol\Desktop\My software\7000 Serials cracks.txt
    C:\DOCUME~1\Carol\Desktop\My software\alchemy.deluxe.1.2.keygen-tsrh.exe
    C:\DOCUME~1\Carol\Desktop\My software\CRACKS & SERIALS - Hundreds Of Serial Numbers And Registration Codes (Kai Flaming Pear Eye Candy Adobe Extensis Plugin Xenofex Paintshop Psp Gif Boris Fx.txt
    C:\DOCUME~1\Carol\Favorites\Cracks Serials\Absolutist - Archibaldgames - AxySoft - Silver Creek - Tibosoftware - Small Games v.3.0.url
    C:\DOCUME~1\Carol\My Documents\Temp\2 Symantec All in one 2005\NIS_RETL\KEYGEN
    C:\DOCUME~1\Carol\My Documents\Temp\2 Symantec All in one 2005\NIS_RETL\KEYGEN\KGNIS.EXE
    C:\DOCUME~1\Carol\My Documents\Temp\2 Symantec All in one 2005\NSWP2005\KEYGEN
    C:\DOCUME~1\Carol\My Documents\Temp\2 Symantec All in one 2005\NSWP2005\KEYGEN\KEYGEN.EXE
    C:\DOCUME~1\Carol\My Documents\Temp\INTERNET HISTORY ERASER v5.6\keygen.exe
    
    Folder::
    C:\DOCUME~1\Carol\Favorites\Cracks Serials
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


Give it a spin. How are things running now?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI